Senior Vulnerability Management Analyst

Income Insurance Limited

Singapore

On-site

SGD 120,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Income Insurance Limited is seeking a leader to run vulnerability management operations in a large IT security program in Singapore. You will oversee scanning, triage, remediation tracking, asset coverage, and reporting to drive timely risk reduction across technology stacks.

You will coordinate DAST and penetration testing, manage bug bounty and external tests, and oversee configuration compliance while applying threat intel and risk prioritisation to focus on critical exposures.

Qualifications

  • Minimum 5 years in IT/security with vulnerability management leadership.
  • Diploma/degree in CS, cybersecurity, or related.
  • Certs such as CISSP, CISM, OSCP, GPEN, GWAPT, GWEB, CEH or cloud certs are a bonus.

Responsibilities

  • Lead BAU vulnerability management operations: scanning, findings triage, remediation SLA tracking, closure follow-up and reporting.
  • Oversee asset coverage and inventory alignment for consistent vulnerability management across technology assets.
  • Drive maturity of DAST testing programme: onboarding apps, scan config, troubleshooting, authenticated scanning, cadence and control improvements.
  • Manage bug bounty and controlled external testing: report review, severity validation, remediation coordination, lessons-learnt analysis.
  • Coordinate annual/ad-hoc penetration testing with stakeholders and vendors, ensuring scope, timelines, deliverables, remediation tracking and closure.
  • Oversee configuration compliance activities: secure config reviews, compliance tracking, exception handling and follow-up.
  • Perform vulnerability risk assessments considering CVSS, asset exposure, threat intel, business impact and mitigations.
  • Develop risk prioritisation and severity re-classification to focus on exploitable, critical exposures.
  • Produce vulnerability statistics and dashboards for management reporting (per-host trends, progress, past-due findings, accepted risks).
  • Escalate overdue/high-risk vulnerabilities to tech/business/risk teams when remediation lags.
  • Support audit/regulatory expectations (MAS TRM, Cyber Hygiene) with evidence of assessments and risk treatment decisions.
  • Collaborate with threat intel and security teams on emerging vulnerability trends.

Skills

Vulnerability management lifecycle
Risk-based prioritisation
Stakeholder management
Mentoring junior staff
Scripting / automation
Dashboards / data handling
Security testing concepts

Education

Diploma/Degree in CS/Cybersecurity

Tools

Vulnerability platforms
AppSec testing tools
Automation scripting

Job description

Description
  • Lead BAU vulnerability management operations, including vulnerability scanning/discovery, findings triage, remediation SLA tracking, closure follow-up and periodic reporting.
  • Oversee asset coverage and inventory alignment to ensure vulnerability management activities are applied consistently across relevant technology assets.
  • Drive maturity of the DAST testing programme, including onboarding of applications, scan configuration, troubleshooting, authenticated scanning, testing cadence and control improvements.
  • Manage bug bounty and controlled external testing activities, including report review, severity validation, remediation coordination and lessons-learnt analysis.
  • Coordinate annual and ad-hoc penetration testing engagements with internal stakeholders and external vendors, ensuring scope, timelines, deliverables, remediation tracking and closure are managed effectively.
  • Oversee configuration compliance activities, including secure configuration reviews, compliance tracking, exception handling and follow-up with relevant stakeholders.
  • Perform vulnerability risk assessments by considering CVSS, VPR, Asset Exposure Score, DOD/BOD, exploitability, asset criticality, internet exposure, threat intelligence, business impact and existing mitigating controls.
  • Develop and apply risk prioritisation and severity re-classification approaches to ensure remediation efforts focus on the most exploitable and business-critical exposures.
  • Produce vulnerability statistics and high-level analysis, including vulnerability-per-host trends, remediation progress, past-due findings, accepted risks, control gate metrics and programme-level dashboards for management reporting.
  • Escalate overdue, material or high-risk vulnerabilities to relevant technology, business, risk and management stakeholders where remediation progress is not aligned with expected timelines.
  • Support audit and regulatory compliance expectations, including MAS TRM and Cyber Hygiene requirements, by maintaining evidence of regular vulnerability assessment, remediation tracking and risk treatment decisions.
  • Collaborate with threat intelligence and other security teams to act on relevant threat intelligence and emerging vulnerability trends affecting the technology environment.
Qualifications
  • At least 5 years of experience in IT, Information Security, Vulnerability Management, Application Security or related cyber assurance functions, with experience leading BAU vulnerability management activities.
  • Diploma/Degree in Computer Science, Cybersecurity, Information Security Management or related discipline.
  • Professional certifications such as CISSP, CISM, OSCP, GPEN, GWAPT, GWEB, CEH or cloud security certifications will be an advantage.
Skills & Experience
  • Strong working knowledge of vulnerability management lifecycle, including discovery, assessment, prioritisation, remediation tracking, validation and reporting.
  • Experience using vulnerability management, application security testing or exposure management platforms to support enterprise security operations.
  • Good understanding of risk-based prioritisation using factors such as severity, exploitability, asset exposure, business impact and compensating controls.
  • Able to interpret vulnerability data, perform high-level analysis and present clear insights to both technical and management stakeholders.
  • Familiar with common infrastructure, cloud, web application, API and mobile security risks, including secure configuration and application security testing concepts.
  • Effective stakeholder management skills, with the ability to coordinate remediation across technology, business, vendor, risk and management teams.
  • Able to guide, mentor and provide technical direction to junior team members or peers in vulnerability management activities.
  • Scripting, data handling, dashboarding or automation experience will be an advantage.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vulnerability Management Analyst
Senior Vulnerability Management Analyst

Income • Singapore

On-site
SGD 90,000 - 130,000
Lead Engineer - Vulnerability Management
Lead Engineer - Vulnerability Management

SYNAPXE PTE. LTD. • Singapore

On-site
SGD 90,000 - 140,000
Vulnerability Management Specialist
Vulnerability Management Specialist

SINGAPORE POWER LIMITED • Singapore

On-site
SGD 90,000 - 150,000
Automation Vulnerability Management Engineer - 1 year contract
Automation Vulnerability Management Engineer - 1 year contract

GMP TECHNOLOGIES (S) PTE LTD • Singapore

On-site
SGD 80,000 - 120,000
Security Analyst
Security Analyst

RAPSYS TECHNOLOGIES PTE. LTD. • Singapore

On-site
SGD 70,000 - 110,000
Vulnerability Management Specialist- Mutiple headcount
Vulnerability Management Specialist- Mutiple headcount

Adecco • Singapore

On-site
SGD 180,000 - 240,000
G01 - Triage Team Lead
G01 - Triage Team Lead

FPT ASIA PACIFIC PTE. LTD. • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity Vulnerability Triage Team Lead
Cybersecurity Vulnerability Triage Team Lead

SEDHA CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Senior Vulnerability Management & Risk Lead
Senior Vulnerability Management & Risk Lead

Income • Singapore

On-site
SGD 90,000 - 130,000
Vulnerability Management Specialist
Vulnerability Management Specialist

SP Group • Singapore

On-site
SGD 70,000 - 100,000
Attractive remuneration for good performance
Positive work environment