int(10654)
Singapore, Singapore

IT Security Analyst

Our Client is a brokerage firm with a footprint spanning across various countries in Asia and they are looking to hire an IT security analyst under a newly created headcount within their technology team.

The IT Security analyst will oversee cyber governance and risk management, including the development and implementation of security policies and standards. This role encompasses ensuring compliance with industry regulations and standards, coordinating penetration testing, and tracking the remediation of vulnerabilities. Responsibilities also include identifying and assessing cyber risks, maintaining user awareness, coordinating security training, serving as a key contact for senior management and regulatory inquiries, managing the remediation of audit findings, and conducting disaster recovery exercises.

Please contact Oliver Lim on +65 93662912 or email your cv directly in word format with job reference no. JOB-12691 to Oliver@theedgepartnership.com

Please note that due to the high number of applications only shortlisted candidates will be contacted. If you do not hear from us in the next 5 business days we regret to inform you that your application for this position was unsuccessful.

EA Licence: 16S8131

Recruiter Licence: R1657051

Apply for this Job

Key responsibilities

  • Oversee cyber governance and risk management.
  • Create, manage, and enforce the security policy framework and relevant standards.
  • Ensure security governance and compliance with industry and regulatory standards (e.g., ISO27001, NIST, MAS TRMG, MAS Outsourcing guideline, MAS Cyber hygiene).
  • Coordinate penetration testing to meet local regulatory requirements and report significant security risks to relevant forums.
  • Track the remediation status of identified vulnerabilities.
  • Identify and evaluate cyber risks, recommend, and implement cybersecurity solutions and initiatives.
  • Maintain user cyber awareness and provide advice on emerging security threats and vulnerabilities.
  • Organize security awareness training programs for staff.
  • Serve as the primary contact for inquiries from senior management and regulatory bodies, including internal and external audit exams.
  • Ensure all audit findings are addressed and independently verified within agreed timelines.
  • Conduct annual disaster recovery exercises with internal and external parties.
  • Regularly assess existing infrastructure, systems, and applications for compliance and vulnerabilities.
  • Develop and implement identity and access management policies and procedures.
  • Monitor and audit user access activities for compliance and security.
  • Manage user access rights and permissions across systems and applications.
  • Monitor security alerts and incidents, investigate, and respond to security breaches.
  • Manage security incidents according to established protocols, maintain security incident response plans and playbooks.
  • Develop, maintain, and manage the Business Continuity Program, coordinating efforts across all department operations into a single plan, ensuring compliance with regulatory requirements, industry standards, and Risk Management requirements.
  • Conduct thorough due diligence on all third parties to ensure compliance with MAS outsourcing guidelines and operational risk management guidelines.

Role requirements

  • Minimum of 5 years of experience in information security
  • Knowledgeable about MAS Technology Risk Management Guidelines, MAS Cyber Hygiene Notice, and MAS Outsourcing Guidelines
  • Strong problem-solving and analytical skills
  • Familiarity with SIEM tools such as Splunk and vulnerability assessment tools like Tenable Nessus
  • Excellent oral, written, presentation, and interpersonal skills.
  • Ability to thrive under pressure and perform effectively in a fast-paced environment.
  • Professional security certifications (CISSP, CISA, CEH, etc.) are preferred.
  • Undergraduate degree or technical certificate required; graduate degree preferred.