Cybersecurity Specialist

🗓️ Posted 2026-08-11 Jurong Island And Bukom, West Region Full-time Hybrid ICT

Company shared salary

NA

Market rate

S$8,000–S$12,000/mo (S$96,000–S$144,000/yr)

Based on similar roles (title + domain + location).

About the Company

Meranti Power Pte Ltd, a fully owned subsidiary of Energy Market Authority, manages and operates a new power generation station on Jurong Island.

Responsibilities

  • Manage security incident response activities, including 24/7 investigations, containment, and remediation.
  • Detect, analyse, and correlate Indicators of Compromise (IoCs) across security logs, systems, and networks to identify potential threats.
  • Support incident response operations and handle additional assigned tasks as required.
  • Oversee the patch management process and ensure timely remediation of vulnerabilities.
  • Conduct vulnerability assessments and monitor the remediation status of identified risks.
  • Maintain user cybersecurity awareness and provide advisory support on emerging threats and vulnerabilities.
  • Develop, review, and enhance IT security training materials; conduct regular user training to improve security readiness and incident response capability.
  • Oversee the Incident Response Plan (IRP), Disaster Recovery Plan (DRP), Business Continuity Plan (BCP), and Cyber Crisis Plan (CCP).
  • Provide independent IT & OT cyber risk management guidance to business, technical, and operations teams to ensure secure technology implementation.
  • Conduct OT & IT risk assessments, document findings, and track remediation actions.
  • Identify, assess, and manage technology and emerging risks, proposing effective mitigating controls.
  • Manage cyber risk analysis and self-assessment programmes across systems, processes, and services in line with industry standards.
  • Ensure compliance with security, regulatory (CSA's CCoP and EMA's Transmission Code), privacy, and contractual cyber requirements.
  • Define and implement controls to meet regulatory (CSA's CCoP and EMA's Transmission Code), legislative, and industry-specific compliance obligations.
  • Manage third-party cyber risk assessment standards and oversee vendor/contractor performance.
  • Drive the implementation and adoption of GRC tools, including ESG risk management.
  • Oversee IT and OT security projects, evaluating proposed solutions and monitoring vendor performance.
  • Ensure secure System Development Life Cycle (SDLC) practices are followed by business and technology units, not limited to software or hardware licenses.
  • Conduct security audits and perform gap analysis to strengthen cyber controls.
  • Identify and assess technology risks in projects and change requests, ensuring implementation of effective security controls.
  • Develop and maintain cybersecurity and IT & OT risk management policies, standards, vendor management frameworks, and system criticality classifications.
  • Collaborate with risk owners to proactively manage risks and reduce the impact of incidents, breaches, or compliance issues.
  • Recommend, implement, and drive cybersecurity initiatives to enhance the organisation's cyber posture.
  • Prepare, draft, review, and manage Approval of Requirement (AOR), tender documents, Request for Proposal (RFP), Request for Quotation (RFQ), technical specifications, and procurement-related documentation in accordance with organisational, regulatory, and cybersecurity requirements.
  • Coordinate with internal stakeholders, technical teams, and vendors.