Lead BAU vulnerability management operations, including vulnerability scanning/discovery, findings triage, remediation SLA tracking, closure follow-up and periodic reporting.
Oversee asset coverage and inventory alignment to ensure vulnerability management activities are applied consistently across relevant technology assets.
Drive maturity of the DAST testing programme, including onboarding of applications, scan configuration, troubleshooting, authenticated scanning, testing cadence and control improvements.
Manage bug bounty and controlled external testing activities, including report review, severity validation, remediation coordination and lessons-learnt analysis.
Coordinate annual and ad-hoc penetration testing engagements with internal stakeholders and external vendors, ensuring scope, timelines, deliverables, remediation tracking and closure are managed effectively.
Oversee configuration compliance activities, including secure configuration reviews, compliance tracking, exception handling and follow-up with relevant stakeholders.
Perform vulnerability risk assessments by considering CVSS, VPR, Asset Exposure Score, DOD/BOD, exploitability, asset criticality, internet exposure, threat intelligence, business impact and existing mitigating controls.
Develop and apply risk prioritisation and severity re-classification approaches to ensure remediation efforts focus on the most exploitable and business-critical exposures.
Produce vulnerability statistics and high-level analysis, including vulnerability-per-host trends, remediation progress, past-due findings, accepted risks, control gate metrics and programme-level dashboards for management reporting.
Escalate overdue, material or high-risk vulnerabilities to relevant technology, business, risk and management stakeholders where remediation progress is not aligned with expected timelines.
Support audit and regulatory compliance expectations, including MAS TRM and Cyber Hygiene requirements, by maintaining evidence of regular vulnerability assessment, remediation tracking and risk treatment decisions.
Collaborate with threat intelligence and other security teams to act on relevant threat intelligence and emerging vulnerability trends affecting the technology environment.
Qualifications
At least 5 years of experience in IT, Information Security, Vulnerability Management, Application Security or related cyber assurance functions, with experience leading BAU vulnerability management activities.
Diploma/Degree in Computer Science, Cybersecurity, Information Security Management or related discipline.
Professional certifications such as CISSP, CISM, OSCP, GPEN, GWAPT, GWEB, CEH or cloud security certifications will be an advantage.
Skills & Experience
Strong working knowledge of vulnerability management lifecycle, including discovery, assessment, prioritisation, remediation tracking, validation and reporting.
Experience using vulnerability management, application security testing or exposure management platforms to support enterprise security operations.
Good understanding of risk-based prioritisation using factors such as severity, exploitability, asset exposure, business impact and compensating controls.
Able to interpret vulnerability data, perform high-level analysis and present clear insights to both technical and management stakeholders.
Familiar with common infrastructure, cloud, web application, API and mobile security risks, including secure configuration and application security testing concepts.
Effective stakeholder management skills, with the ability to coordinate remediation across technology, business, vendor, risk and management teams.
Able to guide, mentor and provide technical direction to junior team members or peers in vulnerability management activities.
Scripting, data handling, dashboarding or automation experience will be an advantage.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Singapore.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Singapore, connecting you to thousands of jobs fast!
Find the best jobs in Singapore, apply in 1 click and get a job today!