Vulnerability Management & Penetration Testing Lead

Singlife

Singapore

On-site

SGD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Singlife is looking for a skilled Vulnerability Management & Penetration Testing Lead to oversee the development and management of its internal program. You will be responsible for identifying and managing vulnerabilities while leading a team to ensure the security and integrity of our IT operations.

The ideal candidate will have over 7 years of relevant experience, a strong background in risk-based methodologies, and leadership abilities to mentor junior staff. This role is based in Singapore.

Qualifications

  • 7+ years of relevant experience in information security.
  • Strong knowledge in risk-based vulnerability management.
  • Ability to lead teams and drive projects across departments.

Responsibilities

  • Build and manage the Vulnerability Management & Penetration Testing program.
  • Develop policies and procedures for vulnerability management.
  • Lead the identification and management of vulnerabilities.

Skills

Risk-based vulnerability management
Team leadership
Communication with diverse audiences
Process optimization
Cybersecurity knowledge
Incident handling
Programming (Python, C++, Java, etc.)

Education

Bachelor’s degree in Computer Science / Information Technology
Professional certifications (SANS, CISA, etc.)

Tools

Qualys
Prisma Cloud
ITSM tools
SIEM platforms

Job description

Singlife is a leading homegrown financial services company, offering consumers a better way to financial freedom. Through innovative, technology-enabled solutions and a wide range of products and services, Singlife provides consumers coantrol over their financial wellbeing at every stage of their lives.

In addition to a comprehensive suite of insurance plans, employee benefits, partnerships with financial adviser channels and bancassurance, Singlife offers investment and advisory solutions through its GROW with Singlife platform. It also offers the Singlife Account, a mobile-first insurance savings plan.

Singlife is the exclusive insurance provider for the Ministry of Defence, Ministry of Home Affairs and Public Officers Group Insurance Scheme. Singlife is also an official signatory of the United Nations Principles for Sustainable Insurance and the United Nations-supported Principles for Responsible Investment, affirming its commitment to finding a better way to sustainability.

The merger of Aviva Singapore and Singlife was announced in September 2020 and created one of the largest homegrown financial services companies in Singapore in a deal valued at S$3.2 billion. It was the largest insurance deal in Singapore at the time. Singlife was subsequently acquired by Sumitomo Life in March 2024, one of Japan’s leading life insurers, which valued Singlife at S$4.6 billion, making the transaction one of the largest insurance deals in Southeast Asia.

Purpose

The Vulnerability Management & Penetration Testing Lead is responsible for developing & running Singlife internal Vulnerability Management & Penetration Testing program and capabilities to support Singlife business, security & integrity of the IT operations.

She/He will lead and manage a team to identify & employ risk-based vulnerability management methodologies, developing standards & procedures for a distributed environment and to champion program improvements that meets the needs of business & security requirements.

Responsibilities

  • Build internal Vulnerability Management & Penetration Testing (VMPT) program & capabilities within the organization.
  • Develop and refine policies, processes & procedures for vulnerability management, penetration testing, communication and reporting.
  • Manage internal VMPT program and relationships with external VMPT vendors and other external stakeholders in Singlife.
  • Build & Lead security review & monitoring of production environments in hybrid infrastructure.
  • Lead identification of gaps in RBVM processes & procedures and drive improvements
  • Lead identification of gaps in adjacent processes & procedures and drive improvements from a RBVM perspective.
  • Lead triage and management of vulnerabilities effectively and efficiently together with other internal teams.
  • Produce quality oral & written work products, presenting complex technical matters & findings clearly & concisely
  • Consult with and take direction from supervisors and other cybersecurity team members regarding vulnerability management and penetration testing status and findings
  • Mentor and guide technical development of more junior VMPT staff and colleagues
  • Research, develop & recommend hardware and software tooling required for effective risk-based vulnerability management
  • Ability to interact with a broad cross-section of personnel to explain and enforce security measures.
  • Extensive experience in information security and/or IT risk management with a focus on security, performance and reliability.
  • Ensure compliance with all applicable laws and regulations relating to the above functional activities.
  • Operation for compliance with governance against security baseline with tool.

Experience

  • Preferable to have 7+ years of relevant experience
  • Strong Knowledge in Risk-based Vulnerability Management
  • Demonstrated ability to lead, with project and team-building skills, including the ability to lead teams and drive projects and initiatives in multiple departments.
  • Experience and ability to identify risks associated with business processes, operations, information security programs and technology projects.
  • Able to communicate with diverse audiences, both technical and non-technical, to achieve consensus with regards to risk-based vulnerability management.
  • Experience with optimization of processes
  • Experience with automation of processes and process workflow using ITSM tools.
  • Experience in log configuration, formats and feeding of logs into SIEM platforms
  • Experience in intrusion analysis and incident handling.
  • Working experience with vulnerability management and security engineering in a high tempo SOC or Cyber Fusion Centre Environment.
  • Leadership experience in a high tempo SOC or Cyber Fusion Centre Environment.
  • Good track record in leading and mentoring a team.
  • Some knowledge in programming in the use of Python, C++, Java, Ruby, Node, Go and/or PowerShell.
  • Have experience with Qualys/Prisma Cloud.

Education

  • Academic: Bachelor’s degree in Computer Science / Information Technology(preferred)
  • Professional Certification(s): SANS, CISA, CISM, CISSP, Vendor Certifications (preferred / willing to get certified in 1 year)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AVP, Information Security (Vulnerability Management & Penetration Testing)
AVP, Information Security (Vulnerability Management & Penetration Testing)

Singlife • Singapore

On-site
SGD 180,000 - 260,000
Manager, Information Security (Vulnerability Management & Penetration Testing)
Manager, Information Security (Vulnerability Management & Penetration Testing)

Singlife • Singapore

On-site
SGD 80,000 - 110,000
VP, Information Security (MDR)
VP, Information Security (MDR)

SINGAPORE LIFE LTD. • Singapore

On-site
SGD 260,000 - 480,000
VP, Information Security (Managed Detection & Response)
VP, Information Security (Managed Detection & Response)

Singlife • Singapore

On-site
SGD 180,000 - 240,000
Information Security Engineer
Information Security Engineer

Singlife • Singapore

On-site
SGD 70,000 - 100,000
VP, Application Development
VP, Application Development

SINGAPORE LIFE LTD. • Singapore

On-site
SGD 140,000 - 210,000
AVP, Vulnerability Management & Pen Testing
AVP, Vulnerability Management & Pen Testing

Singlife • Singapore

On-site
SGD 180,000 - 260,000
Information Security (Vulnerability and Penetration )
Information Security (Vulnerability and Penetration )

Unison Group • Singapore

On-site
SGD 180,000 - 230,000
AVP, Advisor Operations
AVP, Advisor Operations

Singlife • Singapore

On-site
SGD 50,000 - 75,000
SVP, Identity Access Management & Governance
SVP, Identity Access Management & Governance

SINGAPORE LIFE LTD. • Singapore

On-site
SGD 250,000 - 380,000