Digital Business Analyst - Crowdsourced Vulnerability Discovery Programme (CVDP)

Assurity Trusted Solutions Pte Ltd

Santo Niño 1st

On-site

PHP 700,000 - 1,200,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Learning culture
Contract staff benefits
GovTech environment

Job summary

Assurity Trusted Solutions Pte. Ltd. seeks an experienced Programme Manager to lead the Government Bug Bounty Programme (GBBP), Vulnerability Rewards Programme (VRP), and Vulnerability Disclosure Programme (VDP). You will coordinate with government agencies, researchers, and a bug bounty vendor to ensure successful runs.

The role focuses on planning, execution, and monitoring, with emphasis on governance, risk mitigation, and reporting for management and stakeholders.

Qualifications

  • Five+ years of experience managing IT or technology programmes/projects.
  • Experience managing bug bounty, vulnerability disclosure, or related cybersecurity programmes is a strong plus.

Responsibilities

  • Plan, schedule, and oversee GBBP, VRP, and VDP runs.
  • Coordinate with government agencies on participation, scoping, and timely data submission.
  • Manage vendor relationships, contracts, performance, and issue escalation.

Skills

Project management
Vendor management
Data analytics
English communication
Process improvement

Education

PMP or CITPM (preferred)

Tools

GovTech platforms
Vibe coding

Job description

Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade. ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, governance and assurance services as well as managed processes. In a dynamic digital & cyber landscape where trust & collaboration is key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.

The Crowdsourced Vulnerability Discovery Programmes (CVDP) comprises three programmes: the Government Bug Bounty Programme (GBBP), the Vulnerability Rewards Programme (VRP), and the Vulnerability Disclosure Programme (VDP). The Programme Manager will lead the planning, execution, and monitoring of these programmes, working closely with government agencies, security researchers, and the appointed bug bounty vendor to ensure the programmes run successfully.

Responsibilities
  • Plan, schedule, and oversee GBBP, VRP, and VDP runs
  • Coordinate with government agencies on programme participation and scoping timelines, including following up to ensure required data and documentation are submitted on time
  • Manage the CVDP vendor relationship, including contract administration, performance monitoring, and issue escalation, covering end-to-end preparation of each GBBP run and onboarding of researchers (recruitment, vetting, test account provisioning)
  • Support the triage team in preparing reports, and coordinate with agencies on programme matters if disputes arise
  • Support procurement and tender exercises, including drafting requirement specifications and evaluating vendor proposals
  • Prepare programme reporting, dashboards, and management updates for management and stakeholders
  • Drive stakeholder communications and programme outreach such as Agencies' briefings to raise awareness and grow agency participation rates
  • Proactively identify and propose process improvement opportunities across CVDP operations, and lead their implementation — including leveraging vibe coding techniques and GovTech platforms (e.g. Ownself Gather, Opus) to automate workflows, improve reporting, and enhance programme efficiency
Requirements
  • At least five (5) years of experience managing IT or technology programmes/projects; experience managing a bug bounty, vulnerability disclosure, or related cybersecurity programme is a strong plus
  • Strong project management skills to plan, execute, and monitor programme operations
  • Good verbal and written communication skills in English, with the ability to explain technical findings to non-technical stakeholders
  • Experience managing vendors or contracts, including tracking deliverables and service levels
  • Comfortable working with data to track programme metrics and produce reports for management
  • Demonstrated ability to propose and implement process improvements, including using AI-assisted development (vibe coding) or GovTech-approved platforms to streamline operations
Preferred
  • Project Management Professional (PMP), Certified IT Project Manager (CITPM), or equivalent certification
  • Familiarity with vulnerability management, penetration testing, or bug bounty concepts
  • Experience working with or within the public sector

Join us and discover a meaningful and exciting career with Assurity Trusted Solutions!

The remuneration package will commensurate with your qualifications and experience.

We thank you for your interest and please note that only shortlisted candidates will be notified.

By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS's privacy statement which can be found at: https://www.assurity.sg/ or such other successor site.

Benefits
  • A wholly-owned subsidiary of GovTech.
  • We promote a learning culture and encourage you to grow and learn.
  • Contract Staff enjoys the same benefits as Permanent Employees.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer (Solutioning and Architecture) - Multiple Headcounts
Cybersecurity Engineer (Solutioning and Architecture) - Multiple Headcounts

Assurity Trusted Solutions Pte Ltd • Santo Niño 1st

On-site
PHP 5,914,000 - 7,886,000
GovTech affiliation
Learning culture
Contract staff benefits
Cybersecurity Engineer (Incident Response)
Cybersecurity Engineer (Incident Response)

Assurity Trusted Solutions Pte Ltd • Santo Niño 1st

On-site
PHP 4,436,000 - 6,407,000
A wholly-owned subsidiary of GovTech.
Learning culture and growth encouraged
Cybersecurity Engineer (GRC)
Cybersecurity Engineer (GRC)

Assurity Trusted Solutions Pte Ltd • Santo Niño 1st

On-site
PHP 2,957,000 - 4,436,000
GovTech affiliation
Learning culture
Contract staff benefits
Cybersecurity Programme Lead – Bug Bounty & Disclosures
Cybersecurity Programme Lead – Bug Bounty & Disclosures

Assurity Trusted Solutions Pte Ltd • Santo Niño 1st

On-site
PHP 700,000 - 1,200,000
Learning culture
Contract staff benefits
GovTech environment
Infrastructure Engineer (Backup Specialist)
Infrastructure Engineer (Backup Specialist)

Assurity Trusted Solutions Pte Ltd • Santo Niño 1st

On-site
PHP 900,000 - 1,300,000
Learning culture
GovTech affiliation
Application Security Manager
Application Security Manager

PwC • Makati

On-site
PHP 1,200,000 - 1,600,000
Senior Cybersecurity Specialist (VAPT)
Senior Cybersecurity Specialist (VAPT)

Likha Careers • Pasig

Hybrid
Paid training
Health Insurance
Life Insurance
+2
Senior Consultant I - Security & Privacy
Senior Consultant I - Security & Privacy

Cloudstaff • Angeles

Hybrid
Comprehensive health and life insurance
Flexible leave credits
Quarterly perks boxes
+3
Vulnerability Consultant
Vulnerability Consultant

HRTX • Philippines

On-site
PHP 900,000 - 1,300,000
Project Manager - Technology, APAC
Project Manager - Technology, APAC

ICAP • Santo Niño 1st

Hybrid
PHP 4,412,000 - 6,373,000