Senior Manager, Threat and Vulnerability Management

AirAsia

Kuala Lumpur

On-site

MYR 240,000 - 360,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

AirAsia Berhad seeks a senior Cyber Security leader to own and evolve our vulnerability management program across multi-cloud and legacy environments. You will define risk-based prioritization, drive remediation timelines with ICT and SRE, and communicate progress to senior leadership.

You will also define penetration testing strategy, manage internal and external testers, and oversee post-assessment remediation validation.

Qualifications

  • 10+ years in Cyber Security with focus on vulnerability management, pentesting, threat intel and red teaming.
  • Bachelor's degree in Computer Science, Information Security, or related field.
  • Industry certifications (OSCP, GXPN, GPEN, CISSP, CISM or equivalent) advantageous.

Responsibilities

  • Own and evolve end-to-end vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.
  • Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and exploitability metrics.
  • Collaborate with ICT, SRE, and business units to enforce remediation timelines and drive patching accountability.
  • Define operational strategy and schedule for penetration testing and red teaming exercises; manage vendors/testers.
  • Build and integrate a Cyber Threat Intelligence program to detect indicators and TTPs; conduct proactive threat hunting.
  • Lead and mentor a team of vulnerability analysts, testers, and threat researchers; provide technical guidance.

Skills

Vulnerability Management
Penetration Testing
Threat Intelligence
Red Teaming
CVSS / EPSS risk scoring
Cloud security
Stakeholder communication
Leadership

Education

Bachelor's degree in Computer Science / Information Security

Job description

WHAT YOU'LL DO

Vulnerability Assessment & Management Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments. Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics. Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations. Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.

Penetration Testing & Red Teaming

Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises. Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables. Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.

Threat Intelligence & Threat Hunting

Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework). Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses. Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.

Stakeholder Management & Strategic Leadership

Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors. Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact. Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds).

Team Leadership and Development

Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers. Provide hands‑on technical guidance during complex technical deep‑dives, exploit evaluations, and attack surface reviews. Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains.

WHO YOU ARE

10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming. Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling Proven ability to lead and motivate teams, build strong relationships, and influence decision‑making at all levels. Bachelor's degree in Computer Science, Information Security, or a related technical field. Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights. Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.

AirAsia Berhad: Asia’s leading airline was established with the dream of making flying possible for everyone. Since 2001, AirAsia has swiftly broken travel norms around the globe and has risen to become the world’s best. Driven by the Dare to Dream spirit, we pride ourselves in being the region’s largest low‑cost carrier, serving 24 countries and over 130 destinations. We're not confined by walls, except when we need to answer the call of nature, so all departments mingle every day. As we embrace new technology to become a digital airline, services like BIG Duty Free, BIG Pay, BIG Loyalty, Touristly, ROKKI and Xcite Inflight Entertainment will be an exciting evolution, placing us ahead of the game. Are you in? AirAsia is set to take low‑cost flying to an all new high with our belief, "Now Everyone Can Fly"

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Executive, Airport Application Management
Senior Executive, Airport Application Management

AirAsia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Medical benefits
Insurance
Flexible work
+8
Head, Digital & Innovation Services
Head, Digital & Innovation Services

AirAsia • Kuala Lumpur

On-site
MYR 200,000 - 420,000
Leader: Vulnerability Mgmt, Red Team & Threat Intel
Leader: Vulnerability Mgmt, Red Team & Threat Intel

AirAsia • Kuala Lumpur

On-site
MYR 240,000 - 360,000
Senior Executive, Jira Technical Specialist
Senior Executive, Jira Technical Specialist

AirAsia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Free flights
Unlimited flight discounts
Partner discounts
Senior Software Engineer
Senior Software Engineer

AirAsia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Health & Insurance benefits
Flexible work arrangement
Flight benefits
+1
Enterprise Application Manager
Enterprise Application Manager

AirAsia • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Free flights
Unlimited flight discounts
Partner discounts
Senior Executive, Scheduling (Vietnam)
Senior Executive, Scheduling (Vietnam)

AirAsia • Kuala Lumpur

On-site
MYR 67,000 - 112,000
Data Scientist
Data Scientist

AirAsia • Kuala Lumpur

On-site
MYR 60,000 - 150,000
Associate Product Manager
Associate Product Manager

AirAsia • Kuala Lumpur

On-site
MYR 50,000 - 80,000
Senior Product Manager
Senior Product Manager

AirAsia • Kuala Lumpur

On-site
MYR 180,000 - 240,000