Search by job, company or skills

IT Security Officer

IT Security Officer

dbiz.ai
4-7 Years
Not Disclosed
Early Applicant
  • Posted 10 days ago
  • Be among the first 10 applicants

Job Description

Experience Required: 4–7 years

About the Role

DBiz is seeking an IT Security Officer (Cybersecurity) to strengthen cybersecurity operations and governance for government systems. In this role, you will work across security monitoring, vulnerability management, incident response, and security assurance—partnering closely with internal stakeholders and external security vendors. You will ensure security testing is executed effectively, findings are translated into actionable remediation, and security controls remain robust against evolving threats.

Key Responsibilities

  • Own day-to-day security operations and governance, working with internal teams and managed security service providers (MSSPs) to deliver agreed outcomes
  • Manage security vendors and deliverables (scope, timelines, reporting quality, follow-ups, and service performance)
  • Plan and run periodic security testing cycles (e.g., vulnerability scans, penetration tests, configuration reviews), ensuring coverage and timely completion
  • Review security findings and validate mitigation/remediation plans for adequacy, risk reduction, and operational feasibility
  • Track and drive timely remediation closure, coordinating with infrastructure, application, and project teams; escalate risks where required
  • Review and interpret security reports (e.g., VA/PT results, monitoring reports, advisories) and translate them into clear actions and risk narratives
  • Maintain and improve security policies, standards, procedures, and guidelines, aligned to recognised frameworks (e.g., NIST, ISO 27001) and government requirements
  • Provide cybersecurity consultancy to project teams—security-by-design guidance, risk assessments, and control recommendations
  • Monitor and respond to security alerts/advisories, including triage, investigation support, and containment actions where needed
  • Support incident response activities: initial assessment, coordination, evidence handling support, post-incident review, and lessons learned
  • Drive security awareness: conduct briefings/training, publish user advisories, and run targeted campaigns (e.g., phishing, email security hygiene)

Screening Requirements / Skills (Must-Have)

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or related discipline
  • 4–7 years of experience in cybersecurity operations, security assurance, or a similar role
  • Strong fundamentals in networking and operating systems (Windows/Linux) and working knowledge of cloud security concepts (AWS/Azure/GCP)
  • Hands-on experience with security tooling such as SIEM, vulnerability scanners, and/or penetration testing tools
  • Proven ability to manage security testing and remediation end-to-end (from findings to closure)
  • Familiarity with security frameworks/standards such as NIST and/or ISO 27001
  • Ability to communicate security risks and recommendations clearly to both technical and non-technical stakeholders
  • CISSP and/or CISM certification (required)

Nice-to-Have / Advantage

  • Understanding of OWASP Top 10 and common web application security issues
  • Experience in incident handling and operational playbooks/runbooks
  • Scripting/automation skills (e.g., Python, PowerShell) to streamline security operations
  • Exposure to software development, DevSecOps, or security operations in complex environments
  • Additional certifications (advantage): GCIH, Security+, CySA+, ECSA, CEH, SSCP, OSCP

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

vulnerability scanners

penetration testing tools

cloud security concepts

CySA plus

Windows

About Company

Similar Jobs

7-9 yrs
Singapore
Skills:
security assurance , DAST, Cloud security, Penetration Testing, Google Cloud, Identity And Access Management, Incident Response, Microsoft Azure, Vulnerability assessment, AWS, Cyber resilience, Security Architecture, Cybersecurity governance, SAST, Disaster Recovery, Zero Trust, Risk management
5-7 yrs
Singapore
Skills:
cloud security, network security, Vulnerability Management, Iso 27001, Vapt, Azure, AWS, Documentation, Risk Assessment, remediation activities, Policies, security governance, CVSS, Standards, CSPM tools, CVE, system hardening, Security Assessments, audits, GRC activities, firewall controls
4-7 yrs
Singapore
Skills:
security tools , PowerShell, Operating Systems, Windows, Network Protocols, Iso 27001, Gcp, Linux, Scripting Languages, Azure, Python, AWS, vulnerability scanners, penetration testing tools, SIEM platforms, cybersecurity frameworks, nist, cloud security concepts
4-7 yrs
SGD 6,500 - 7,500 per month
Singapore
Skills:
Government Commercial Cloud (GCC), OWASP Application Security Verification Standard (ASVS), Github, Soap, Sonarqube, SSL, REST, DevSecOps, Ansible, Owasp Top 10, Agile Development, Gitlab, Tls, AWS, Security awareness training, Fortify-on-Demand, Cybersecurity risk assessments, CI/CD, Threat modelling, SAST code scanning tools, Cybersecurity incident response and management
8-11 yrs
SGD 8,000 - 9,200 per month
Singapore
Skills:
Government Commercial Cloud (GCC), Iso 27001, Siem, PAM, cloud security controls, NIST CSF, CIS Controls, vulnerability management tools, IM8, EDR, audit remediation, security risk assessments