IT Security Officer (ITSO)
- Hiring from
- Singapore
- Work type
- Hybrid
- Posted
538,387 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
IT Security Officer (ITSO)
00070356001
- Date published Oct 05 2026
- Location Singapore,SG / Singapore
- Job category Technology & Engineering
- Work model Hybrid
IT SECURITY OFFICER
The Senior IT Security Officer is responsible for providing cybersecurity governance, risk management, security assurance and security advisory across ICT systems, digital services, cloud platforms and infrastructure
The role works closely with system owners, application teams, infrastructure and cloud teams, cybersecurity operations, enterprise architects, project managers, vendors and management to ensure that security risks are identified early, controls are proportionate and effective, and systems are operated in accordance with applicable Government ICT&SS policies and standards, organisational requirements, contractual obligations and recognised cybersecurity good practices.
Key Responsibilities
Cybersecurity Governance and Risk Management
· Provide independent cybersecurity governance and advisory across the project and system lifecycle.
· Lead or review cybersecurity risk assessments, including threat identification, vulnerability analysis, attack-path considerations, inherent risk, residual risk, compensating controls and risk treatment plans.
· Ensure material security risks, deviations and exceptions are properly documented, justified, tracked, escalated and formally accepted by the appropriate risk owner when required.
· Monitor recurring control gaps, overdue remediation and systemic risks, and recommend programme-level corrective actions.
· Maintain clear security decision records, evidence and audit trails for governance and management assurance.
Security Architecture and Security-by-Design
· Review application, cloud, infrastructure, network, identity and integration architectures for security risks and control gaps.
· Assess trust boundaries, data flows, privileged access paths, external exposure, administrative interfaces, API integrations and dependency risks.
· Challenge security assumptions and ensure proportionate preventive, detective and recovery controls are included before production implementation.
· Advise teams on secure design patterns for authentication, authorisation, encryption, secrets, logging, segmentation, resilience and least privilege.
· Participate in architecture review boards, design reviews, go-live readiness reviews and security acceptance decisions.
Cloud, Identity and Platform Security
· Assess cloud security designs and configurations across AWS, Microsoft Azure and/or Google Cloud, including IAM, network controls, workload protection, encryption, key management, logging and monitoring.
· Review identity and access management controls including MFA, privileged access, RBAC, service accounts, workload identities, conditional access and access lifecycle management.
· Assess Zero Trust, ZTNA, remote access, endpoint security and security service integrations where applicable.
· Evaluate security implications of SaaS, managed services, containers, Kubernetes and other modern platform technologies.
Vulnerability Management, VA/PT and Security Testing
· Review vulnerability findings and determine practical risk, remediation priority and required treatment based on business context and exploitability.
· Track remediation against applicable service levels and escalate overdue or repeated high-risk findings.
· Define or review security testing requirements, including vulnerability assessment, penetration testing, application security testing, configuration review and other assurance activities.
· Review test reports, validate remediation evidence and challenge inappropriate risk acceptance or weak compensating controls.
· Support secure development practices by reviewing relevant SAST, DAST, SCA, API security and CI/CD security evidence where applicable.
Security Operations and Incident Response
· Work with SOC and security operations teams to ensure appropriate logging, telemetry, alerting, detection use cases and escalation paths exist for critical systems.
· Participate in or coordinate cybersecurity incident response, investigation, containment, eradication, recovery and lessons-learned activities as required.
· Translate incident findings and adversary techniques into preventive improvements, detection requirements and remediation actions.
· Assess emerging vulnerabilities, CVEs and threat intelligence to determine applicability and priority for systems within the assigned portfolio.
· Support cyber exercises, tabletop exercises and operational readiness testing.
Cyber Resilience and Recovery
· Review cybersecurity aspects of business continuity, disaster recovery, backup, restoration and ransomware resilience arrangements.
· Assess recovery dependencies, privileged recovery paths, backup protection, immutability and recovery test evidence.
· Participate in disaster recovery and cyber resilience exercises and ensure security lessons are tracked to closure.
Stakeholder Management, Reporting and Leadership
· Act as a trusted cybersecurity advisor to project teams, system owners, business stakeholders and senior management.
· Explain complex cybersecurity risks in clear business language and recommend practical options for decision-making.
· Prepare concise management reports covering key risks, vulnerabilities, incidents, audit findings, remediation progress and security posture.
· Mentor junior ITSOs and contribute to consistent security assessment methods, templates, playbooks and standards across the organisation.
· Escalate material risks objectively and maintain independence when reviewing solutions or risk acceptance requests.
Minimum Requirements
· Minimum 7 years of relevant IT or cybersecurity experience, with substantial experience in cybersecurity governance, risk management, security assurance, architecture, operations, cloud security, audit or security consulting.
· At least 3 years of experience independently reviewing or governing enterprise-scale systems, major ICT projects or government/public-sector environments.
· Demonstrated ability to conduct or critically review cybersecurity risk assessments and recommend proportionate technical and governance controls.
· Strong understanding of enterprise security architecture across applications, infrastructure, networks, cloud, identity and security operations.
· Experience working with technical teams, project management, auditors, vendors and senior stakeholders.
· Strong written and verbal communication skills, including the ability to produce clear risk statements, security recommendations, management papers and audit responses.
· Ability to work independently, exercise professional judgement and escalate material risk where necessary.
· Relevant degree in Cybersecurity, Information Systems, Computer Science, Engineering or a related discipline; equivalent professional experience may be considered.
Professional Certifications
The candidate should possess at least one current recognised professional cybersecurity certification. Suitable certifications include:
· CISSP - Certified Information Systems Security Professional
· CISM - Certified Information Security Manager
· CRISC - Certified in Risk and Information Systems Control
· CISA - Certified Information Systems Auditor
· CCSP - Certified Cloud Security Professional
· CGEIT - Certified in the Governance of Enterprise IT
· Relevant GIAC certifications or equivalent professional cybersecurity certifications
Framework and Standards Knowledge
The Senior ITSO should have practical working knowledge of relevant frameworks and be able to apply them proportionately rather than as a checklist. Useful knowledge includes:
· Applicable Singapore Government ICT&SS cybersecurity policies, standards, control requirements and agency-specific security directives.
· ISO/IEC 27001 and ISO/IEC 27002.
· NIST Cybersecurity Framework and relevant NIST SP 800-series guidance.
· CIS Controls and CIS Benchmarks.
· MITRE ATT&CK for understanding adversary tactics and techniques.
· OWASP guidance for web application and API security.
· Cloud security good practices and shared-responsibility principles.
· Applicable legal, regulatory and data-protection requirements, including PDPA and sector-specific obligations where relevant.
Additional employment information
Compensation information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
Applicants may be required to attend interviews in person or by video conference. In addition, candidates may be required to present their current state or government issued ID during each interview.
Cognizant is an equal opportunity employer. Your application and candidacy will not be considered based on race, color, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, state or local laws.
Applicants for US based positions must be currently authorized to work for any employer in the United States. The company is unable to provide employment-based immigration sponsorship for US based positions.
If you have a disability that requires reasonable accommodation to search for a job opening or submit an application, please email CareersNA2@cognizant.com for roles based in the Americas or CareersIndia2@cognizant.com for roles based in India.
About Cognizant:
Cognizant (Nasdaq: CTSH) is an AI Builder and technology services provider, bridging the gap between AI investment and enterprise value by building full-stack AI solutions for our clients. Our deep industry, process and engineering expertise enables us to build an organization’s unique context into technology systems that amplify human potential, drive tangible outcomes and keep global enterprises ahead in a fast-changing world. See how at cognizant.ai or @cognizant.
Benefits that help you thrive and grow
Our benefits program is built with you in mind—so you can enjoy a fulfilling, balanced and healthy life.
Financial wellbeing
We regularly review market data to ensure compensation reflects the value you bring. Your benefits extend beyond pay and may include retirement plans, financial education, etc.
Physical and mental health
We empower you to prioritize your wellbeing through paid time off, flexible working where possible, healthcare plans, counselling, our Mental Health Allyship program and more.
Your career, your way
With 350,000+ roles at Cognizant, you’ll have opportunities explore new technologies, industries and locations—and build the skills you need to grow your career.
Real-world impact
Think about the biggest brands you rely on. Chances are, they rely on us to help strengthen their business. Here, you’ll turn bold ideas into solutions that improve lives everywhere.
Your path to Cognizant
Here’s what you can expect from our hiring process. Please keep in mind that it may vary by role and location. Explore our FAQs to learn more.
Step 1: Apply to the right opportunity
Find an open role that matches your skills and career goals and show us why you’re the person for the job. Don’t see the right opportunity? Consider joining our Talent Community.
Step 2: Connect with your recruiter
If one of our recruiters sees a fit, they’ll set up a short intro call to learn more about you and how your experiences and skills match the role.
Step 3: Show off your skills
If you and our team would like to continue the process, you’ll interview with our hiring team. Some roles may also require technical assessments and/or client interviews.
Step 4: Decision time
Our team will then review each candidates’ potential to succeed in the role. This step may take some time because we want to find the right fit for both you and us—but you can count on us to keep you updated.
Cognizant has one of the best learning ecosystems you can ask for. From sponsored certifications to training platforms to mentorship, we have all that we need to grow.Debashish Mishra SAP MM Developer
Cognizant offers me more than a job; it offers a community. We support each other, collaborate across borders and celebrate wins together. If you’re looking for a culture that values flexibility, diversity and growth, this is the place to be.Laura Reynaud Lead Counsel
When I first joined, I was quiet and hesitant to share my thoughts. The leadership programs and the mentoring I’ve received have helped me find my voice and grow as a leader.Sujatha Gopalakrishnan Portfolio Delivery Lead
I’ve had the chance to work on impactful projects and shadow colleagues, all while getting involved in internal initiatives. The world is your oyster at Cognizant—you just need to take advantage of it!Lucas Hoffman Consultant
Haven't yet found the right opportunity?
Get the latest updates on job opportunities, recruitment events and company news—tailored just for you!
Be in the know