IT Security Officer (Application Security, DevSecOps & Cloud Security))
CMC Global · Raffles Place, Central Region ·
- Work mode
- Onsite
- Employment
- Full time
- Category
- Security
- Experience
- 5+ years
- Salary
- SGD 3,500 – 5,000 / month
CMC Global · Raffles Place, Central Region ·
CMC-APAC PRIVATE LIMITED · Singapore
USER Experience Researchers · Singapore
SCIENTEC CONSULTING PTE. LTD. · Singapore
User Experience Researchers Pte.Ltd · Singapore
An IT Security Officer (consultant level) who identifies and manages cybersecurity risks across applications, systems, infrastructure and cloud services. Day to day involves security architecture reviews, risk assessments, threat modeling, vulnerability remediation tracking, incident response, and security awareness training, using AWS, OWASP standards and DevSecOps tooling like GitLab, GitHub, An
Salary: $3,500 – $5,000 per month
About the role
IT Security Officer at Consultant level responsible for identifying, assessing, and managing cybersecurity risks across applications, systems, infrastructure and cloud services.
Key responsibilities
Review system architecture, data flows, interfaces, APIs, internet-facing entry points and security controls to identify potential security risks
Conduct cybersecurity risk assessments for new and existing IT systems, applications, infrastructure and cloud services
Develop threat profiles for application projects to identify, quantify and remediate application security risks
Review remediation plans and supporting evidence to verify that security risks have been adequately addressed
Track and address security vulnerabilities with timely remediation and patching and closure in accordance with established requirements
Monitor and investigate cybersecurity alerts and incidents, including malware, phishing, account compromise, data breaches, unauthorised access, and cloud security incidents
Perform cybersecurity incident response and management, including incident triage, investigation, containment, remediation, recovery, and post-incident review
Conduct security awareness training sessions to promote security awareness and good cybersecurity practices
About you
At least 5 years combined work experience in software development, application security and cloud computing (e.g. AWS)
Good understanding of mobile and web application architectures, including APIs and related technologies and protocols such as REST, SOAP and SSL/TLS
Strong knowledge of application security principles and industry best practices, including the OWASP Top 10 and OWASP Application Security Verification Standard (ASVS)
Familiar with Agile development, CI/CD and DevSecOps practices, including tools such as GitLab, GitHub and Ansible, and the integration of automated security testing into CI/CD pipelines
Experience using SAST code scanning tools such as Fortify-on-Demand, Sonarqube, etc
Good verbal and written communications, collaboration skills and experience interacting with various stakeholders
Strong analytical, problem-solving and troubleshooting skills, ability to work independently
Degree in a relevant discipline, or an equivalent qualification
Relevant professional certifications such as CISSP, OSCP, CCSP, CRISC, AWS security certification or equivalent are preferred
Experience in working with Government Commercial Cloud (GCC) preferred
ScienTec Consulting · Central Region