Zorky CRMZorky CRM
EN|RU
@termdocs
← All jobs

Cybersecurity Specialist

lead4,000 SGDSingapore, SGScore 72.5/100today
Market insights
📊 Security: salaries and demand on the market
Stack
Security OperationsVulnerability ScanningEmail SecurityOrganization & prioritization skillsCoverage AnalysisInfocomm Security and Data PrivacyInformation TechnologyAudit ComplianceTechnical AbilityEndpoint SecurityNetwork Securitycloud
Apply
Upload your CV — we will connect you with the employer directly through our pool.
Send your CV →
Description
Job Summary The Cybersecurity Specialist is the hands-on group focal point for cybersecurity operations, enterprise audit and certification management, information-security assurance, incident response and customer assurance. Reporting to the Head of IT, the role works across all group functions, legal entities and sites, and with Sales, technology teams, business leaders, auditors, certification bodies, customers and vendors. The role is the central owner and coordinator of the group-wide audit and certification programme. It leads the full lifecycle for internal, external, customer, regulatory, supplier, ISO and cybersecurity audits and certifications, including annual planning, scope definition, readiness assessment, evidence coordination, audit execution, finding management, corrective actions, surveillance and recertification. Functional and control owners remain responsible for operating their controls, providing evidence and implementing remediation. The role works closely with Sales, Account Management and Bid/Tender teams to interpret customer ISO and cybersecurity requirements, support tenders and due diligence, prepare accurate and approved responses, and participate in customer assurance discussions. It enables commercial progress without making unsupported claims, disclosing restricted evidence or accepting commitments without the required business, legal and technical approvals. The role combines practical cybersecurity expertise, audit discipline and commercial judgement. Lead audits, test controls, coordinate remediation, manage incidents and translate certification requirements into clear actions for management, customers and delivery teams. Key Responsibilities Security Operations and Monitoring Review and improve security monitoring across identity, endpoint, email, cloud, network, applications and critical third parties, tune use cases and escalation paths. Coordinate XDR/MDR and vendor alert triage, validate severity and evidence, manage escalations and ensure false positives/negatives inform tuning. Track threat intelligence and indicators relevant to the group, convert them into practical detections, blocks, checks or communications. Maintain security operational dashboards and daily/weekly oversight of material alerts, incidents, coverage gaps and overdue actions. Vulnerability, Configuration and Identity Risk Coordinate asset-based vulnerability scanning, triage, risk-based remediation targets, exception documentation and validation of closure. Review security configuration and exposure for endpoints, identity, email, cloud, networks, applications and digital solutions against approved baselines. Support least privilege, MFA, privileged-access controls, joiner/mover/leaver processes, service-account governance and periodic access reviews to all systems. Partner with technology owners to prioritise and verify remediation, escalate overdue or repeatedly deferred critical risk. Incident Response and Digital Forensics Coordination Maintain and activate incident-response policy, severity model, contact tree, playbooks, evidence procedures and communications/escalation requirements. Act as security incident coordinator or technical lead as directed, maintaining timeline, hypotheses, actions, evidence, containment options and stakeholder updates. Coordinate containment, eradication, recovery and validation with IT owners and qualified third parties while preserving evidence and chain of custody. Lead post-incident review, lessons learned and corrective-action tracking, support legal, privacy, insurer, regulator or law-enforcement engagement when authorised. Maintain and manage BCP procedures and communications/escalation requirements. Enterprise Audit, ISO and Certification Management Own and centrally coordinate the group-wide audit and certification programme across functions, legal entities, sites, systems and key third parties, covering internal, external, customer, regulatory, supplier, ISO and cybersecurity audits. Maintain the master audit and certification calendar, scope register, obligations register, responsible-owner matrix, readiness status, evidence plan, renewal dates, budget inputs and escalation milestones. Lead the end-to-end lifecycle for applicable ISO management-system and cybersecurity certifications, including scoping, gap assessment, implementation planning, internal audit, management review, certification, surveillance, recertification and approved scope expansion. Maintain the management-system and assurance artefacts required by applicable standards, including policies, objectives, risk assessments, control library, Statement of Applicability where required, document register, records, metrics and management-review inputs. Plan and perform, or coordinate qualified parties to perform, readiness reviews, internal audits, control testing and evidence sampling using a risk-based and documented approach. Act as the primary liaison for certification bodies, external auditors, regulators, customers and other assessors, coordinate scope, agendas, interviews, site activities, evidence requests, responses and factual clarification. Maintain a controlled, access-managed audit evidence repository with clear ownership, version control, retention, traceability and approval before external release. Record findings, nonconformities and observations, assign accountable owners and due dates, challenge weak root-cause analysis or corrective actions, verify effectiveness before closure, and escalate overdue or repeatedly deferred items to the Head of IT and relevant executives. Report audit readiness, certification health, open findings, ageing, recurring themes, residual risk and resource needs to leadership. Preserve audit integrity, avoid self-certification and ensure residual risk is accepted only by an authorised risk owner. Sales, Bids and Customer Assurance Act as the audit, ISO and cybersecurity assurance partner to Sales, Account Management and Bid/Tende
Employer contacts (email/phone/telegram) are hidden from the public preview — send your CV, and we will connect you directly.
Urgent question? Message @termdocs