IT Security Officer

About the job

About the IT Security Officer role

The IT Security Officer is responsible for strengthening application and cloud security by identifying, assessing, and mitigating cybersecurity risks across digital platforms and projects. This role performs threat modelling, establishes threat profiles, manages vulnerability remediation activities, and ensures security best practices are integrated throughout the software development lifecycle. Working closely with development, DevOps, and infrastructure teams, the officer supports secure application design, automated security testing, and cloud security initiatives while promoting compliance with industry standards such as OWASP. The role also delivers security awareness training, provides security advisory support to stakeholders, and helps maintain a strong security posture across enterprise systems and cloud environments.

Key Responsibilities:

  • Experience in threat modelling and able to establish threat profiles for application projects to identify, quantify and remediate application security risks
  • Track and address security vulnerabilities with timely remediation and patching processes
  • Conduct security awareness training sessions

Requirements:

  • At least 4 years combined work experience in software development, application security and cloud computing (e.g. AWS)
  • Familiar with mobile and web application programming interfaces (API) architecture (e.g. REST, SOAP, SSL/TLS)
  • Strong knowledge of security best practices such as OWASP Top 10, OWASP application security verification standard
  • Familiar with Agile Development process, CI/CD, DevOps concepts, tools (Gitlab, Github, Ansible etc) and how automated security testing can be incorporated into CI/CI pipelines
  • Experience on using SAST code scanning tools such as Fortify-on-Demand, Sonarqube, etc
  • Good verbal/written communications, collaboration skills and experience interacting with various stakeholders
  • Strong analytical, problem-solving and troubleshooting skills, ability to work independently
  • Relevant certifications preferred (eg. CISSP, OSCP, AWS security, AWS DevOps Engineer or equivalent etc.)
  • Experience in working with Government Commercial Cloud (GCC) preferred

Search Popup

Help me find…

This will close in 0 seconds