Security Exposure Engineer 6 Months Contract
ntt singapore pte. ltd.- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
Position: Detection Engineer - Cybersecurity
Employment Type: Contract
Contract Duration: 6 months
Work Location: Singapore
Job Description
We are seeking a hands-on cybersecurity professional with specialised experience across Security Exposure Management (SEM), External Attack Surface Management (EASM), Third-Party Cyber Risk/Assurance and Cyber Threat Intelligence (CTI).
The role will focus on continuously identifying external cyber exposures, assessing third-party security posture, validating material cyber threats and driving remediation across complex enterprise environments.
Key Responsibilities
- Perform continuous external attack-surface discovery and monitoring of internet-facing assets, domains, subdomains, IP addresses, certificates, exposed services and cloud resources.
- Identify unknown, unmanaged and externally exposed assets and validate material security exposures.
- Analyse vulnerabilities and external exposures against exploitability and threat intelligence to determine actual organisational risk.
- Conduct end-to-end cybersecurity assessments of third-party service providers, including inherent risk assessment, security questionnaires, evidence review, control validation, risk rating and residual-risk assessment.
- Perform cybersecurity due diligence and continuous assurance of critical third parties.
- Assess fourth-party/nth-party dependencies and cyber-risk propagation across the supply chain.
- Conduct structured third-party assessments using SIG, CAIQ, VDD/ODD or equivalent methodologies.
- Assess security controls against NIST CSF, ISO 27001 and CIS Controls.
- Investigate emerging vulnerabilities, active exploitation, external threats, leaked credentials, impersonation and digital-risk indicators.
- Correlate threat intelligence, vulnerability information, asset criticality and external exposure to prioritise remediation.
- Validate clear-and-present-danger cyber threats affecting the organisation or critical third parties.
- Develop cyber exposure, third-party posture, risk dashboards and management reporting.
- Automate security monitoring, enrichment, assessment and reporting activities using Python, PowerShell and/or Bash.
- Work with security engineering, infrastructure, cloud, risk and business stakeholders to drive identified risks through remediation and closure.
Essential Requirements
- 3-5 years of hands-on cybersecurity experience with direct exposure to Security Exposure Management, EASM, Attack Surface Management or Digital Risk.
- Hands-on experience conducting third-party/vendor cybersecurity assessments, beyond vendor coordination or procurement activities.
- Experience conducting security questionnaires, evidence/control reviews, risk assessments and remediation tracking.
- Practical understanding of third-party, fourth-party and nth-party cyber risk.
- Experience with external attack-surface, cyber exposure, digital-risk or threat-intelligence platforms.
- Strong vulnerability-management and risk-based prioritisation experience, including CVE, CVSS and actively exploited vulnerabilities.
- Practical knowledge of NIST CSF, ISO 27001 and CIS Controls.
- Strong understanding of TCP/IP, DNS, HTTP/HTTPS, TLS, APIs and internet-facing infrastructure.
- Security exposure across AWS, Microsoft Azure and/or Google Cloud Platform.
- Hands-on scripting/automation experience using Python, PowerShell and/or Bash.
- Strong analytical, documentation, stakeholder-management and security-risk communication skills.
Relevant Technology Exposure
Hands-on experience with one or more of the following or equivalent technologies is highly desirable:
SecurityScorecard, BitSight, RiskRecon, CyCognito, Censys, Microsoft Defender EASM, Tenable Attack Surface Management, Palo Alto Cortex Xpanse, Recorded Future, Flashpoint, Mandiant Threat Intelligence, ZeroFox, watchTowr, ServiceNow GRC/IRM and RSA Archer.
Preferred Certifications
- CompTIA Security+ / CySA+
- CEH
- GIAC GSEC / GCIH
- CISSP / Associate of ISC2
- CISM
- ISO 27001 related certifications
Candidates should have demonstrable hands-on experience in external cyber exposure and/or third-party cybersecurity assessment. Experience limited primarily to SOC alert monitoring, SIEM operations, general IT audit, vulnerability scanning or vendor coordination without direct cyber-risk assessment experience may not meet the specialised requirements of this position.
Interested candidates are kindly requested to email their CV with their experience to [Confidential Information]
We look forward to your application!
More Info
Key Skills
Liaising With Third Parties
Organisational Risk Management
data understanding
Asset Integrity Management
assessment systems
