Vulnerability Management & Penetration Testing Lead - #1171640
FPT ASIA PACIFIC PTE. LTD.
Date: 3 hours ago
District: Singapore
Salary:
$5,000
-
$5,700
/ month
Contract type: Full time
Work schedule: Full day
Role Overview
We are seeking an experienced Information Security professional to lead Vulnerability Management and Penetration Testing (VMPT) activities across the organisation.
The role covers three core areas: VMPT program management and governance, end-to-end vulnerability management, and penetration testing. The successful candidate will drive a risk-based approach to identifying, assessing, prioritising, and remediating security vulnerabilities across applications, infrastructure, and cloud environments.
Key Responsibilities
Program Management & Governance
- Build, manage, and continuously improve the Vulnerability Management and Penetration Testing (VMPT) program and capabilities.
- Develop and enhance policies, processes, standards, and procedures covering vulnerability management, penetration testing, communication, and reporting.
- Lead the triage and prioritisation of vulnerabilities and penetration testing findings based on threat exposure, compensating controls, business impact, and overall risk.
- Lead vulnerability and penetration testing governance forums, driving accountability and tracking remediation against defined SLAs.
- Escalate overdue, critical, or high-risk security findings to relevant stakeholders and management.
- Manage relationships with external vulnerability management and penetration testing vendors.
- Establish meaningful metrics and dashboards covering security posture, remediation progress, outstanding risks, and overall program effectiveness.
- Identify gaps in security processes and drive improvements using Risk-Based Vulnerability Management (RBVM) principles.
- Research, evaluate, and recommend appropriate vulnerability management and penetration testing tools.
- Produce clear technical reports and communicate complex security findings to both technical and non-technical stakeholders.
- Collaborate with cybersecurity teams and stakeholders on vulnerability management, penetration testing, and broader security initiatives.
- Mentor and provide technical guidance to junior security team members.
- Maintain security baseline governance using appropriate security tooling.
- Ensure security activities comply with applicable regulatory and organisational requirements.
Vulnerability Management
- Own and manage the end-to-end vulnerability management lifecycle from discovery and triage through remediation tracking, verification, and closure.
- Perform risk-based vulnerability assessments to determine actual exposure and remediation priorities.
- Identify gaps in vulnerability management processes and drive continuous improvement.
- Lead security reviews and monitoring of production environments across hybrid infrastructure.
- Track vulnerability remediation activities and ensure findings are addressed within established timelines.
- Support vulnerability verification and closure activities.
- Integrate relevant security and vulnerability information with SIEM and monitoring platforms where required.
Penetration Testing
- Own and manage the end-to-end penetration testing program, including scoping, rules of engagement, execution oversight, findings management, retesting, and closure.
- Develop and maintain an annual risk-based penetration testing plan.
- Coordinate penetration testing across external and internal networks, web applications, mobile applications, APIs, cloud environments, wireless environments, social engineering, and red/purple team exercises.
- Define and maintain penetration testing standards, methodologies, and rules of engagement.
- Apply recognised security frameworks and methodologies such as OWASP, PTES, NIST SP 800-115, and MITRE ATT&CK.
- Ensure appropriate quality, coverage, and independence of internally and externally delivered penetration testing.
- Review, triage, and validate penetration testing findings to determine severity, exposure, and remediation priorities.
- Retest remediated findings to confirm effective closure.
- Track security exceptions and residual risks through acceptance or resolution.
- Coordinate independent, threat-led, and scenario-based security testing where required.
- Ensure penetration testing activities meet applicable regulatory and industry requirements, including MAS Technology Risk Management (TRM) requirements.
Requirements
- Minimum 7 years of relevant information security or cybersecurity experience.
- Extensive experience in information security and/or IT risk management.
- Proven experience owning or managing vulnerability management and/or penetration testing programs.
- Strong experience establishing security governance processes and managing remediation activities.
- Strong hands-on experience with vulnerability management, penetration testing, and security engineering.
- Strong knowledge of Risk-Based Vulnerability Management (RBVM), including vulnerability triage and risk prioritisation.
- Experience identifying security risks associated with business processes, technology operations, applications, infrastructure, and technology projects.
- Experience with industry-standard vulnerability management, penetration testing, and Cloud Security Posture Management (CSPM) solutions.
- Strong hands-on penetration testing experience across network, web, mobile, API, and cloud environments.
- Experience managing external penetration testing vendors and validating security findings.
- Working knowledge of OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
- Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, Kali Linux, and Cobalt Strike.
- Working knowledge of scripting or programming languages such as Python, C++, Java, Ruby, Node.js, Go, or PowerShell.
- Experience with log configuration, log formats, and integration with SIEM platforms.
- Experience with process optimisation, automation, and ITSM workflow tools.
- Strong leadership, project management, and team-building capabilities.
- Ability to lead security initiatives involving multiple teams and departments.
- Strong communication and stakeholder management skills with the ability to communicate security risks to technical and non-technical audiences.
Education & Certifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred.
- Professional certifications such as CISSP, CISM, CISA, or SANS/GIAC certifications are preferred.
- Penetration testing certifications such as OSCP, GPEN, GWAPT, CREST CRT/CCT, or CEH are preferred.
- Candidates without the preferred certification may be expected to obtain a relevant certification within the required timeframe.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Associate, Continuing Sponsorship (M&A, Training Provided)
TRUST RECRUIT PTE. LTD.,
Singapore
$3,800
-
$5,500
/ month
4 hours ago
Job Responsibilities Advise listed companies on continuing obligations and requirements under the SGX Listing Manual. Provide guidance on corporate governance, disclosure and regulatory compliance matters. Review corporate announcements, shareholder circulars, annual reports and other disclosure documents. Advise on corporate actions,...
Training Provided - Sales Coordinator (Sales Admin Support | Quotation)
EA RECRUITMENT PTE. LTD.,
Singapore
$2,200
-
$3,000
/ month
1 day ago
Basic $2,200 - $3,000 + AWS + VB Working location: Joo Koon Working Days: Monday - Friday Working Hours: 8.00am - 5.30pm TRAINING PROVIDED Job Descriptions Prepare, submit, and follow up on sales quotations with customers. Process customer orders accurately...
Linux Engineer (Agency contract)
PERSOL SINGAPORE PTE. LTD.,
Singapore
$7,000
-
$10,000
/ month
1 day ago
About the client Our client is a Reputed Bank. Responsibilities Design, implement, and configure OpenShift clusters and containerized applications Building a CI/CD pipeline for automating the provisioning and management of infrastructure components with Ansible and/or Terraform. Collaborating with cross-functional teams...