ITSO(IT Security Officer)
Avensys is a reputed global IT professional services company headquartered in Singapore. Our service spectrum includes enterprise solution consulting, business intelligence, business process automation and managed services. Given our decade of success, we have evolved to become one of the top trusted providers in Singapore and service a client base across banking and financial services, insurance, information technology, healthcare, retail and supply chain.
We are currently looking to hire ITSO. This is an exciting opportunity to expand your skill set, achieve job satisfaction and work-life balance. More details as below.
Job Description
Vulnerability Management
- Assist in vulnerability scanning and assessments toidentify security weaknesses within the client’s environment.
- Help prioritize and track remediation efforts based on theseverity and impact of vulnerabilities.
- Collaborate with internal teams to ensure that identifiedvulnerabilities are mitigated in a timely manner.
- Provide regular vulnerability reports and updates to theSenior IT Security Manager.
Firewall Rules Review and Management
- Support the periodic review of firewall rules to ensureproper access control and network segmentation.
- Work closely with network and infrastructure teams toassess and adjust firewall configurations as needed to enhance security.
- Assist in ensuring that firewall rules comply withinternal policies and regulatory requirements.
Audit Support
- Assist in preparing for and supporting internal andexternal security audits.
- Provide documentation, logs, and reports to auditors andensure timely responses to audit requests.
- Help track and resolve audit findings, ensuring correctiveactions are implemented to meet compliance requirements.
- Support the maintenance of audit trails for criticalsecurity events and activities.
Identity and Access Management (ID Validation)
- Assist with user identity validation processes, ensuringproper authentication mechanisms are in place.
- Support the enforcement of access control policies toensure that only authorized personnel have access to sensitive data andsystems.
- Help monitor and audit user access rights, ensuring theyalign with role-based access controls and least privilege principles.
Security Awareness Training
- Assist in the development and delivery of securityawareness training programs for client employees and internal teams.
- Help create educational materials to raise awareness aboutcommon cybersecurity threats (e.g., phishing, social engineering).
- Track training progress and ensure all employees areregularly updated on security best practices.
- Support client-facing initiatives to promote a culture ofcybersecurity within the organization.
Security Advisory Support
- Provide support for security advisory services bygathering information on emerging threats and vulnerabilities.
- Assist the Senior IT Security Manager in providingrecommendations for mitigating risks associated with new and emerging securitythreats.
- Help maintain a repository of security advisories,updates, and patches, ensuring timely distribution to relevant stakeholders.
Incident Response
- Support the investigation and response to securityincidents, gathering data and providing initial analysis.
- Help escalate security incidents and assist indocumentation and resolution.
- Participate in post-incident reviews to identify lessonslearned and areas for process improvement.
Risk Management and Compliance
- Help in conducting risk assessments to identify potentialsecurity risks and recommend mitigation strategies.
- Assist with ensuring the client’s environment remainscompliant with industry standards and regulations.
- Contribute to the maintenance of security policies,procedures, and controls to ensure compliance and mitigate risks.
Collaboration and Communication
- Work closely with other IT Security team members toimplement and enforce security policies and practices.
- Communicate effectively with internal teams and clientstakeholders about security status, risks, and incidents.
- Provide support in preparing reports, presentations, andsecurity briefings for senior management and clients.
Continuous Learning and Improvement
- Stay up-to-date on the latest trends in cybersecurity,including new tools, vulnerabilities, and attack techniques.
- Participate in ongoing professional development to expandsecurity knowledge and skills.
- Assist in identifying and implementing improvements toexisting security processes, policies, and tools.
Qualifications
Education:
- Bachelor’s degree in Information Technology,Cybersecurity, Computer Science, or related field.
- Relevant certifications such as CISM, CISA, CompTIASecurity+, Certified Ethical Hacker (CEH), or equivalent are a plus.
- Min 2 years of experience in IT security, cybersecurity,or a related field.
- Hands-on experience or familiarity with vulnerabilityscanning tools, firewall rule configurations, and identity management systems.
- Experience or exposure to supporting security audits andcompliance processes.
- Familiarity with network security concepts, SIEM systems,and basic incident response protocols is a plus.
- Understanding of IT security principles and bestpractices.
- Basic knowledge of security tools such as firewalls,antivirus software, IDS/IPS, and SIEM systems.
- Familiarity with security frameworks (e.g., NIST, ISO27001, CIS Controls).
- Strong analytical and troubleshooting skills.
- Good written and verbal communication skills.
- Ability to work effectively in a team and manage tasks ina dynamic environment.
WHAT’S ON OFFER
You will be remunerated with an excellent base salary and entitled to attractive company benefits. Additionally, you will get the opportunity to enjoy a fun anPrimary Purpose
To submit your application, please apply online or email your UPDATED CV in Microsoft Word format to khalid@aven-sys.com. Your interest will be treated with strict confidentiality.