- Islandwide (Singapore) Singapore
工作地点
职位描述
岗位职责
Role Overview
We are seeking a System Engineer to support enterprise systems by conducting vulnerability assessments, managing patching activities, and overseeing secure software lifecycle practices throughout the year. The role focuses on maintaining system resilience, ensuring security compliance, and reducing security risks across infrastructure and applications. The role also ensures compliance with Government IT security standards such as IM8 and supports audit requirements.
Key Responsibilities
1. Vulnerability Management
Perform regular vulnerability scanning on systems, applications, and infrastructure using industry-approved tools. Analyse scan results and prioritise vulnerabilities based on severity and business impact. Validate findings and track remediation status to closure. Work with stakeholders to mitigate security risks in a timely manner.
2. Patch Management
Plan and execute security patching across servers, endpoints, and applications. Ensure timely remediation of vulnerabilities identified through scans or external advisories. Maintain patch schedules and ensure compliance with organisational standards. Conduct post-patch validation to confirm successful remediation.
3. Software Lifecycle Security
Support secure software lifecycle practices (SDLC), including code security reviews and testing. Work closely with development teams to identify and remediate security issues early. Conduct security testing (e.g. SAST, DAST) during development and deployment phases. Maintain security testing tools and frameworks.
4. Monitoring & Continuous Improvement
Maintain dashboards and reports for vulnerability and patching status. Track trends and recommend improvements to reduce recurring vulnerabilities. Support audits and compliance checks related to cybersecurity controls. Improve scanning, patching, and lifecycle processes through automation.
5. Collaboration & Governance
Collaborate with IT, infrastructure, and application teams to drive remediation efforts. Provide security advice and best practices across projects. Ensure adherence to internal security policies and regulatory requirements, including IM8 compliance.
Manage vulnerability scanning, patching, and lifecycle updates for enterprise platforms including Citrix, Nutanix, Microsoft AD/Entra, NetScaler, and business-critical software such as Autodesk and Graphisoft products.
Requirements
Experience:
Technical Skills
Key Competencies
Bonus
重要安全守则
申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。