jobs in OPENSOURCE TECHNOLOGIES PTE. LTD.

全职 Security Analyst 工作, 薪水 up to SGD 8,000, OPENSOURCE TECHNOLOGIES PTE. LTD. 公司招聘中 - Ricebowl

Security Analyst

OPENSOURCE TECHNOLOGIES PTE. LTD.

SGD6,000 - SGD8,000 每月

Singapore

分享
保存

工作地点

  • Singapore

职位描述

岗位职责

Key Responsibilities

Vulnerability Management

  • Own and manage the end-to-end Vulnerability Management process, including intake, triage, and lifecycle tracking of security findings across the organization's systems and assets.
  • Classify vulnerabilities by severity, exploitability, and business impact using frameworks such as CVSS, EPSS, and internal risk criteria.
  • Plan, coordinate, and manage Quarterly Vulnerability Assessments — scoping targets, engaging scanning tools, reviewing outputs, and driving findings through to resolution.
  • Manage the Yearly Penetration Testing cycle, including scoping, vendor coordination, findings review, and tracking remediation commitments through to closure.
  • Track key remediation implementations end-to-end, maintaining visibility from initial detection through to verified closure — for example, overseeing the transition of WAF rules from detection mode to prevention mode, ensuring each step is documented, tested, and signed off.
  • Coordinate with remediation teams (engineering, DevOps, infrastructure) to ensure timely resolution of findings, providing clear context and prioritization guidance.
  • Maintain and update risk acceptance records, ensuring appropriate approvals are obtained, documented, and reviewed on schedule.
  • Track and report on remediation SLAs, escalating overdue or high-risk items to the appropriate stakeholders.
  • Produce regular status reports and dashboards that communicate the project's overall security posture to technical and non-technical audiences.

Security Visibility & Reporting

  • Aggregate vulnerability data from multiple scanning tools and sources into a coherent, unified view of security risk.
  • Develop and maintain metrics and KPIs that enable leadership visibility into ongoing security exposure and program effectiveness.
  • Present findings, trends, and recommendations in written reports, executive briefings, and team meetings.

Collaboration & Process Improvement

  • Act as a liaison between the security team and remediation owners, facilitating communication and removing blockers to resolution.
  • Continuously improve vulnerability management workflows, tooling, and documentation.
  • Support audit and compliance activities by providing evidence of vulnerability tracking and risk treatment processes.
  • Contribute to threat intelligence efforts and stay current on emerging CVEs and attack trends relevant to the organization.

Qualifications Required

  • 2+ years of experience in an information security, vulnerability management, or related role.
  • Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7, Wiz, or similar).
  • Solid understanding of CVSS scoring, vulnerability classification, and risk-based prioritization.
  • Experience communicating security findings and risk to both technical teams and business stakeholders.
  • Familiarity with common compliance and risk frameworks (e.g., NIST CSF, ISO 27001, SOC 2).
  • Familiarity with GovTech's IM8 (Instruction Manual 8) policies and its associated risk-based assessment methodology, including the application of controls, classification of government ICT systems, and conducting or supporting IM8-aligned security reviews.
  • Strong organizational skills with the ability to manage multiple workstreams and deadlines simultaneously.

Preferred

  • Relevant certifications such as CompTIA Security+, CEH, GWAPT, or equivalent.
  • Experience with ticketing and workflow tools (e.g., Jira, ServiceNow) for tracking remediation.
  • Scripting or automation skills (Python, Bash) to support data aggregation and reporting workflows.
  • Background in cloud security environments (AWS, Azure, GCP).

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多