IT Security Officer (ITSO)

FLARE CONSULTING PTE. LTD.Singaporemycareersfuturepublished 10/08/2026
Must-have:AWSAzureCloudSecuritySenior

About the role Our client, runs critical digital systems that handle sensitive data. The ITSO is the security point of contact for assigned systems, making sure they meet government security policy across their full lifecycle. You will work with project teams, vendors and the agency's cybersecurity office to assess risk, enforce controls and drive remediation, from design through to operations and audit. Key responsibilities Act as IT Security Officer for assigned systems, ensuring compliance with the Government Instruction Manual on ICT & Smart Systems Management (IM8) and agency security policies. Conduct security risk assessments, threat and risk analysis (TRA) and security design reviews for new systems and major changes. Review and approve security requirements, architecture and controls with project teams and vendors. Plan and manage Vulnerability Assessment and Penetration Testing (VAPT); track findings through to remediation and closure. Maintain security documentation: system security plans, risk registers, waivers and residual risk acceptance. Coordinate internal and external IT audits and compliance checks, prepare evidence and manage audit findings. Monitor security posture, including patching, access reviews, privileged account management and logging. Support security incident response, investigation and reporting in line with government incident management procedures. Advise on cloud security controls for systems hosted on Government Commercial Cloud (GCC) and on-premise environments. Promote security awareness and secure-by-design practices across project and operations teams. Requirements Must have Degree in Computer Science, Information Security or a related field. 6+ years in IT or cybersecurity, with at least 3 years in security governance, risk and compliance. Hands-on experience with security risk assessments, VAPT management and audit remediation. Good understanding of network, application, infrastructure and cloud security controls. Familiarity with security frameworks and standards such as ISO 27001, NIST CSF and CIS Controls. Strong stakeholder management; able to work with vendors, project teams and senior management. Clear written communication for security reports, risk papers and audit responses. Good to have Prior ITSO or security role in Singapore public sector, with working knowledge of IM8. Professional certifications: CISSP, CISM, CISA, CRISC or CCSP. Experience securing AWS / Azure workloads, especially on GCC. Familiarity with SIEM, EDR, PAM and vulnerability management tools.