Lead - VM & App Security Engineer

StarHub

Singapore

On-site

SGD 90,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

StarHub is seeking a Vulnerability Management Specialist to lead the identification, assessment, prioritization, and remediation tracking of security vulnerabilities across our technology environment. You will partner with infrastructure, application, cloud, and DevOps teams to reduce cyber risk through a structured, risk-based vulnerability management programme.

Responsibilities include operating scanning platforms, performing targeted scans across systems, analysing results, and driving

Qualifications

  • Degree in Cybersecurity, IT, CS or equivalent practical experience.
  • Hands-on with vulnerability scanning tools (Tenable/Nessus and/or Qualys).
  • Strong understanding of vulnerability management processes, CVSS, risk assessment, remediation verification, and reporting.
  • Familiarity with OSes, networks, cloud environments, and enterprise infrastructure.
  • Experience with Jira, ServiceNow or equivalent ticketing/workflow tools.
  • Ability to explain risk and remediation actions to technical and non-technical stakeholders.
  • Attention to detail and ability to drive findings to closure.

Responsibilities

  • Operate and maintain vulnerability scanning platforms (Tenable/Nessus, Qualys).
  • Conduct authenticated and unauthenticated scans across servers, endpoints, cloud workloads, and apps.
  • Analyse results, validate findings, and assess risk.
  • Manage end-to-end vulnerability lifecycle from discovery to closure.
  • Produce vulnerability reports and dashboards with SLA metrics.
  • Maintain policies, scan schedules, and audit evidence.
  • Support remediation in CI/CD pipelines and software tools.

Skills

Vulnerability management
Security operations
Risk assessment
Stakeholder communication

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

Tenable/Nessus
Qualys
Jira
ServiceNow
Fortify
SonarQube
JFrog
Bitbucket
CI/CD pipelines

Job description

Vulnerability Management Specialist

We are seeking a Vulnerability Management Specialist to lead the identification, assessment, prioritization, and remediation tracking of security vulnerabilities across our technology environment. This role will work closely with application, infrastructure, cloud, and security teams to reduce cyber risk through a structured, risk-based vulnerability management programme.

Key Responsibilities
  • Operate and maintain vulnerability scanning platforms, preferably including Tenable/Nessus and Qualys.
  • Conduct authenticated and unauthenticated vulnerability scans across servers, endpoints, network devices, cloud workloads, and applications.
  • Analyse scan results, validate findings, eliminate false positives, and assess business and technical risk.
  • Manage the end-to-end vulnerability lifecycle: discovery, triage, prioritisation, assignment, remediation tracking, validation, exception management, and closure.
  • Apply risk-based prioritisation using CVSS, exploitability, asset criticality, internet exposure, business impact, and known active threats.
  • Partner with infrastructure, application, cloud, and DevOps teams to define practical remediation plans and meet agreed remediation timelines.
  • Produce regular vulnerability reports, dashboards, metrics, and management updates, including SLA compliance, overdue findings, vulnerability ageing, and risk trends.
  • Maintain vulnerability management policies, procedures, asset coverage, scan schedules, and evidence for audit and compliance requirements.
  • Support remediation of application and software‑supply‑chain vulnerabilities through tools and platforms such as JFrog, Bitbucket, SonarQube, Fortify, and CI/CD pipelines.
  • Identify gaps in asset inventory, scanning coverage, and remediation ownership, and recommend process or automation improvements.
  • Stay current on emerging vulnerabilities, exploit activity, vendor advisories, and threat intelligence relevant to the organisation.
Required Qualifications
  • Degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
  • Experience in vulnerability management, security operations, infrastructure security, application security, or a related cybersecurity function.
  • Hands‑on experience with vulnerability scanning tools, especially Tenable/Nessus and/or Qualys.
  • Strong understanding of vulnerability management processes, including scanning, validation, CVSS, risk assessment, remediation verification, exception handling, and reporting.
  • Familiarity with common operating systems, networks, cloud environments, and enterprise infrastructure.
  • Understanding of common application vulnerabilities and the OWASP Top 10.
  • Experience working with ticketing and workflow tools such as Jira, ServiceNow, or equivalent.
  • Ability to analyse technical findings and explain risk and remediation actions clearly to technical and non-technical stakeholders.
  • Strong attention to detail, organisation, and follow‑through in managing findings through closure.
Preferred Qualifications
  • Experience with application-security or DevSecOps platforms such as JFrog, Bitbucket, SonarQube, Fortify, SAST, DAST, SCA, and container-security tools.
  • Familiarity with cloud-security and cloud-native vulnerability management across AWS, Azure, or Google Cloud.
  • Knowledge of threat intelligence sources, CISA Known Exploited Vulnerabilities, and exploitability assessment.
  • Experience developing vulnerability dashboards, metrics, or automated reporting.
  • Security certifications such as Security+, CEH, CISSP, CISM, CSSLP, or relevant vendor certifications.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Vulnerability Management Analyst
Senior Vulnerability Management Analyst

Income • Singapore

On-site
SGD 90,000 - 130,000
Vulnerability Management Engineer (Cyber Security / Tenable)
Vulnerability Management Engineer (Cyber Security / Tenable)

GMP Technologies • Singapore

On-site
SGD 120,000 - 180,000
Cyber Security Development Engineer (Tenable and Rapid7)
Cyber Security Development Engineer (Tenable and Rapid7)

NCS Group • Singapore

On-site
SGD 42,000 - 70,000
Vulnerability Management Operations Analyst
Vulnerability Management Operations Analyst

U3 SOLUTIONS PTE. LTD. • Singapore

On-site
SGD 60,000 - 120,000
Vulnerability Management Specialist (Multiple Headcounts), Global Firm
Vulnerability Management Specialist (Multiple Headcounts), Global Firm

Kerry Consulting • Singapore

On-site
SGD 70,000 - 110,000
Vulnerability Management Operations Analyst
Vulnerability Management Operations Analyst

U3 PROJECTS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Sr Security Engineer (Vulnerability)
Sr Security Engineer (Vulnerability)

MANPOWER STAFFING SERVICES (SINGAPORE) PTE LTD • Singapore

On-site
SGD 90,000 - 150,000
Head of Vulnerability Management
Head of Vulnerability Management

Kerry Consulting Pte Ltd • Singapore

On-site
SGD 250,000 - 450,000
Cyber Security Lead (Vulnerability Management) - 1 year contract
Cyber Security Lead (Vulnerability Management) - 1 year contract

GMP Technologies • Singapore

On-site
SGD 180,000 - 240,000
Cybersecurity Platform Engineer (Tenable)
Cybersecurity Platform Engineer (Tenable)

Ensign InfoSecurity • Singapore

On-site
SGD 60,000 - 90,000