Search Jobs

Search by job, company or skills

Security Exposure Engineer 6 Months Contract

Security Exposure Engineer 6 Months Contract

ntt singapore pte. ltd.
6-9 Years
SGD 7,000 - 10,000 per month
  • Posted 8 hours ago
  • Be among the first 10 applicants

Job Description

Position: Detection Engineer - Cybersecurity

Employment Type: Contract

Contract Duration: 6 months

Work Location: Singapore

Job Description

We are seeking a hands-on cybersecurity professional with specialised experience across Security Exposure Management (SEM), External Attack Surface Management (EASM), Third-Party Cyber Risk/Assurance and Cyber Threat Intelligence (CTI).

The role will focus on continuously identifying external cyber exposures, assessing third-party security posture, validating material cyber threats and driving remediation across complex enterprise environments.

Key Responsibilities

  • Perform continuous external attack-surface discovery and monitoring of internet-facing assets, domains, subdomains, IP addresses, certificates, exposed services and cloud resources.
  • Identify unknown, unmanaged and externally exposed assets and validate material security exposures.
  • Analyse vulnerabilities and external exposures against exploitability and threat intelligence to determine actual organisational risk.
  • Conduct end-to-end cybersecurity assessments of third-party service providers, including inherent risk assessment, security questionnaires, evidence review, control validation, risk rating and residual-risk assessment.
  • Perform cybersecurity due diligence and continuous assurance of critical third parties.
  • Assess fourth-party/nth-party dependencies and cyber-risk propagation across the supply chain.
  • Conduct structured third-party assessments using SIG, CAIQ, VDD/ODD or equivalent methodologies.
  • Assess security controls against NIST CSF, ISO 27001 and CIS Controls.
  • Investigate emerging vulnerabilities, active exploitation, external threats, leaked credentials, impersonation and digital-risk indicators.
  • Correlate threat intelligence, vulnerability information, asset criticality and external exposure to prioritise remediation.
  • Validate clear-and-present-danger cyber threats affecting the organisation or critical third parties.
  • Develop cyber exposure, third-party posture, risk dashboards and management reporting.
  • Automate security monitoring, enrichment, assessment and reporting activities using Python, PowerShell and/or Bash.
  • Work with security engineering, infrastructure, cloud, risk and business stakeholders to drive identified risks through remediation and closure.

Essential Requirements

  • 3-5 years of hands-on cybersecurity experience with direct exposure to Security Exposure Management, EASM, Attack Surface Management or Digital Risk.
  • Hands-on experience conducting third-party/vendor cybersecurity assessments, beyond vendor coordination or procurement activities.
  • Experience conducting security questionnaires, evidence/control reviews, risk assessments and remediation tracking.
  • Practical understanding of third-party, fourth-party and nth-party cyber risk.
  • Experience with external attack-surface, cyber exposure, digital-risk or threat-intelligence platforms.
  • Strong vulnerability-management and risk-based prioritisation experience, including CVE, CVSS and actively exploited vulnerabilities.
  • Practical knowledge of NIST CSF, ISO 27001 and CIS Controls.
  • Strong understanding of TCP/IP, DNS, HTTP/HTTPS, TLS, APIs and internet-facing infrastructure.
  • Security exposure across AWS, Microsoft Azure and/or Google Cloud Platform.
  • Hands-on scripting/automation experience using Python, PowerShell and/or Bash.
  • Strong analytical, documentation, stakeholder-management and security-risk communication skills.

Relevant Technology Exposure

Hands-on experience with one or more of the following or equivalent technologies is highly desirable:

SecurityScorecard, BitSight, RiskRecon, CyCognito, Censys, Microsoft Defender EASM, Tenable Attack Surface Management, Palo Alto Cortex Xpanse, Recorded Future, Flashpoint, Mandiant Threat Intelligence, ZeroFox, watchTowr, ServiceNow GRC/IRM and RSA Archer.

Preferred Certifications

  • CompTIA Security+ / CySA+
  • CEH
  • GIAC GSEC / GCIH
  • CISSP / Associate of ISC2
  • CISM
  • ISO 27001 related certifications

Candidates should have demonstrable hands-on experience in external cyber exposure and/or third-party cybersecurity assessment. Experience limited primarily to SOC alert monitoring, SIEM operations, general IT audit, vulnerability scanning or vendor coordination without direct cyber-risk assessment experience may not meet the specialised requirements of this position.


Interested candidates are kindly requested to email their CV with their experience to [Confidential Information]

We look forward to your application!

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Liaising With Third Parties

Organisational Risk Management

data understanding

Asset Integrity Management

assessment systems