Role Overview
We are looking for an
IT Security Officer
specializing in
Vulnerability Management and IT Risk Management
to support a hybrid on-premises and AWS environment.
The role will own the vulnerability management lifecycle, maintain the IT Risk Register, drive remediation and risk acceptance activities, and provide risk-based recommendations to technical and business stakeholders.
Key Responsibilities
Manage the end-to-end
vulnerability management lifecycle
across on-premises and AWS environments.
Run and manage vulnerability scans using tools such as
Tenable/Nessus, Qualys or Rapid7
.
Review vulnerability findings, assess their impact and prioritize remediation based on
CVSS and business/technical context
.
Track remediation activities with infrastructure and application SMEs and escalate overdue vulnerabilities.
Maintain the
IT Risk Register
and ensure risks, owners, treatment plans and status are current.
Prepare and coordinate
Risk Acceptance
for vulnerabilities or risks that cannot be remediated within the required timeframe.
Work with technical and business stakeholders to obtain risk acceptance approvals and periodically review accepted risks.
Review vendor security advisories and determine their applicability and potential impact to the environment.
Monitor security-update compliance for
AV/EDR, IDS/IPS and similar security controls
.
Prepare vulnerability and risk management dashboards/status reports for management.
Work across Security, Infrastructure, Cloud and Application teams to drive remediation and risk reduction.
Required Skills
3–5+ years of experience in Vulnerability Management, IT Security or Risk Management.
Hands-on experience with
Tenable/Nessus, Qualys, Rapid7 or equivalent vulnerability scanning tools
.
Strong understanding of
CVSS and risk-based vulnerability prioritization
.
Practical experience managing
Risk Registers and Risk Acceptance processes
.
Strong experience in vulnerability remediation tracking and coordination with technical SMEs.
Good understanding of
on-premises infrastructure security
covering servers, network devices and endpoints.
Working knowledge of
AWS security and the shared responsibility model
, particularly EC2, S3, RDS, IAM and services such as Security Hub, GuardDuty and Inspector.
Strong stakeholder management and communication skills.
Preferred
Experience with
GRC tools
such as ServiceNow GRC or RSA Archer.
Knowledge of
NIST CSF, NIST 800-53 or ISO 27001
.
Relevant certifications such as
Security+, CySA+, CISSP, CRISC or AWS Security Specialty
.
Experience supporting security/risk management in a hybrid cloud environment or managed-services/customer environment.
SAGL Consulting
was established in year 2016 by group of experienced head-hunters in Singapore. The founders realised the need for an executive search firm with sole focus on technology recruitment and works on the recruitment practices suited for it.
The firm was set up to bring top IT recruiters together who have passion to get the best talents for their clients.The recruitment practice in the firm is designed to create a strong network of technology professionals and leaders.We give utmost importance to keep the candidate information confidential and provide consultancy for career progression.
We use the agile methodology of recruitment and have adopted AI powered solutions for getting the best talents in the market. But always keeping the human touch first to give you true experience of boutique recruitment.