Leads enterprise vulnerability management operations, including scanning, triage, risk-based prioritization, remediation tracking, penetration testing, bug bounty coordination, DAST program maturity, configuration compliance, reporting, audit support, and escalation of high-risk exposures. Collaborates with threat intelligence, technology, business, risk, vendors, and management stakeholders while guiding junior security team members.
Description
- Lead BAU vulnerability management operations, including vulnerability scanning/discovery, findings triage, remediation SLA tracking, closure follow-up and periodic reporting.
- Oversee asset coverage and inventory alignment to ensure vulnerability management activities are applied consistently across relevant technology assets.
- Drive maturity of the DAST testing programme, including onboarding of applications, scan configuration, troubleshooting, authenticated scanning, testing cadence and control improvements.
- Manage bug bounty and controlled external testing activities, including report review, severity validation, remediation coordination and lessons-learnt analysis.
- Coordinate annual and ad-hoc penetration testing engagements with internal stakeholders and external vendors, ensuring scope, timelines, deliverables, remediation tracking and closure are managed effectively.
- Oversee configuration compliance activities, including secure configuration reviews, compliance tracking, exception handling and follow-up with relevant stakeholders.
- Perform vulnerability risk assessments by considering CVSS, VPR, Asset Exposure Score, DOD/BOD, exploitability, asset criticality, internet exposure, threat intelligence, business impact and existing mitigating controls.
- Develop and apply risk prioritisation and severity re-classification approaches to ensure remediation efforts focus on the most exploitable and business-critical exposures.
- Produce vulnerability statistics and high-level analysis, including vulnerability-per-host trends, remediation progress, past-due findings, accepted risks, control gate metrics and programme-level dashboards for management reporting.
- Escalate overdue, material or high-risk vulnerabilities to relevant technology, business, risk and management stakeholders where remediation progress is not aligned with expected timelines.
- Support audit and regulatory compliance expectations, including MAS TRM and Cyber Hygiene requirements, by maintaining evidence of regular vulnerability assessment, remediation tracking and risk treatment decisions.
- Collaborate with threat intelligence and other security teams to act on relevant threat intelligence and emerging vulnerability trends affecting the technology environment.
Qualifications
- At least 5 years of experience in IT, Information Security, Vulnerability Management, Application Security or related cyber assurance functions, with experience leading BAU vulnerability management activities.
- Diploma/Degree in Computer Science, Cybersecurity, Information Security Management or related discipline.
- Professional certifications such as CISSP, CISM, OSCP, GPEN, GWAPT, GWEB, CEH or cloud security certifications will be an advantage.
Skills & Experience
- Strong working knowledge of vulnerability management lifecycle, including discovery, assessment, prioritisation, remediation tracking, validation and reporting.
- Experience using vulnerability management, application security testing or exposure management platforms to support enterprise security operations.
- Good understanding of risk-based prioritisation using factors such as severity, exploitability, asset exposure, business impact and compensating controls.
- Able to interpret vulnerability data, perform high-level analysis and present clear insights to both technical and management stakeholders.
- Familiar with common infrastructure, cloud, web application, API and mobile security risks, including secure configuration and application security testing concepts.
- Effective stakeholder management skills, with the ability to coordinate remediation across technology, business, vendor, risk and management teams.
- Able to guide, mentor and provide technical direction to junior team members or peers in vulnerability management activities.
- Scripting, data handling, dashboarding or automation experience will be an advantage.
Income Insurance Singapore, Singapore, SGP Office
75 Bras Basah Road, Singapore, Singapore, Singapore, 189557
Income Insurance Singapore Office
Singapore
Income Insurance Singapore, Singapore, SGP Office
1 Paya Lebar Link, #07-01 PLQ 1 Paya Lebar Quarter, Singapore, Singapore, Singapore, 408533
Income Insurance Singapore, Singapore, SGP Office
2 Tampines Central 6, #01-01 NTUC Income Tampines Point, Singapore, Singapore, Singapore, 529483
Similar Jobs
Information Technology • Software • Financial Services • Big Data Analytics
Summer intern role building high-performance, large-data research platforms and web frameworks. Collaborate in small teams to create tools for trading strategies, applying distributed computing, NLP, and machine learning.
Top Skills:
Distributed ComputingHigh-Performance ComputingLarge Data Research PlatformsMachine LearningNatural Language ProcessingWeb Frameworks
Information Technology • Software • Financial Services • Big Data Analytics
Engineers at Citadel work in small teams to develop high-performing technology under quick cycles. They focus on creating tools for trading strategies and data research platforms.
Top Skills:
Distributed ComputingMachine LearningNatural Language Processing
Information Technology • Software • Financial Services • Big Data Analytics
The Quantitative Researcher develops trading models and conducts research using complex statistical techniques, requiring a PhD in a quantitative field.
Top Skills:
C++PythonR
What you need to know about the Singapore Tech Scene
The digital revolution has driven a constant demand for tech professionals across industries like software development, data analytics and cybersecurity. In Singapore, one of the largest cities in Southeast Asia, the demand for tech talent is so high that the government continues to invest millions into programs designed to develop a talent pipeline directly from universities while also scaling efforts in pre-employment training and mid-career upskilling to expand and elevate its workforce.

