Cyber Security Specialist- Vulnerability Management

3 weeks ago


Singapore IKAS INTERNATIONAL (ASIA) PTE. LTD. Full time
Roles & Responsibilities

We are looking to speak to Cyber Security candidates with good experience in Vulnerability Management

You will be part of the Data Security Services team and will take ownership of Vulnerability Management. The individual will receive support from platform teams for implementing remediation actions.

Responsibilities

  • Vulnerability Management Plan: Prepare and execute the Vulnerability Management Plan through all phases of the Vulnerability Management Lifecycle.
  • Vulnerability Scans: Ensure vulnerability scans are scheduled, properly configured in tools, and executed according to the plan. Investigate any failures and reschedule scans for re-execution.
  • IT Asset Discovery: Conduct periodic discovery of IT assets, ensuring identified assets are communicated to the CMDB owner for appropriate asset tagging and are onboarded into the Vulnerability Management tool.
  • Vulnerability Assessment: Assess identified vulnerabilities, studying and understanding their risk profiles and impact based on the environmental context.
  • Collaboration and Advising: Participate in discussions with Infrastructure and Application teams, advising on the relevance of vulnerabilities and their potential impact.
  • False Positives and Risk Acceptance: Understand and address false positives and technical limitations in the environment, facilitating the Risk Acceptance process where needed. Liaise with stakeholders to propose and maintain approvals for Risk Acceptance cases.
  • Collaboration with Infrastructure Teams: Work with Infrastructure teams (Windows, Unix, Networks, etc.) to ensure the remediation of identified vulnerabilities.
  • Vulnerability Dashboard & Reporting: Maintain the Vulnerability Dashboard, submitting regular reports for technical teams and management.
  • KPIs & Progress Reporting: Organize and prioritize work to comply with established KPIs for Vulnerability Management. Regularly report on progress and proactively work to meet these KPIs.
  • Escalation & Consultation: Escalate issues, discuss, and consult with higher levels of management when needed.
  • Specialist Support: Provide specialist-level support for the Vulnerability Management service.
  • Penetration Testing: Lead the remediation planning following penetration testing, collaborating with cross-functional teams.
  • Threat Exposure Scanning: Conduct threat exposure scans across the asset scope, advising on applicability and leading remediation efforts with cross-functional teams.
  • Stakeholder Meetings & Collaboration: Participate in scheduled meetings with various stakeholders and liaise with teams across different geographical zones.
  • Service Improvements: Propose, plan, and execute initiatives for service improvements.
  • Policy Adherence: Ensure adherence to the organization's policies and procedures.
  • Reporting to Manager: Prepare and provide regular (weekly, monthly, ad-hoc) reports to the manager as necessary.
  • Continuous Knowledge Maintenance: Stay up-to-date with new threats and vulnerabilities, providing relevant analysis based on their applicability.
  • Compliance with Legal & Regulatory Requirements: Ensure compliance with all applicable legal, regulatory, and internal compliance requirements, including the Singapore Compliance manual, financial security obligations, and reporting requirements related to preventing financial crime, fraud, and reporting to the Money Laundering Reporting Officer.

Requirements

  • Experience:
  • 8-10 years of IT experience, with at least 4-7 years specifically in IT Security, and a minimum of 4+ years managing the Vulnerability Management process within an enterprise.
  • Professional Certifications (highly preferred):
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Enterprise Vulnerability Assessor (GEVA) or other relevant Vulnerability Management certifications
    CREST certification
  • Technical Expertise:
  • Hands-on experience managing the Vulnerability Management process in an enterprise setting.
  • Strong technical understanding and experience in assessing vulnerabilities and identifying weaknesses across multiple operating system platforms, networks, databases, and application servers.
  • Ability to assess vulnerabilities and prioritize remediation efforts based on risk and impact.
  • Collaboration and Risk Management:
  • Proven experience working collaboratively with cross-functional/transverse IT teams in a production environment (Operations mode).
  • Ability to apply a risk-based approach to the assigned responsibilities, balancing technical needs with business priorities.
  • Tool Expertise:
  • Extensive experience with Tenable (Nessus) Security Center for vulnerability management in a large-scale enterprise environment.
  • Good understanding of reporting needs at various levels of the organization and the ability to design, create, and present clear, actionable reports.
  • Reporting & Dashboarding:
  • Hands-on experience creating reports using tools like Excel, PowerPoint, and Word, including graphical formats and trending analyses.
  • Experience with BI tools, such as Power BI, for creating dashboards to present vulnerability data and trends.
  • Security Knowledge:
  • Solid knowledge of various domains of Information Security.
  • Experience in working within a financial organization is highly preferred.
  • Skills and Abilities:
  • Strong analytical, communication, and documentation skills.
  • Ability to organize, prioritize, and manage work efficiently in a fast-paced environment.
  • Strong understanding of ITIL processes and comfort working in a process-oriented environment.
  • Ability to work independently as well as part of a team, with minimal supervision.
  • Excellent time management skills.
  • Language Skills:
  • Fluent in written and oral English
  • French language skills are preferred but not required

Work hours

  • Summer Season: 2:00 PM to 11:00 PM or 4:00 PM to 1:00 AM.
  • Winter Season: 3:00 PM to 12:00 AM or 5:00 PM to 2:00 AM.
  • There may be a requirement for on-call support outside of regular business hours, including weekends. Any such hours will be eligible for claimable allowances

"Sanderson-iKas" is the brand name for iKas International (Asia) Pte Ltd, a company incorporated in Singapore under Company UEN No.: 200914065E with EA license number 16S8086.

Website: www.sanderson-ikas.sg

Tell employers what skills you have

Vulnerability Management
Cyber Security
Application Servers
Documentation Skills
Scripting
Threat Assessment
Risk Management
Assessor
Penetration Testing
Windows
Fraud
ITIL
Regulatory Requirements
Cyber Security Management
Threat & Vulnerability Management
Vulnerability Assessment
Linux
CISSP
Threat and Vulnerability Management

  • Singapore IKAS INTERNATIONAL (ASIA) PTE. LTD. Full time

    Roles & ResponsibilitiesWe are looking to speak to Cyber Security candidates with good experience in Vulnerability Management! You will be part of the Data Security Services team and will take ownership of Vulnerability Management. The individual will receive support from platform teams for implementing remediation actions.Responsibilities Vulnerability...


  • Singapore STAR CAREER CONSULTING PTE. LTD. Full time

    Roles & ResponsibilitiesCyber Security Specialist (VAPT)Job DescriptionArchitect, design, review and implement cyber security resilient in our product and projects. You are familiar with cloud security architectures and solutions, making sure the companies can operate in a safe, secure environment.ResponsibilitiesResponsible in managing CyberSecurity VAPT,...


  • Singapore PEOPLESEARCH PTE. LTD. Full time

    Roles & ResponsibilitiesCyber Security GRC SpecialistOur client is looking for an experienced Cyber Security GRC Specialist to develop, implement and maintain governance, risk and compliance programs within their cyber security framework.Responsibilities:Develop and maintain cyber security policies, procedures and standards in alignment with industry...


  • Singapore STAR CAREER CONSULTING PTE. LTD. Full time

    Roles & ResponsibilitiesCyber Security Specialist (VAPT)Job DescriptionArchitect, design, review and implement cyber security resilient in our product and projects. You are familiar with cloud security architectures and solutions, making sure the companies can operate in a safe, secure environment.ResponsibilitiesResponsible in managing CyberSecurity VAPT,...


  • Singapore Citi Full time

    Citi is a global leader in the financial services industry, with a long history of innovation and commitment to excellence. We are currently seeking an Information Security Expert - Cyber Vulnerability Specialist to join our team.Job DescriptionThe ideal candidate will have a strong background in information security and experience with vulnerability...


  • Singapore PEOPLESEARCH PTE. LTD. Full time

    Roles & ResponsibilitiesCyber Security GRC SpecialistOur client is looking for an experienced Cyber Security GRC Specialist to develop, implement and maintain governance, risk and compliance programs within their cyber security framework.Responsibilities: Develop and maintain cyber security policies, procedures and standards in alignment with industry...


  • Singapore PLAN B SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description:As a next-gen Cyber Security Consultant. The candidates will be involve in project planning, rolling out of security solution to secure customers environment. Having an open heart and open mind, to learn the sophisticated Cyber Security technology. Join us and onboard to the next-gen journey.Product Coverage* Next-Gen...


  • Singapore PLAN B SECURITY PTE. LTD. Full time

    Roles & ResponsibilitiesJob Description:As a next-gen Cyber Security Consultant. The candidates will be involve in project planning, rolling out of security solution to secure customers environment. Having an open heart and open mind, to learn the sophisticated Cyber Security technology. Join us and onboard to the next-gen journey.Product Coverage* Next-Gen...


  • Singapore ERP21 PTE LTD Full time

    Roles & ResponsibilitiesRole OverviewThe Cyber Security Specialist is responsible for designing, implementing, and managing security solutions to protect the company's information systems, networks, and data from potential threats and cyber-attacks. The primary role is to provide expert guidance, support, and leadership in all matters related to security...


  • Singapore PERSOLKELLY SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesThe Cyber Security GRC Specialist is responsible for developing, implementing, and maintaining governance, risk, and compliance programs within an organization's cybersecurity framework. The role involves ensuring adherence to regulatory requirements, identifying and mitigating risks, and establishing robust security policies and...


  • Singapore ERP21 PTE LTD Full time

    Roles & ResponsibilitiesRole OverviewThe Cyber Security Specialist is responsible for designing, implementing, and managing security solutions to protect the company's information systems, networks, and data from potential threats and cyber-attacks. The primary role is to provide expert guidance, support, and leadership in all matters related to security...


  • Singapore TIKTOK PTE. LTD. Full time

    We are seeking a talented Vulnerability Management Specialist to join our Global Security Organization at TikTok PTE. LTD. As a key member of our team, you will be responsible for analyzing, assessing, compiling, and prioritizing vulnerabilities to document and communicate mitigation recommendations.Responsibilities:Analyze and assess vulnerabilities to...


  • Singapore PERSOLKELLY SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesThe Cyber Security GRC Specialist is responsible for developing, implementing, and maintaining governance, risk, and compliance programs within an organization's cybersecurity framework. The role involves ensuring adherence to regulatory requirements, identifying and mitigating risks, and establishing robust security policies and...


  • Singapore STT GDC PTE. LTD. Full time

    Roles & ResponsibilitiesAbout STT GDCBe part of a global leader in data centre solutionsST Telemedia Global Data Centres (STT GDC) is a data centre provider headquartered in Singapore, with a global footprint in major business markets across Singapore, the United Kingdom, Germany, India, Thailand, South Korea, Indonesia, Japan, the Philippines, Malaysia and...


  • Singapore SINGAPORE AIRLINES LIMITED Full time

    Roles & ResponsibilitiesJob DescriptionYou will be a member of the Group Information Security Team responsible for ensuring corporate applications, systems, networks, and digital assets are adequately protected and mitigated against cyber threats and risks. You will help drive cybersecurity and risk management efforts and user awareness and education within...


  • Singapore PERSOLKELLY SINGAPORE PTE. LTD. Full time

    Roles & Responsibilitiesole Overview:The role involves safeguarding systems, applications, and infrastructure through proactive vulnerability management, the application of security controls, secure development practices, incident response, and continuous threat monitoring. You will collaborate with both internal teams and external service providers to...


  • Singapore DEXIAN SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesIdeal candidate: should hold a degree in Cyber Security or a related field, or possess a cyber security certification, with a minimum of 2 years of experience in the cyber security field, particularly in security governance, design, and deployment. Key responsibilities include staying informed about the latest cybersecurity trends,...


  • Singapore ECHO TECHNICAL PTE. LTD. Full time

    Roles & ResponsibilitiesWe are dedicated to ensuring the security and privacy of our clients' data and systems. As part of our commitment to excellence, we are seeking a highly skilled Cyber Security Consultant to join our team.Job Description:As a Cyber Security Consultant at Echo Technical, you will be responsible for assessing, implementing, and...


  • Singapore DEXIAN SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesIdeal candidate: should hold a degree in Cyber Security or a related field, or possess a cyber security certification, with a minimum of 2 years of experience in the cyber security field, particularly in security governance, design, and deployment. Key responsibilities include staying informed about the latest cybersecurity trends,...


  • Singapore PEPPER INTERNET TECHNOLOGY PTE. LTD. Full time

    Roles & ResponsibilitiesAs a Cyber Security Consultant at Pepper Internet , you will be responsible for assessing, implementing, and maintaining security measures to protect our clients' digital assets. You will work closely with clients to understand their security needs, identify vulnerabilities, and develop customized solutions to mitigate risks....