Skip to content

Open nowPosted today

IT Security Officer (ITSO) - #1682

MyCareersFuture94,660 open roles

Pay
SGD 6,500 – SGD 7,500 a month
Where
Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT Security Officer (ITSO) - #1682MyCareersFuture · Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. MyCareersFuture postings stay open a median of 3 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted today

MyCareersFuture median: 3 days open

The posting

Job Description – Information Technology Security Officer

1. Scope of Work

The Information Technology Security Officer will support the Board's cybersecurity governance, assurance, and security management activities across security architecture, vulnerability assessment and penetration testing, risk assessment, system hardening, cloud security posture management, software clearance, firewall and network deviation management, cybersecurity policies and standards, and security metrics reporting.

The officer will coordinate security reviews and assessments, maintain cybersecurity registers and trackers, follow up on remediation and outstanding actions with relevant stakeholders, prepare security reports and management dashboards, and support the upkeep of cybersecurity policies, standards, specifications, and documentation.

This role requires strong coordination, analytical, documentation, and stakeholder management skills, with a good understanding of enterprise cybersecurity controls, risk management, and governance processes.

2. Roles and Responsibilities

Security Architecture

  • Assist in maintaining security architecture diagrams, records, and approved design documentation.
  • Track security architecture review requests and coordinate inputs from project teams and relevant stakeholders.
  • Maintain records of architecture decisions, recommendations, and approved designs.
  • Support preparation of security advisory materials and architecture review documentation.

Vulnerability Assessment & Penetration Testing

  • Coordinate and schedule VAPT engagements with system owners, vendors, and security testers.
  • Maintain the VAPT tracker and follow up on remediation of identified vulnerabilities.
  • Coordinate re-testing activities and update finding closure status.
  • Assist in preparing VAPT reports, summaries, and presentation materials.

Risk Assessment

  • Coordinate cybersecurity risk assessment exercises with system owners and stakeholders.
  • Maintain the cybersecurity risk register and track risk treatment and remediation actions.
  • Support preparation of risk reports and management review materials.
  • Facilitate risk acceptance, exception, and approval processes in accordance with the Board's requirements.

Hardening Compliance

  • Coordinate security hardening compliance assessments with system and infrastructure teams.
  • Track hardening gaps and follow up on remediation progress.
  • Maintain hardening compliance records, checklists, and trackers.
  • Support preparation of periodic hardening compliance reports.

Cloud Security Posture Management

  • Monitor and triage findings generated by Cloud Security Posture Management tools.
  • Track cloud security misconfigurations and follow up on remediation with system and cloud owners.
  • Maintain CSPM findings and remediation status records.
  • Prepare periodic cloud security posture reports and summaries.

Software Clearance

  • Receive, log, and track software security clearance requests.
  • Coordinate with requestors and vendors to obtain required technical and security documentation.
  • Maintain the software clearance register and approval status.
  • Support preparation of software security evaluation summaries and monitor expiring clearances.

Firewall & Network Deviation Management

  • Receive, track, and maintain firewall rule change and network security deviation requests.
  • Follow up with requestors and network teams on outstanding actions and expiring deviations.
  • Maintain deviation registers and prepare review summaries for approval.
  • Coordinate periodic firewall rule and network deviation reviews with relevant teams.

Policy, Standards & Governance / Cyber Specifications

  • Assist in drafting, reviewing, and updating cybersecurity policies, standards, guidelines, and procedures.
  • Maintain the cybersecurity policy and standards documentation repository.
  • Track document review cycles, approvals, and expiry dates.
  • Support preparation and review of cybersecurity specifications for projects, procurements, and tenders.

Security Metrics & Reporting

  • Collate and consolidate cybersecurity data and status updates from relevant teams and systems.
  • Maintain cybersecurity dashboards covering vulnerabilities, risks, deviations, compliance, and audit items.
  • Prepare routine security metrics and management reports.
  • Follow up with responsible parties on outstanding cybersecurity actions and remediation items.

Security & Compliance

  • Ensure activities are performed in accordance with the Board's cybersecurity policies, applicable regulatory requirements, and the Cybersecurity Code of Practice (CCoP).
  • Support cybersecurity assessments, internal and external audits, and evidence collection activities.
  • Maintain accurate and up-to-date cybersecurity records, reports, registers, and supporting documentation.
  • Protect sensitive and security-classified information in accordance with the Board's requirements.

3. Technical Requirements

Mandatory Technical Skills

  • Good understanding of enterprise cybersecurity concepts, including vulnerability management, security risk assessment, system hardening, firewall controls, cloud security, and security governance.
  • Experience coordinating cybersecurity assessments, remediation activities, and security review processes involving multiple technical and business stakeholders.
  • Ability to review and understand vulnerability assessment findings, security risk assessments, security architecture diagrams, firewall rules, and security compliance reports.
  • Familiarity with security frameworks, policies, standards, and cybersecurity governance processes.
  • Strong analytical, documentation, stakeholder coordination, and follow-up skills.

Good-to-Have

  • Familiarity with CSPM platforms and cloud security concepts across AWS, Azure, or equivalent cloud environments.
  • Experience with vulnerability management or VAPT tools and interpreting CVE/CVSS information.
  • Understanding of enterprise network architecture, firewall rules, security zones, and network segmentation.
  • Experience supporting cybersecurity audits, governance, risk, and compliance activities.

Certifications

  • CompTIA Security+, ISC2 Certified in Cybersecurity (CC), or equivalent foundational cybersecurity certification is highly preferred.
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent will be advantageous.
  • Certified in Risk and Information Systems Control (CRISC), ISO 27001-related certification, or equivalent risk/governance certification will be advantageous.
  • Relevant cloud security certification such as Microsoft Azure Security, AWS Security, or equivalent will be advantageous.

4. Working Arrangement

  • Onsite at designated PUB secure premises in Singapore, as required.
  • The officer will work closely with system owners, infrastructure teams, cybersecurity teams, project teams, vendors, and contractors.
  • Must comply with all security, confidentiality, and access control requirements of PUB premises and systems.
  • The officer shall be subjected to security clearance by the Board prior to commencement of work.

5. Contract Details

The contract period and start date shall be as stipulated in the awarded contract. The proposed Service Personnel shall be subjected to the requisite security clearance category prior to onboarding.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.