跳到主要內容

IT Security Officer (ITSO)

00070356001

IT SECURITY OFFICER

The Senior IT Security Officer is responsible for providing cybersecurity governance, risk management, security assurance and security advisory across ICT systems, digital services, cloud platforms and infrastructure

The role works closely with system owners, application teams, infrastructure and cloud teams, cybersecurity operations, enterprise architects, project managers, vendors and management to ensure that security risks are identified early, controls are proportionate and effective, and systems are operated in accordance with applicable Government ICT&SS policies and standards, organisational requirements, contractual obligations and recognised cybersecurity good practices.

Key Responsibilities

Cybersecurity Governance and Risk Management

· Provide independent cybersecurity governance and advisory across the project and system lifecycle.

· Lead or review cybersecurity risk assessments, including threat identification, vulnerability analysis, attack-path considerations, inherent risk, residual risk, compensating controls and risk treatment plans.

· Ensure material security risks, deviations and exceptions are properly documented, justified, tracked, escalated and formally accepted by the appropriate risk owner when required.

· Monitor recurring control gaps, overdue remediation and systemic risks, and recommend programme-level corrective actions.

· Maintain clear security decision records, evidence and audit trails for governance and management assurance.

Security Architecture and Security-by-Design

· Review application, cloud, infrastructure, network, identity and integration architectures for security risks and control gaps.

· Assess trust boundaries, data flows, privileged access paths, external exposure, administrative interfaces, API integrations and dependency risks.

· Challenge security assumptions and ensure proportionate preventive, detective and recovery controls are included before production implementation.

· Advise teams on secure design patterns for authentication, authorisation, encryption, secrets, logging, segmentation, resilience and least privilege.

· Participate in architecture review boards, design reviews, go-live readiness reviews and security acceptance decisions.

Cloud, Identity and Platform Security

· Assess cloud security designs and configurations across AWS, Microsoft Azure and/or Google Cloud, including IAM, network controls, workload protection, encryption, key management, logging and monitoring.

· Review identity and access management controls including MFA, privileged access, RBAC, service accounts, workload identities, conditional access and access lifecycle management.

· Assess Zero Trust, ZTNA, remote access, endpoint security and security service integrations where applicable.

· Evaluate security implications of SaaS, managed services, containers, Kubernetes and other modern platform technologies.

Vulnerability Management, VA/PT and Security Testing

· Review vulnerability findings and determine practical risk, remediation priority and required treatment based on business context and exploitability.

· Track remediation against applicable service levels and escalate overdue or repeated high-risk findings.

· Define or review security testing requirements, including vulnerability assessment, penetration testing, application security testing, configuration review and other assurance activities.

· Review test reports, validate remediation evidence and challenge inappropriate risk acceptance or weak compensating controls.

· Support secure development practices by reviewing relevant SAST, DAST, SCA, API security and CI/CD security evidence where applicable.

Security Operations and Incident Response

· Work with SOC and security operations teams to ensure appropriate logging, telemetry, alerting, detection use cases and escalation paths exist for critical systems.

· Participate in or coordinate cybersecurity incident response, investigation, containment, eradication, recovery and lessons-learned activities as required.

· Translate incident findings and adversary techniques into preventive improvements, detection requirements and remediation actions.

· Assess emerging vulnerabilities, CVEs and threat intelligence to determine applicability and priority for systems within the assigned portfolio.

· Support cyber exercises, tabletop exercises and operational readiness testing.

Cyber Resilience and Recovery

· Review cybersecurity aspects of business continuity, disaster recovery, backup, restoration and ransomware resilience arrangements.

· Assess recovery dependencies, privileged recovery paths, backup protection, immutability and recovery test evidence.

· Participate in disaster recovery and cyber resilience exercises and ensure security lessons are tracked to closure.

Stakeholder Management, Reporting and Leadership

· Act as a trusted cybersecurity advisor to project teams, system owners, business stakeholders and senior management.

· Explain complex cybersecurity risks in clear business language and recommend practical options for decision-making.

· Prepare concise management reports covering key risks, vulnerabilities, incidents, audit findings, remediation progress and security posture.

· Mentor junior ITSOs and contribute to consistent security assessment methods, templates, playbooks and standards across the organisation.

· Escalate material risks objectively and maintain independence when reviewing solutions or risk acceptance requests.

Minimum Requirements

· Minimum 7 years of relevant IT or cybersecurity experience, with substantial experience in cybersecurity governance, risk management, security assurance, architecture, operations, cloud security, audit or security consulting.

· At least 3 years of experience independently reviewing or governing enterprise-scale systems, major ICT projects or government/public-sector environments.

· Demonstrated ability to conduct or critically review cybersecurity risk assessments and recommend proportionate technical and governance controls.

· Strong understanding of enterprise security architecture across applications, infrastructure, networks, cloud, identity and security operations.

· Experience working with technical teams, project management, auditors, vendors and senior stakeholders.

· Strong written and verbal communication skills, including the ability to produce clear risk statements, security recommendations, management papers and audit responses.

· Ability to work independently, exercise professional judgement and escalate material risk where necessary.

· Relevant degree in Cybersecurity, Information Systems, Computer Science, Engineering or a related discipline; equivalent professional experience may be considered.

Professional Certifications

The candidate should possess at least one current recognised professional cybersecurity certification. Suitable certifications include:

· CISSP - Certified Information Systems Security Professional

· CISM - Certified Information Security Manager

· CRISC - Certified in Risk and Information Systems Control

· CISA - Certified Information Systems Auditor

· CCSP - Certified Cloud Security Professional

· CGEIT - Certified in the Governance of Enterprise IT

· Relevant GIAC certifications or equivalent professional cybersecurity certifications

Framework and Standards Knowledge

The Senior ITSO should have practical working knowledge of relevant frameworks and be able to apply them proportionately rather than as a checklist. Useful knowledge includes:

· Applicable Singapore Government ICT&SS cybersecurity policies, standards, control requirements and agency-specific security directives.

· ISO/IEC 27001 and ISO/IEC 27002.

· NIST Cybersecurity Framework and relevant NIST SP 800-series guidance.

· CIS Controls and CIS Benchmarks.

· MITRE ATT&CK for understanding adversary tactics and techniques.

· OWASP guidance for web application and API security.

· Cloud security good practices and shared-responsibility principles.

· Applicable legal, regulatory and data-protection requirements, including PDPA and sector-specific obligations where relevant.


关于高知特 (Cognizant)
高知特(Cognizant)(纳斯达克代码:CTSH)作为一家AI Builder和相关技术服务提供商,致力于通过打造全栈AI解决方案,帮助企业将人工智能投资转化为实际价值。公司凭借深厚的行业经验、流程优化和工程技术专长,将企业独特的业务场景融入科技系统,赋能组织释放人才潜能,推动切实成果,并帮助全球企业在瞬息万变的环境中保持领先。如需了解更多详情,敬请访问 cognizant.ai 或关注@cognizant。

补充雇佣信息
薪酬信息截至本职位发布之日为准。Cognizant 保留在适用法律允许的范围内随时修改该信息的权利。
申请人可能需要通过现场面试或视频会议的方式参加面试。此外,候选人在每次面试时可能需要出示其当前所在州或政府签发的有效身份证件。
Cognizant 是一家提供平等就业机会的雇主。在招聘过程中,您的申请和候选资格不会因种族、肤色、性别、宗教、信仰、性取向、性别认同、国籍、残疾、遗传信息、怀孕、退伍军人身份或任何其他受联邦、州或地方法律保护的特征而受到影响。

帮助您蓬勃发展与成长的福利

我们的福利计划以您为中心打造——帮助您享受充实、平衡且健康的生活。
有葉子的植物的藍色線條圖

财务健康

我们会定期审查市场数据,确保薪酬体现您所带来的价值。您的福利不仅限于薪资,还可能包括退休计划、财务教育等。

Stay Healthy Midnight Blue RGB

身心健康

我们通过带薪休假、在条件允许下的灵活工作安排、医疗保障计划、心理咨询、心理健康盟友计划等,赋能您将身心健康放在首位。

Build The Career You Want Midnight Blue RGB

您的职业发展,由您做主

在 Cognizant 提供的 35 万多个岗位中,您将有机会探索新的技术、行业和工作地点,并打造推动职业发展的关键技能。

Making A Meaningful Impact Midnight Blue RGB

现实世界的影响力

想想您所依赖的那些知名品牌。很可能,他们也依赖我们来帮助强化其业务。在这里,您将把大胆的想法转化为改善全球生活的解决方案。

还没有找到合适的机会吗?

获取为您量身定制的最新职位机会、招聘活动和公司新闻!

掌握最新动态