Information Security Engineer (VA/PT)
3500 - 6000 SGDHelius Technologies Pte Ltd
Role: Information Security (Vulnerability Management and Penetration Testing)
Responsibilities
The role's responsibilities span three core areas: program management and governance across the combined function, day-to-day vulnerability management, and end-to-end penetration testing.
Program Management & Governance
• Build, run, and continuously improve the internal Vulnerability Management and Penetration Testing (VMPT) program and capabilities within the organization.
• Develop and refine the policies, processes, standards, and procedures for vulnerability management, penetration testing, communication, and reporting.
• Lead the triage of vulnerabilities and penetration test findings, taking into consideration compensating controls, threat exposure, and "True Risk" to Singlife, and prioritize remediation accordingly.
• Chair the vulnerability and penetration testing governance forum, driving accountability, tracking remediation SLAs, and escalating overdue or high-risk items to management.
• Manage the internal VMPT program and relationships with external VMPT/PT vendors and other stakeholders across Singlife.
• Establish and report meaningful metrics and dashboards on vulnerability and penetration testing posture, remediation progress, and program effectiveness to management and relevant committees.
• Identify gaps in adjacent processes and procedures and drive improvements from a risk-based vulnerability management (RBVM) and penetration testing perspective.
• Research, develop, and recommend appropriate tooling required for effective risk-based vulnerability management and penetration testing.
• Produce high-quality oral and written work products, presenting complex technical matters and findings clearly and concisely.
• Collaborate with supervisors and other cybersecurity team members on vulnerability management and penetration testing status and findings.
• Mentor and guide the technical development of junior VMPT staff and colleagues.
• Collaborate with stakeholders across the organization on security initiatives.
• Ensure compliance with all applicable laws and regulations relating to the above functional activities.
• Operate and maintain compliance with security baseline governance using appropriate tooling.
Vulnerability Management
• Own and manage the end-to-end vulnerability management process, from discovery and triage through remediation tracking, verification, and closure.
• Identify gaps in RBVM processes and procedures and drive continuous improvement.
• Build and lead the security review and monitoring of production environments across the hybrid infrastructure.
Penetration Testing
• Own and manage the end-to-end penetration testing program, from scoping and rules of engagement through execution oversight, findings management, retesting, and closure with external PT vendors and internal stakeholders.
• Define and maintain the annual, risk-based penetration testing plan, covering test types such as external and internal network, web and mobile application, API, cloud, wireless, social engineering, and red/purple team exercises.
• Set and enforce penetration testing standards, methodologies, and rules of engagement (e.g., OWASP, PTES, NIST SP 800-115, MITRE ATT&CK), and assure the quality, coverage, and independence of internal and vendor-delivered testing.
• Validate and retest remediated penetration test findings to confirm effective closure, and track exceptions and residual risk to acceptance or resolution.
• Ensure penetration testing satisfies regulatory and industry requirements (e.g., MAS TRM), and coordinate independent, threat-led and scenario-based testing where required.
Requirements
• Minimum 7 years of relevant security experience.
• Extensive experience in information security and/or IT risk management.
• Proven experience owning and running a vulnerability management and/or penetration testing program, process, and governance forum.
• Demonstrated leadership, project, and team-building skills, including the ability to lead teams and drive projects and initiatives across multiple departments.
• Ability to identify risks associated with business processes, operations, information security programs, and technology projects.
• Ability to communicate with diverse audiences, both technical and non-technical, to build consensus on risk-based vulnerability management and penetration testing.
• Experience with process optimization.
• Experience with process automation and workflow using ITSM tools.
• Hands-on experience with vulnerability management, penetration testing, and security engineering.
• Experience with industry-known vulnerability management, penetration testing, and CSPM solutions.
Vulnerability Management
• Strong knowledge of risk-based vulnerability management, including triage of vulnerabilities to determine "True Risk" exposure to Singlife.
• Experience in log configuration, formats, and feeding logs into SIEM platforms.
Penetration Testing
• Strong hands-on penetration testing background across multiple domains (network, web, mobile, API, and cloud), including managing external PT vendors and triaging and validating penetration test findings.
• Working knowledge of recognized penetration testing methodologies and frameworks (OWASP Testing Guide, PTES, NIST SP 800-115, MITRE ATT&CK) and common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Kali Linux, Cobalt Strike).
• Working knowledge of one or more programming/scripting languages such as Python, C++, Java, Ruby, Node, Go, and/or PowerShell.
Education
• Academic: Bachelor's degree in Computer Science or Information Technology (preferred).
• Professional Certification(s): One or more of CISSP, CISM, CISA, or SANS/GIAC certifications, together with a recognized penetration testing certification such as OSCP, GPEN, GWAPT, CREST (CRT/CCT), or CEH (preferred, or willing to become certified within one year).
If you are keen to explore the above role, please send across your updated resume to View email address on mycareersfuture.gov.sg and we can discuss to proceed further.
EA Personnel Registration Number: R1112410
Singapore Employment Agency Licence No: 11C3373
3500 - 4500 SGD
...We are looking for a IT Security Engineer proactive and technically skilled to join our Enterprise Information Security team. The ideal candidate will be responsible for implementing, maintaining, and enhancing cybersecurity controls to safeguard enterprise systems, applications...3500 - 5500 SGD
...ROLE: Information Security (Security Engineer) Responsibilities Security Measures Implementation and Performance Tracking o Develop and implement effective security measures to protect company data and network infrastructure. o Regularly track and report on the...8000 - 10000 SGD
...About the Role We are hiring a Senior Information Security Engineer to design, build, automate, operate, and continuously improve the security platforms that power modern Managed Security Services Provider (MSSP) Security Operations Centre services. This is a senior...10000 - 15000 SGD
...Position Summary: Our client is recruiting for a Sr. Staff Engineer, Information Security operating from our office in Singapore. This position will have the opportunity to participate in high impact projects on a global scale. The Information Security position will evaluate...5000 - 8500 SGD
...We are partnering a leading bank to hire a Information Security & Business Continuity (BCM) Consultant The Opportunity ~ Adecco is partnering... ...Management Dashboards/Security MIS related to Patching, VA, PT, Baselines and end point security controls, etc to support the...7000 - 12000 SGD
...critical digital infrastructure and help build secure, resilient and AI-enabled solutions that... ...become reality. Whether you're engineering intelligent networks, advancing sovereign... ...Make An Impact: Support comprehensive information security risk assessments for new and existing...6300 - 7700 SGD
...Join a high-impact cybersecurity team Gain exposure to leading security technologies and frameworks , About Our Client An... ...located in Singapore. Job Description Monitor and assess information security risks across systems and networks. Implement and manage...10000 - 14000 SGD
...and application onboarding while ensuring compliance with security and regulatory standards. Key Responsibilities• Manage... .... Qualifications• Bachelor's Degree in Computer Science, Information Technology, Engineering or related discipline.• Minimum 5 years' experience in Identity...13000 - 16000 SGD
...About the Role We are looking for an experienced Head of Site Reliability Engineering (SRE) & Information Security to lead our cloud infrastructure, DevOps, security, and reliability initiatives. The ideal candidate will have extensive experience designing and managing secure...5000 - 9500 SGD
...both group and local policies. It monitors the regional outsourcing framework and controls, supporting the Head of Compliance & Information Security as Data Protection Officer under Singapore’s Personal Data Protection Act (PDPA) for the MSIG Asia entity. Additionally, this...5500 - 6500 SGD
...in Planning, implementing, managing, monitoring, and upgrading security measures for the protection of the organization's data, systems... ...Requirements: ~ A degree/Diploma in Computer Science, IT, Systems Engineering, or related qualification. ~2 - 3 years of work experience...5500 - 6500 SGD
...Job Overview We are looking for a proactive Information Security professional to support enterprise IT security operations and infrastructureinitiatives across regional environments. This role will focus on strengthening cybersecurity operations, monitoring security threats...8500 - 10000 SGD
...Management: Serve as the primary point of contact for client security inquiries, presenting security metrics, risks, and proposed... ...plans Develop, implement, and maintain the firm's sustainable information security framework, policies, and risk management plans Operational...7000 - 8000 SGD
...We are seeking a self-motivated, authoritative Cyber & Information Security Manager to take ownership of our security ecosystem. You will... ...maturity and firmness required to enforce security policies across engineering and application teams. Highly hands-on with security...6500 - 12000 SGD
...The Strategy and Security PT/TS department (Sales and Customer Services for Mercedes-Benz Cars) takes care of key issues relating to IT... .../TST Cyber Security, Risk and Compliance team coordinates the information security-related topics for the market regions Europe, USA, China...- Senior Information Security Specialist Date: 4 Aug 2026 Location:Singapore, Singapore Company: Singtel Group An... ...security tools managed by CISO Singtel Singapore, Cyber Security Engineering ~Supporting and ensuring adequacy of Cyber Security posture...
5600 - 7000 SGD
...About the Role: We are seeking an experienced Senior Cyber Security Officer to lead and mature our enterprise security operations.... ...Required Qualifications: ~ Bachelor's degree in Computer Science, Information Security, or a related field. ~5+ years of hands-on...5000 - 6000 SGD
$5000 - $6000 Mon - Fri 9am-6pm Tiong Bahru Job description: This position will be responsible for managing all Information security projects of our clients, and this includes implementation of ISO 27001, Cybersecurity, Cloud Security, HIPPA, Privacy, and other security...3800 - 4000 SGD
...viewing, and software issues. 5) Conduct site surveys and system assessments to identify customer requirements and recommend suitable security system solutions. 6) Configure and maintain network infrastructure supporting access control and CCTV systems, including IP...5000 - 6000 SGD
..., efficacy and value. Lead detection engineering and proactive, intelligence-led threat hunting... ...MITRE ATT&CK framework. Shape our security telemetry and logging strategy,... ...Bachelor's degree in Computer Science, Information Security or a related field, or equivalent...15000 - 17500 SGD
...We are partnering with a leading services organisation to hire an experienced Senior Manager, Information Security to lead a team responsible for strengthening and protecting the organisation's cybersecurity capabilities. Responsibilities Lead, mentor, and develop a...4500 - 8500 SGD
...Patience and Knowledge of Systems engineering software tools Min 3 years of... ...-on experiences Familiar with Security Systems such as ISMS, CCTV, ACS and VA systems will be advantageous Familiar... ...has an added advantage Other Information: Location: Kaki Bukit or as...5000 - 8000 SGD
...ROLE OVERVIEW The Information Security Consultant is one of the most pivotal roles at Insyghts Security. This is a broad, high-impact position... ...engagements including network, web application, social engineering, and red team assessments. Findings are communicated clearly...- ...Job Description Implement and manage security measures to protect systems and networks... ...selected vendors for the assigned workstreams (VA, PT, Source Code Review, Risk Assessments,... ...Applicant A successful Cyber Security Engineer should have: A strong understanding of...
4900 - 6000 SGD
...systems. - Handle and follow up on Cyber Security Incident Management. - Conduct Cyber... ...standards. - Conduct Vulnerability Management (VA Scanning) on classified network computers... ...of appointment) - CISA — Certified Information Systems Auditor - CISM — Certified...14000 - 28000 SGD
...Job description Google's software engineers develop the next-generation technologies... ...users connect, explore, and interact with information and one another. Our products need to handle... ...design, networking and data storage, security, artificial intelligence, natural language...15000 - 19000 SGD
...As a Senior Associate, Technology, Information Security & Privacy Risk, you will play a key role in providing Technology, Information Security and Privacy Risk management expertise globally for the Institutional Division. Partnering with Country Risk Owners, Material Risk Theme...8000 - 9500 SGD
...Job Description We are seeking an experienced Information Technology Engineer to design, develop, and manage enterprise-scale AI-driven data platforms supporting security operations, business intelligence, and operational analytics. The successful candidate will play...7000 - 9000 SGD
...Information Security Analyst - Financial Services Job Summary Responsible for cyber governance, risk management, and security operations... ...degree in Computer Science, Information Technology, Engineering, or equivalent Preferred CISSP, CISA, or CEH certification...2000 - 2600 SGD
Responsibilities: Prepare and serve a variety of hot and cold beverages, including coffee, tea, and specialty drinks, to a high standard. Operate coffee machines and other equipment with care and precision. Ensure consistent quality of drinks by following recipes and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Engineer (VA/PT). Be the first to apply!
