Be wary of WhatsApp messages impersonating Jobline Resources's staff offering job opportunities. Those who encounter suspicious messages can contact Jobline at +65 6339 7198

Responsibilities

Vulnerability Management 
  • Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services) 
  • Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership 
  • Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions 
  • Track remediation status and escalate overdue items per defined SLAs 

Risk Register & Risk Acceptance 
  • Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data 
  • Draft Risk Acceptance forms for identified risks that cannot be immediately remediated 
  • Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances 
  • Periodically review accepted risks for continued validity and reassessment 

Security Operations Oversight 
  • Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment 
  • Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment 
  • Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems 

Impact & Risk Analysis 
  • Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores 
  • Contextualise CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritisation 
  • Provide risk-based recommendations to stakeholders to support remediation prioritization decisions 

Reporting & Communication 
  • Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review 
  • Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding 

Requirements

  • Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience) 
  • 3–5+ years of experience in IT security operations, vulnerability management, or risk management 
  • Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7) 
  • Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM) 
  • Solid understanding of on-premises infrastructure security (servers, network devices, endpoints) 
  • Strong understanding of CVSS scoring methodology and practical risk-based prioritization 
  • Experience developing and managing Risk Registers and Risk Acceptance documentation 
  • Excellent stakeholder management and communication skills, with ability to work cross-functionally 

Shortlisted candidate will be offered a 1 year direct contract employment.