jobs in RiDiK (a Subsidiary Of CLPS. Nasdaq: CLPS)

Kerja Sepenuh Masa, Senior Information Technology Security Officer di RiDiK (a Subsidiary Of CLPS. Nasdaq: CLPS) - Maukerja

Senior Information Technology Security Officer

RiDiK (a Subsidiary Of CLPS. Nasdaq: CLPS)

Singapore

Kongsi
Simpan

Lokasi Kerja

  • Singapore

Penerangan Kerja

Tanggungjawab

IT Security Officer – OT / ICS Cybersecurity

Location: Singapore

Experience: 5+ Years


Job Overview


We are looking for an experienced IT Security Officer – OT/ICS Cybersecurity to protect the integrity, availability, and confidentiality of critical operational technology infrastructure supporting meteorological services.


The role will bridge cybersecurity expertise with operational technology and environmental monitoring systems, ensuring that weather observation, forecasting, data processing, and dissemination platforms remain secure, resilient, and compliant with applicable national and international cybersecurity standards.


The ideal candidate will have strong hands-on experience in OT/ICS/SCADA security, SIEM, vulnerability management, incident response, network architecture, and critical infrastructure cybersecurity. Experience with meteorological, remote sensing, satellite, radar, or environmental monitoring systems will be highly advantageous.


Key Responsibilities

OT Asset Discovery & Architecture Mapping

Conduct passive and non-disruptive discovery of OT assets across meteorological networks without impacting live operations.

Maintain a comprehensive OT Asset Register covering hardware, firmware, software, network connectivity, and system ownership.

Identify and flag shadow, unmanaged, and unauthorized devices.

Review, document, and maintain IT/OT network architecture and topology diagrams.

Identify and risk-rate OT-to-IT connectivity, remote access paths, vendor interfaces, and network boundary crossings.

Map operational data flows between OT and IT environments to identify potential lateral attack paths and security weaknesses.

Maintain the OT Asset Register and IT/OT Architecture Map as the baseline for vulnerability management, risk assessments, and incident response.

Security Operations & Monitoring

Monitor and protect OT environments supporting critical meteorological systems, including:

Doppler Weather Radar systems

Satellite Ground Stations

Upper-Air Sounding Systems

Automated Weather Observation Systems (AWOS)

Weather observation and forecasting infrastructure

Operate and maintain SIEM, IDS/IPS, EDR and other security monitoring technologies.

Detect, investigate, and respond to cybersecurity threats and anomalies across hybrid IT/OT environments.

Work closely with the CISO and infrastructure teams to implement critical security patches and remediation measures.

Investigate and manage security incidents, coordinating with national CERT teams and relevant agency stakeholders when required.

Risk Management & Compliance

Conduct regular cybersecurity risk assessments across meteorological data acquisition, processing, and dissemination pipelines.

Assess risks associated with OT infrastructure, network connectivity, remote access, vendors, and data flows.

Ensure compliance with relevant cybersecurity frameworks and standards, including:

NIST SP 800-82

FISMA

IEC 62443

ICS/SCADA security standards

Agency-specific cybersecurity policies

Maintain and test Continuity of Operations Plans (COOP) and disaster recovery procedures.

Support business continuity and operational resilience for critical weather services.

Vulnerability & Patch Management

Coordinate vulnerability assessments, security audits, vulnerability scans, and penetration testing activities.

Identify and prioritize vulnerabilities based on operational and business risk.

Manage security patch cycles in coordination with system and infrastructure engineers.

Balance cybersecurity requirements with the 24/7/365 availability requirements of mission-critical meteorological services.

Ensure changes and remediation activities do not negatively impact operational systems.

Vendor & Supply Chain Security

Assess cybersecurity risks associated with third-party hardware, software, sensors, data feeds, and vendor-supplied processing systems.

Review security requirements for technology vendors and data partners.

Support the implementation and enforcement of cybersecurity requirements within vendor contracts.

Assess remote vendor access and third-party connectivity to OT environments.

Security Awareness & Training

Develop and deliver cybersecurity awareness training tailored to OT and meteorological operational environments.

Educate technical and non-technical stakeholders on OT-specific cybersecurity threats and best practices.

Act as the primary OT cybersecurity subject matter expert for the division.

Required Qualifications

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline.

Minimum 5 years of experience in IT/OT cybersecurity, OT security, ICS/SCADA security, or a closely related field.

Experience working in critical infrastructure, government, utilities, industrial, scientific, or mission-critical environments is preferred.

Strong hands-on experience with:

SIEM platforms

IDS/IPS

EDR/security monitoring tools

Vulnerability management

Incident response

Network security

OT asset discovery and inventory

Experience with OT/ICS network architecture, segmentation, and secure remote access.

Strong understanding of cybersecurity risk management and incident response processes.

Active government security clearance or ability to obtain the required level of security clearance.

Preferred Qualifications

Experience securing SCADA, ICS, PLC, DCS, or other OT environments.

Knowledge of NIST SP 800-82, IEC 62443, FISMA, and related cybersecurity frameworks.

Experience in critical infrastructure or 24/7 mission-critical operational environments.

Familiarity with meteorological systems, weather radar, satellite ground stations, remote sensing, or environmental monitoring infrastructure.

Knowledge of World Meteorological Organization (WMO) standards and international weather data-sharing protocols.

Experience with hybrid cloud security environments, including AWS and Azure Government.

Experience working with national CERTs, government agencies, or regulated environments.

Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut