Website:
user.com.sg
Job details:
Position Overview
We are seeking a Cybersecurity VM & NIS2 Compliance Analyst to support Vulnerability Management (VM) and NIS2 compliance initiatives across global operations. This role is responsible for aligning vulnerability management processes with NIS2 cybersecurity requirements, supporting compliance readiness, and driving continuous improvement of cybersecurity risk management practices.
The ideal candidate has hands-on experience in vulnerability management, cybersecurity compliance, security assessments, and regulatory frameworks such as NIS2. This role requires close collaboration with global security teams across APAC, EMEA, and US regions in a rotational support model.
Key Responsibilities
- Support the implementation and maintenance of NIS2 compliance activities across cybersecurity operations.
- Maintain and continuously improve the mapping between Vulnerability Management (VM) processes and NIS2 cybersecurity controls, including:
- Cybersecurity risk management
- Vulnerability identification and remediation
- Incident handling
- Business continuity
- Supply chain security
- Assist in security assessments, compliance reviews, evidence collection, and audit documentation.
- Support regulatory readiness by maintaining compliance documentation and technical evidence.
- Perform vulnerability analysis and prioritize remediation using the CVSS scoring framework and vulnerability vectors.
- Support vulnerability detection, assessment, tracking, and mitigation following cybersecurity best practices.
- Contribute to the maturity and continuous improvement of the organization's Threat & Vulnerability Management program.
- Produce cybersecurity dashboards, metrics, and compliance reports for management and stakeholders.
- Collaborate with infrastructure, security operations, governance, and application teams to ensure timely vulnerability remediation.
- Participate in cross-functional cybersecurity initiatives supporting regulatory compliance and operational resilience.
- Assist with incident reporting readiness and documentation aligned with NIS2 expectations.
- Support ongoing process improvements to strengthen cybersecurity governance and compliance.
Mandatory Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.
- 3+ years of experience in Cybersecurity, Vulnerability Management, Information Security, or Cybersecurity Compliance.
- Hands-on experience supporting NIS2 compliance programs, regulatory readiness, or cybersecurity governance initiatives.
Good understanding of the NIS2 Directive, including:
- Cybersecurity governance
- Risk management measures
- Incident reporting expectations
- Operational resilience
- Experience conducting:
- Security assessments
- Compliance assessments
- Evidence collection
- Compliance documentation
- Stakeholder reporting
Strong understanding of Vulnerability Management lifecycle, including:
- Vulnerability identification
- Risk analysis
- Prioritization
- Remediation tracking
- Experience applying the CVSS scoring methodology for vulnerability risk assessment.
- Knowledge of Threat & Vulnerability Management best practices.
- Strong analytical skills with experience in cybersecurity reporting and data analysis.
- Excellent written and verbal communication skills.
- Ability to work collaboratively with global teams across multiple regions.
Click on Apply to know more.