- Singapore
工作地点
职位描述
岗位职责
We're Hiring: Security Analyst!
We are looking for a detail-oriented and proactive Security Analyst to join our team in Singapore. The ideal candidate will have a strong background in cybersecurity, risk management, and incident response. You will play a crucial role in safeguarding our organization's information systems and ensuring compliance with security standards.
Location: Singapore, Singapore
Work Mode: Work from Office
Role: Security Analyst
Key Responsibilities
Vulnerability Management
• Own and manage the end-to-end Vulnerability Management process, including intake, triage, and lifecycle tracking of security findings across the organization's systems and assets.
• Classify vulnerabilities by severity, exploitability, and business impact using frameworks such as CVSS, EPSS, and internal risk criteria.
• Plan, coordinate, and manage Quarterly Vulnerability Assessments — scoping targets, engaging scanning tools, reviewing outputs, and driving findings through to resolution.
• Manage the Yearly Penetration Testing cycle, including scoping, vendor coordination, findings review, and tracking remediation commitments through to closure.
• Track key remediation implementations end-to-end, maintaining visibility from initial detection through to verified closure — for example, overseeing the transition of WAF rules from detection mode to prevention mode, ensuring each step is documented, tested, and signed off.
• Coordinate with remediation teams (engineering, DevOps, infrastructure) to ensure timely resolution of findings, providing clear context and prioritization guidance.
• Maintain and update risk acceptance records, ensuring appropriate approvals are obtained, documented, and reviewed on schedule.
• Track and report on remediation SLAs, escalating overdue or high-risk items to the appropriate stakeholders.
• Produce regular status reports and dashboards that communicate the project's overall security posture to technical and non-technical audiences.
Security Visibility & Reporting
• Aggregate vulnerability data from multiple scanning tools and sources into a coherent, unified view of security risk.
• Develop and maintain metrics and KPIs that enable leadership visibility into ongoing security exposure and program effectiveness.
• Present findings, trends, and recommendations in written reports, executive briefings, and team meetings.
Collaboration & Process Improvement
• Act as a liaison between the security team and remediation owners, facilitating communication and removing blockers to resolution.
• Continuously improve vulnerability management workflows, tooling, and documentation.
• Support audit and compliance activities by providing evidence of vulnerability tracking and risk treatment processes.
• Contribute to threat intelligence efforts and stay current on emerging CVEs and attack trends relevant to the organization.
Qualifications Required
• 2+ years of experience in an information security, vulnerability management, or related role.
• Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7, Wiz, or similar).
• Solid understanding of CVSS scoring, vulnerability classification, and risk-based prioritization.
• Experience communicating security findings and risk to both technical teams and business stakeholders.
• Familiarity with common compliance and risk frameworks (e.g., NIST CSF, ISO 27001, SOC 2).
• Familiarity with GovTech's IM8 (Instruction Manual 8) policies and its associated risk-based assessment methodology, including the application of controls, classification of government ICT systems, and conducting or supporting IM8-aligned security reviews.
• Strong organizational skills with the ability to manage multiple workstreams and deadlines simultaneously.
Preferred
• Relevant certifications such as CompTIA Security+, CEH, GWAPT, or equivalent.
• Experience with ticketing and workflow tools (e.g., Jira, ServiceNow) for tracking remediation.
• Scripting or automation skills (Python, Bash) to support data aggregation and reporting workflows.
• Background in cloud security environments (AWS, Azure, GCP).
Ready to secure our future? Apply now and be part of our dynamic team!
重要安全守则
申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。