IT Security Officer (ITSO)
Job description
About the Role
We are seeking an Information Technology Security Officer to support cybersecurity governance, assurance, and security management activities across the organisation. This role will be involved in key cybersecurity functions including security architecture, vulnerability assessment and penetration testing (VAPT), risk assessment, system hardening, cloud security posture management, software security clearance, firewall and network security governance, cybersecurity policies and standards, and security reporting.
You will work closely with internal stakeholders, project teams, infrastructure teams, vendors, and cybersecurity professionals to coordinate security reviews, track remediation activities, maintain cybersecurity records, and support compliance with organisational policies and regulatory requirements.
This role is suitable for candidates at the Associate Consultant, Consultant, or Senior Consultant level who possess strong analytical, coordination, documentation, and stakeholder management skills, along with a solid understanding of cybersecurity governance and risk management practices.
Job Responsibilities
Security Architecture
- Support the maintenance of security architecture diagrams, records, and approved design documentation.
- Coordinate security architecture review requests and engage relevant project teams and stakeholders.
- Maintain records of architecture decisions, recommendations, and approved designs.
- Assist in preparing security advisory materials and architecture review documentation.
Vulnerability Assessment & Penetration Testing (VAPT)
- Coordinate VAPT engagements with system owners, vendors, and security testing teams.
- Maintain vulnerability trackers and follow up on remediation activities.
- Coordinate re-testing activities and monitor closure of identified findings.
- Support the preparation of VAPT reports, summaries, and presentation materials.
Cybersecurity Risk Management
- Coordinate cybersecurity risk assessment activities with system owners and stakeholders.
- Maintain risk registers and track remediation and risk treatment actions.
- Support the preparation of risk reports and management review materials.
- Facilitate risk acceptance, exception handling, and approval processes.
Security Hardening & Compliance
- Coordinate security hardening assessments with infrastructure and system teams.
- Track remediation of hardening gaps and monitor compliance progress.
- Maintain hardening records, checklists, and reporting artefacts.
- Prepare periodic compliance reports and status updates.
Cloud Security Posture Management
- Monitor and triage findings from Cloud Security Posture Management (CSPM) tools.
- Track cloud security findings and coordinate remediation efforts with relevant stakeholders.
- Maintain records of cloud security findings and remediation status.
- Prepare regular cloud security posture reports and summaries.
Software Security Clearance
- Manage software security clearance requests and associated documentation.
- Coordinate with requestors and vendors to obtain required security information.
- Maintain software security clearance registers and approval records.
- Support software security evaluations and monitor clearance expiry dates.
Firewall & Network Security Governance
- Track firewall rule change requests and network security deviation requests.
- Coordinate with requestors and network teams on outstanding security actions.
- Maintain firewall and network deviation registers.
- Support periodic reviews of firewall rules and network security exceptions.
Cybersecurity Policies, Standards & Governance
- Assist in drafting, reviewing, and updating cybersecurity policies, standards, guidelines, and procedures.
- Maintain cybersecurity documentation repositories.
- Track document review cycles, approvals, and expiry dates.
- Support the development and review of cybersecurity specifications for projects, procurements, and tenders.
Security Metrics & Reporting
- Consolidate cybersecurity data from various teams and systems.
- Maintain dashboards covering vulnerabilities, risks, compliance, audit findings, and remediation activities.
- Prepare cybersecurity metrics, reports, and management presentations.
- Follow up with stakeholders on outstanding security actions and remediation items.
Security & Compliance Support
- Support cybersecurity assessments, audits, and evidence collection activities.
- Ensure activities are carried out in accordance with applicable policies, standards, and regulatory requirements.
- Maintain accurate cybersecurity records, registers, reports, and supporting documentation.
- Handle sensitive and confidential information in accordance with security requirements.
Job Requirements
Required Skills & Experience
- Diploma or Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, or a related discipline.
- Good understanding of cybersecurity concepts, including:Vulnerability managementSecurity risk assessmentSystem hardeningFirewall and network security controlsCloud securityCybersecurity governance
- Experience coordinating cybersecurity reviews, assessments, remediation activities, or security governance processes involving multiple stakeholders.
- Ability to review and interpret:Vulnerability assessment reportsSecurity risk assessmentsSecurity architecture documentationFirewall and network security controlsCompliance and audit reports
- Familiarity with cybersecurity frameworks, standards, policies, and governance practices.
- Strong analytical, organisational, documentation, and stakeholder management skills.
- Good written and verbal communication skills.
Preferred Skills
- Familiarity with CSPM platforms and cloud security concepts within AWS, Microsoft Azure, or comparable cloud environments.
- Experience with vulnerability management tools, VAPT activities, and interpretation of CVE/CVSS ratings.
- Understanding of enterprise network architecture, security zones, network segmentation, and firewall management.
- Experience supporting cybersecurity governance, risk, compliance, or audit-related activities.
Preferred Certifications
Candidates with one or more of the following certifications will have an advantage:
- CompTIA Security+
- ISC2 Certified in Cybersecurity (CC)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- ISO 27001-related certifications
- Microsoft Azure Security certifications
- AWS Security certifications
- Other relevant cybersecurity certifications
Working Arrangement
- Based onsite at designated secure premises in Singapore as required by project needs.
- Collaborate closely with system owners, infrastructure teams, cybersecurity teams, project teams, vendors, and contractors.
- Must comply with applicable security, confidentiality, and access control requirements.
- Employment is subject to the successful completion of any required security clearance processes.
Skills mentioned
Apply for this job
Use the application link supplied with this listing to apply to CAPGEMINI SINGAPORE PTE. LTD.. Check the destination before entering personal information.

