Job Description - Head of Vulnerability & Exposure Management
We are seeking an experienced cybersecurity leader to lead and evolve the organisation's Vulnerability and Exposure Management capabilities across a complex enterprise technology environment.
The role will be responsible for strengthening how the organisation identifies, prioritises and remediates security vulnerabilities and exposures across infrastructure, applications, cloud and emerging technology environments.
We welcome candidates from Vulnerability Management, Exposure Management, Cyber Defence, Security Engineering, Offensive Security or related cybersecurity backgrounds who have experience leading enterprise-scale security programmes.
Key Responsibilities
Define and drive the organisation's Vulnerability and Exposure Management strategy and roadmap.
Lead vulnerability identification, assessment, prioritisation and remediation across infrastructure, applications and cloud environments.
Improve visibility of the organisation's attack surface and security exposures across complex technology environments.
Drive a risk-based approach to vulnerability management, considering exploitability, threat intelligence, business criticality and potential impact.
Partner with Technology, Engineering and Security teams to drive timely remediation and sustainable risk reduction.
Leverage threat intelligence, security analytics and automation to improve vulnerability prioritisation and remediation.
Work with penetration testing, offensive security and other security teams to validate vulnerabilities and identify potential attack paths.
Establish appropriate standards, governance, KRIs/KPIs and management reporting for vulnerability and exposure management.
Drive continuous improvement of security processes, technologies and automation to reduce remediation time and recurring vulnerabilities.
Provide senior-level communication on cyber exposures, remediation priorities and security posture.
Build, lead and develop a high-performing cybersecurity team.
Requirements:
Significant experience in Cybersecurity, with leadership experience in Vulnerability Management, Exposure Management, Cyber Defence, Security Engineering, Offensive Security or related areas.
Strong understanding of vulnerability management and remediation within large and complex technology environments.
Experience with some of the following areas would be highly valuable:
Vulnerability Management
Attack Surface Management
Cloud Security / Cloud Exposure
Threat Intelligence
Penetration Testing / Offensive Security
Attack Path Analysis
Security Analytics and Automation
Experience driving risk-based vulnerability prioritisation rather than relying solely on vulnerability severity or scanning results.
Strong understanding of enterprise cybersecurity and technology risk.
Experience working with Technology and Engineering teams to drive remediation and security improvements.
Strong stakeholder management skills with the ability to communicate technical cyber risks to senior leadership.
Experience within financial services or another large, regulated or technology-intensive organisation would be advantageous.
Relevant cybersecurity certifications such as CISSP, CISM, CRISC, SANS or Offensive Security certifications are advantageous.
What We Are Looking For:
We are open to candidates from a broader cybersecurity background who have strong vulnerability management foundations and are looking to lead the evolution towards a more proactive, threat-informed Exposure Management approach.
You do not need to have held the formal title of "Head of Exposure Management". Candidates who have led Vulnerability Management, Cyber Defence, Security Engineering, Attack Surface Management or Offensive Security programmes and can demonstrate strong enterprise-level leadership are encouraged to apply.
How to Apply
Interested candidates, please apply by sending your CV to .
Pam Lim
Morgan Mckinley Pte Ltd
EA Licence No: 11C5502 | EAP Registration No: R1106192
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Singapore.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Singapore, connecting you to thousands of jobs fast!
Find the best jobs in Singapore, apply in 1 click and get a job today!