Hiring.Camp

M01 - Information Technology Security Officer

Fpt Asia Pacific Pte Ltd

·

Today

Location
Singapore
Type
Full-time
Department
IT
Closing date
Today
Source
CareersPage

Description

About the Role

We are looking for an Information Technology Security Officer to support cybersecurity governance, assurance, risk management, and security operations.

The role covers security architecture, vulnerability assessment and penetration testing (VAPT), cybersecurity risk assessments, system hardening, cloud security posture management, software security clearance, firewall and network deviation management, cybersecurity policies and standards, and security reporting.

You will work closely with system owners, infrastructure and cybersecurity teams, project teams, vendors, and other stakeholders to coordinate security assessments, track remediation activities, maintain security registers and documentation, and support cybersecurity governance and compliance requirements.

Key Responsibilities

Security Architecture

  • Maintain security architecture diagrams, records, and approved design documentation.
  • Coordinate security architecture reviews with project teams and relevant stakeholders.
  • Track architecture decisions, recommendations, and approved designs.
  • Support the preparation of security advisory materials and architecture review documentation.

Vulnerability Assessment & Penetration Testing (VAPT)

  • Coordinate and schedule VAPT activities with system owners, vendors, and security testers.
  • Maintain VAPT trackers and monitor remediation of identified vulnerabilities.
  • Coordinate re-testing activities and track findings through to closure.
  • Prepare VAPT reports, summaries, and presentation materials.

Cybersecurity Risk Management

  • Coordinate cybersecurity risk assessments with system owners and stakeholders.
  • Maintain cybersecurity risk registers and track risk treatment and remediation actions.
  • Support the preparation of risk reports and management review materials.
  • Facilitate risk acceptance, exception, and approval processes.

Security Hardening & Compliance

  • Coordinate security hardening assessments with system and infrastructure teams.
  • Track security hardening gaps and remediation progress.
  • Maintain compliance records, checklists, and trackers.
  • Prepare periodic hardening and compliance reports.

Cloud Security Posture Management

  • Monitor and triage security findings generated by Cloud Security Posture Management (CSPM) tools.
  • Track cloud security misconfigurations and coordinate remediation with system and cloud owners.
  • Maintain CSPM findings and remediation records.
  • Prepare periodic cloud security posture reports and summaries.

Software Security Clearance

  • Receive, log, and track software security clearance requests.
  • Coordinate with requestors and vendors to obtain the required technical and security documentation.
  • Maintain software clearance registers and approval status.
  • Prepare software security evaluation summaries and monitor expiring clearances.

Firewall & Network Security

  • Track firewall rule changes and network security deviation requests.
  • Follow up with requestors and network teams on outstanding actions and expiring deviations.
  • Maintain deviation registers and prepare review summaries for approval.
  • Coordinate periodic reviews of firewall rules and network security deviations.

Cybersecurity Policies, Standards & Governance

  • Support the drafting, review, and updating of cybersecurity policies, standards, guidelines, and procedures.
  • Maintain cybersecurity policy and standards documentation.
  • Track document review cycles, approvals, and expiry dates.
  • Support the preparation and review of cybersecurity requirements and specifications for projects, procurements, and tenders.

Security Metrics & Reporting

  • Consolidate cybersecurity data and status updates from relevant teams and systems.
  • Maintain dashboards covering vulnerabilities, risks, deviations, compliance, and audit findings.
  • Prepare regular cybersecurity metrics and management reports.
  • Track outstanding security actions and follow up with responsible stakeholders.

Security & Compliance

  • Support cybersecurity assessments, internal and external audits, and evidence collection activities.
  • Ensure activities comply with applicable cybersecurity policies, regulatory requirements, and the Cybersecurity Code of Practice (CCoP).
  • Maintain accurate and up-to-date cybersecurity records, registers, reports, and supporting documentation.
  • Handle sensitive and security-classified information in accordance with applicable security requirements.

Requirements

  • Good understanding of enterprise cybersecurity concepts, including vulnerability management, cybersecurity risk assessment, system hardening, firewall controls, cloud security, and security governance.
  • Experience coordinating cybersecurity assessments, remediation activities, and security review processes involving multiple technical and business stakeholders.
  • Ability to understand and review vulnerability assessment findings, cybersecurity risk assessments, security architecture diagrams, firewall rules, and compliance reports.
  • Familiarity with cybersecurity frameworks, policies, standards, and governance processes.
  • Strong analytical, documentation, stakeholder management, coordination, and follow-up skills.

Good to Have

  • Familiarity with CSPM platforms and cloud security concepts across AWS, Microsoft Azure, or similar cloud environments.
  • Experience with vulnerability management or VAPT tools and interpreting CVE and CVSS information.
  • Understanding of enterprise network architecture, firewall rules, security zones, and network segmentation.
  • Experience supporting cybersecurity audits, Governance, Risk and Compliance (GRC) activities.

Certifications

  • The following certifications are preferred or advantageous:
  • CompTIA Security+, ISC2 Certified in Cybersecurity (CC), or equivalent.
  • CISSP, CISM, or equivalent cybersecurity certification.
  • CRISC, ISO 27001-related certification, or equivalent risk/governance certification.
  • Relevant cloud security certifications for AWS, Microsoft Azure, or equivalent platforms.

Working Arrangement

  • Onsite at designated secure premises in Singapore, as required.
  • Work closely with system owners, infrastructure teams, cybersecurity teams, project teams, vendors, and contractors.
  • Compliance with all applicable security, confidentiality, and access control requirements is required.
  • Successful completion of the required security clearance is mandatory prior to commencement.

Skills

AWSAzureCybersecurityPenetration TestingRisk ManagementComplianceISO 27001CISSPCompTIA