Head of Vulnerability & Exposure Management

Morgan McKinley

Santo Niño 1st

On-site

PHP 1,500,000 - 2,500,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Morgan McKinley is seeking an experienced cybersecurity leader to evolve the organisation's Vulnerability and Exposure Management capabilities across a complex enterprise technology environment. You will strengthen how vulnerabilities and exposures are identified, prioritised and remediated across infrastructure, applications, cloud, and emerging tech environments.

The role requires leading enterprise-scale programmes with a focus on risk-based prioritisation, governance and reporting to senior

Qualifications

  • Significant experience in Cybersecurity with leadership in Vulnerability Management or Exposure Management.
  • Strong understanding of vulnerability management in large, complex environments.
  • Experience with risk-based vulnerability prioritisation rather than relying solely on severity or scans.
  • Proven ability to partner with Technology, Engineering and Security teams to drive remediation.

Responsibilities

  • Define and drive Vulnerability and Exposure Management strategy and roadmap.
  • Lead vulnerability identification, assessment, prioritisation and remediation across infrastructure, applications and cloud.
  • Improve visibility of attack surface and security exposures across complex environments.
  • Drive a risk-based approach to vulnerability management and remediation.
  • Build and lead a high-performing cybersecurity team.
  • Communicate cyber exposures and remediation priorities to senior leadership.

Skills

Leadership
Stakeholder management
Security risk management
Communication to leadership

Education

CISSP certification
CISM certification
CRISC certification
SANS certification

Job description

We are seeking an experienced cybersecurity leader to lead and evolve the organisation's Vulnerability and Exposure Management capabilities across a complex enterprise technology environment.

The role will be responsible for strengthening how the organisation identifies, prioritises and remediates security vulnerabilities and exposures across infrastructure, applications, cloud and emerging technology environments.

We welcome candidates from Vulnerability Management, Exposure Management, Cyber Defence, Security Engineering, Offensive Security or related cybersecurity backgrounds who have experience leading enterprise-scale security programmes.

Key Responsibilities
  • Define and drive the organisation's Vulnerability and Exposure Management strategy and roadmap.
  • Lead vulnerability identification, assessment, prioritisation and remediation across infrastructure, applications and cloud environments.
  • Improve visibility of the organisation's attack surface and security exposures across complex technology environments.
  • Drive a risk-based approach to vulnerability management, considering exploitability, threat intelligence, business criticality and potential impact.
  • Partner with Technology, Engineering and Security teams to drive timely remediation and sustainable risk reduction.
  • Leverage threat intelligence, security analytics and automation to improve vulnerability prioritisation and remediation.
  • Work with penetration testing, offensive security and other security teams to validate vulnerabilities and identify potential attack paths.
  • Establish appropriate standards, governance, KRIs/KPIs and management reporting for vulnerability and exposure management.
  • Drive continuous improvement of security processes, technologies and automation to reduce remediation time and recurring vulnerabilities.
  • Provide senior-level communication on cyber exposures, remediation priorities and security posture.
  • Build, lead and develop a high-performing cybersecurity team.
Requirements:
  • Significant experience in Cybersecurity, with leadership experience in Vulnerability Management, Exposure Management, Cyber Defence, Security Engineering, Offensive Security or related areas.
  • Strong understanding of vulnerability management and remediation within large and complex technology environments.
  • Experience with some of the following areas would be highly valuable:
    • Vulnerability Management
    • Attack Surface Management
    • Cloud Security / Cloud Exposure
    • Threat Intelligence
    • Penetration Testing / Offensive Security
    • Attack Path Analysis
    • Security Analytics and Automation
  • Experience driving risk-based vulnerability prioritisation rather than relying solely on vulnerability severity or scanning results.
  • Strong understanding of enterprise cybersecurity and technology risk.
  • Experience working with Technology and Engineering teams to drive remediation and security improvements.
  • Strong stakeholder management skills with the ability to communicate technical cyber risks to senior leadership.
  • Experience within financial services or another large, regulated or technology-intensive organisation would be advantageous.
  • Relevant cybersecurity certifications such as CISSP, CISM, CRISC, SANS or Offensive Security certifications are advantageous.
What We Are Looking For:

We are open to candidates from a broader cybersecurity background who have strong vulnerability management foundations and are looking to lead the evolution towards a more proactive, threat-informed Exposure Management approach.

You do not need to have held the formal title of "Head of Exposure Management". Candidates who have led Vulnerability Management, Cyber Defence, Security Engineering, Attack Surface Management or Offensive Security programmes and can demonstrate strong enterprise-level leadership are encouraged to apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Vulnerability & Exposure Management
Director of Vulnerability & Exposure Management

Morgan McKinley • Santo Niño 1st

On-site
PHP 1,500,000 - 2,500,000
Cybersecurity
Cybersecurity

Ample Success HR • Hinoba-an

On-site
PHP 1,200,000 - 1,800,000
Senior Cybersecurity Analyst (Vulnerability)
Senior Cybersecurity Analyst (Vulnerability)

Tenet Healthcare • Taguig

On-site
PHP 600,000 - 900,000
Head of Technology & Cybersecurity
Head of Technology & Cybersecurity

Pleco Inc • Manila

On-site
PHP 2,500,000 - 4,200,000
Vulnerability Consultant
Vulnerability Consultant

HRTX • Taguig

On-site
PHP 900,000 - 1,300,000
Vulnerability Remediation Lead | Up to 280K Salary
Vulnerability Remediation Lead | Up to 280K Salary

weSource Management Consultancy Firm • Taguig

Hybrid
PHP 200,000 - 280,000
Vulnerability Remediation Lead (Cyber/InfoSec) | Up to 280K Salary
Vulnerability Remediation Lead (Cyber/InfoSec) | Up to 280K Salary

weSource Management Consultancy Firm • Taguig

Hybrid
Specialist (Cybersecurity)
Specialist (Cybersecurity)

NTUC FIRST CAMPUS LIMITED • Santo Niño 1st

On-site
PHP 1,200,000 - 1,800,000
Vulnerability Remediation Lead
Vulnerability Remediation Lead

UpSkill MNL • Metro Manila

On-site
PHP 600,000 - 900,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Morgan McKinley • Taguig

On-site
PHP 1,200,000 - 2,400,000