Company Banner
Applied Internship Icon Internship Fresh Graduate Experienced Icon Fresh Grads & Experienced Latest Job

IT Security Analyst (Security Operations & Cybersecurity)

  • 2023-09-07

-

Singapore, Singapore

IT Security Analyst (Security Operations & Cybersecurity)

Job Description

Roles & Responsibilities

Responsibilities


a. Security Policy Planning and Standards

i. Maintain the security policies, frameworks/standards and procedures/processes in alignment with government regulations.

ii. Conduct regular briefing and training to internal staff and contractors on the latest security measures, vulnerabilities, and security trends.


b. Security Audit Management

i. Manage audit activities (Interna/External) and track and ensure all audit findings are duly closed.

ii. Manage compliance monitoring and improvement activities to ensure

conformance to ISO/IEC 27000 certification and regulatory compliance.


c. Cybersecurity Risk Management

i. Manage and ensure authorised access in alignment with the organisational, regulatory requirements. E.g. reviewing, approving, revoking access grants and maintaining exception tracking.

ii. Maintain risk register and track to ensure the risk items are mitigated and closed in accordance to stipulated timeline.

iii. Perform risk assessments for new projects and escalate key risks to Technology Management Team.


d. Security Change Control and Project Support

i. Manage change control for security-related aspects of project implementation or operational enhancements to ensure proper risk assessment has been performed.

ii. Support operational and project implementations, by providing security advice and guidance and ensure compliance to established framework, policies, and regulations.

iii. Identify projects’ security risks and come out with specific security requirements or mitigation measures to address the risks.

iv. Assist the project owners to evaluate vendors’ security solutions' and assess vendor’s security solution architecture and processes.


e. Security Operations Management

i. Assist in Security Operations Management to maintain the security infrastructure availability by tracking the performance of the Managed Security Services (MSS).

ii. Manage external vendors to provide the 24x7 support and track their

performance to ensure compliance to the SLA. Oversee and manage the detection and monitoring of cyber threats to the Company’s Information Technology Systems together with the Security Operation Centre.

iii. Manage Penetration Testing, Application Source Code Vulnerability Assessment and Vulnerability Assessment (VA) process, review and validate the assessment reports.

iv. Perform tirage and assessment of the criticality/impact and manage the tracking of security incidents together with Technology Infrastructure and Application teams.


Requirements:

• Degree in IT, Engineering or Science; or equivalent

• Possess diagnostic skills and recovery experience in IT infrastructure, systems and applications

• Minimum of 3 years’ working experience in supporting cybersecurity risk and controls management programs with good knowledge and experience of cybersecurity frameworks and regulatory requirements.

• Operational knowledge of security processes and standards in all security domains.

• High level knowledge of security audit and audit processes. Broad IT knowledge and experience a plus.

• Experience in the energy industry and/or public service is advantage.

Experience in ISO 27001, NIST Framework and Security by Design (SBD) Framework

• Understanding of Singapore Government security protocols and best practices

• Possess diagnostic skills and recovery experience in IT infrastructure, systems and applications.

• Excellent verbal communication skills and possess good vendor management skills.

• Good project management skills with the ability to lead and execute security risk and control projects and initiatives.


Tell employers what skills you have

Management Skills
Security Operations
Risk Assessment
Regulatory Compliance
Regulatory Affairs
ISO
Operations Management
Risk Management
Information Technology
ISO 27001
Penetration Testing
Audit Management
Public Service
Regulatory Requirements
Vulnerability Assessment
Audit

Beware of scams. Do NOT give personal information or money to unknown sources. Verify identity before acting. Report any suspected scams immediately. Stay informed and stay safe.

Company Logo

EXASOFT PTE. LTD.

Job Majestic Logo

© Copyright 2024 Agensi Pekerjaan JEV Management Sdn. Bhd., registered in Malaysia (Company No: 201701016948 (1231113-U), EA License No. JTKSM860)
© Copyright 2024 Job Majestic Sdn. Bhd., registered in Malaysia (Company No: 201701037852 (1252023-X))
All Rights Reserved.

Ask us