This 3-month project opportunity is part of the Social Service Reternship Programme, where our Reternees contribute their expertise to charities through a short-term project (Stipend-based, SGD 1,500/month). Upon project completion, both participant & charity will decide on longer-term arrangements if suitable. [Note: Participants of our Social Service Reternship Programme will be prioritised for this project]
About Project: Information Systems
The project focuses on strengthening the organization’s information security posture through strategic collaboration with IT and business stakeholders. It encompasses policy alignment with regulatory standards, staff education, solution sourcing, and operational support to foster a culture of security awareness and resilience. The project and daily support aim to foster a culture of security awareness while ensuring robust protection of organizational assets.
Job Responsibilities
- Collaborate with IT and Business stakeholders to align security initiatives with organizational goals.
- Review and align internal practices with regulatory and industry security frameworks such as ISO 27001 and AIC Health Information Bill.
- Develop and distribute EDMs to educate staff on Information Security policies and best practices.
- Research and source appropriate security solutions to strengthen the organization’s security posture.
- Monitor security alerts and threat intelligence to detect and respond to potential cyber threats.
- Conduct security awareness workshops or phishing campaigns and publish advisories to promote a security-first culture.
- Manage incident containment, eradication, and recovery to minimize impact and restore operations swiftly.
- Perform risk assessments on IT systems, networks, and applications, and implement controls to mitigate identified risks.
Deliverables
- Updated Information Security Policy or practices aligned with ISO 27001 and AIC HIB requirements.
- A series of educational EDMs covering key Information Security topics.
- Evaluation report or shortlist of recommended security solutions.
- Security advisories published on a regular basis.
- Incident response logs and reports for internal tracking and audit purposes.
Job Specifications
Minimum Education / Qualifications
Degree in Information systems or equivalent.
Minimum Years of Relevant Experience
5 or more years’ experiences in setting up and managing information security operations.
Knowledge/Skills
- Familiar with ISO27001 ISMS, NIST and/ or CIS frameworks.
- Experiences in incident handling and understanding in digital forensic investigation, tools and processes.
- Experiences in security protections, practices or solutions like Firewall, IDS/ IPS, DLP, WAF, NAC, WiFi security, encryption, patch management, etc.
- CISA, CISM, CISSP and/ or PMP certifications will be an advantage. Knowledgeable in Microsoft Office and other Windows and web applications.
Attributes (functional or leadership competencies)
- Meticulous and hands on.
- Excellent communication and written skills.
- Strong analytical and problem-solving skills.
- Team player with excellent interpersonal skills and multi-tasker.
- Customer-centric and proactive.