Central Provident Fund Board
In CPF Board, we believe in achieving our mission and vision through motivated people who are committed to learn, upgrade and innovate.
People are important. Therefore, we create opportunities for our staff to develop their potential through our well-structured training & career development programme. We have also in place an attractive remuneration and benefits package.
We are looking for highly motivated, talented and committed professionals to join us in our mission to enable Singaporeans save for a secure retirement. If you have the relevant working experience, take up the challenge and apply today.
People are important. Therefore, we create opportunities for our staff to develop their potential through our well-structured training & career development programme. We have also in place an attractive remuneration and benefits package.
We are looking for highly motivated, talented and committed professionals to join us in our mission to enable Singaporeans save for a secure retirement. If you have the relevant working experience, take up the challenge and apply today.
Security Consultant (IT Governance & Penetration Testing)
jobsDB Ref. JSG400003003628448
Employer Ref. 6428046
Responsibilities:
- Keep abreast of Information/Cyber Security landscape and work with industry to evaluate potential security solutions, including product evaluations, pilots and proof of concept
- Review system design to identify IT Security risks and provide mitigation measures
- Develop and maintain Baseline Security Standards (BSS) for servers, databases, network devices and monitoring tools
- Conduct periodic BSS compliance assessment against servers, databases, network equipment and monitoring tools
- Conduct Penetration Test, Source Code Vulnerability Assessment and Vulnerability Assessment (VA)
- Review threat intelligence reports to identify threats and take appropriate actions to improve the security posture
- Assist Technical Project Manager to manage the implementation and operation of Information Security projects
Requirements:
- At least 2-4 years of relevant experience in area of IT security and network domains: VPN, firewall, network/user authentication, intrusion detection, disk/file encryption, vulnerability assessment/mitigation, risk assessments, platform hardening, network switches and routers
- Practical experience in conducting security assessments using commercial and open-source host-scanning tools, network-scanning tools, application and database vulnerability assessment tools
- Good knowledge of industry best practices and frameworks pertaining to IT Controls (IM8, MAS TRM Guideline, ISO27001/2 etc.)
- Preferably has experience in two or more of the following tools: (BurpSuite, Qualys, AppScan, Fortify, Solarwinds, Nessus, Nexpose, Tripwire etc.)
- Preferably possess one or more appropriate IT security certifications, such as CISSP, CISM, CRISC, CEH, OWASP, GPEN, GWAPT, OCSP, CSSLP
- Excellent interpersonal, presentation and communication skills
- Position will be on a 2 years contract