Senior Vulnerability Management Analyst

Posted One Month Ago
Be an Early Applicant
2 Locations
In-Office or Remote
Senior level
Insurance
The Role
Leads enterprise vulnerability management operations, including scanning, triage, risk-based prioritization, remediation tracking, penetration testing, bug bounty coordination, DAST program maturity, configuration compliance, reporting, audit support, and escalation of high-risk exposures. Collaborates with threat intelligence, technology, business, risk, vendors, and management stakeholders while guiding junior security team members.
Summary Generated by Built In

Description

  • Lead BAU vulnerability management operations, including vulnerability scanning/discovery, findings triage, remediation SLA tracking, closure follow-up and periodic reporting.
  • Oversee asset coverage and inventory alignment to ensure vulnerability management activities are applied consistently across relevant technology assets.
  • Drive maturity of the DAST testing programme, including onboarding of applications, scan configuration, troubleshooting, authenticated scanning, testing cadence and control improvements.
  • Manage bug bounty and controlled external testing activities, including report review, severity validation, remediation coordination and lessons-learnt analysis.
  • Coordinate annual and ad-hoc penetration testing engagements with internal stakeholders and external vendors, ensuring scope, timelines, deliverables, remediation tracking and closure are managed effectively.
  • Oversee configuration compliance activities, including secure configuration reviews, compliance tracking, exception handling and follow-up with relevant stakeholders.
  • Perform vulnerability risk assessments by considering CVSS, VPR, Asset Exposure Score, DOD/BOD, exploitability, asset criticality, internet exposure, threat intelligence, business impact and existing mitigating controls.
  • Develop and apply risk prioritisation and severity re-classification approaches to ensure remediation efforts focus on the most exploitable and business-critical exposures.
  • Produce vulnerability statistics and high-level analysis, including vulnerability-per-host trends, remediation progress, past-due findings, accepted risks, control gate metrics and programme-level dashboards for management reporting.
  • Escalate overdue, material or high-risk vulnerabilities to relevant technology, business, risk and management stakeholders where remediation progress is not aligned with expected timelines.
  • Support audit and regulatory compliance expectations, including MAS TRM and Cyber Hygiene requirements, by maintaining evidence of regular vulnerability assessment, remediation tracking and risk treatment decisions.
  • Collaborate with threat intelligence and other security teams to act on relevant threat intelligence and emerging vulnerability trends affecting the technology environment.

Qualifications

  • At least 5 years of experience in IT, Information Security, Vulnerability Management, Application Security or related cyber assurance functions, with experience leading BAU vulnerability management activities.
  • Diploma/Degree in Computer Science, Cybersecurity, Information Security Management or related discipline.
  • Professional certifications such as CISSP, CISM, OSCP, GPEN, GWAPT, GWEB, CEH or cloud security certifications will be an advantage.

Skills & Experience

  • Strong working knowledge of vulnerability management lifecycle, including discovery, assessment, prioritisation, remediation tracking, validation and reporting.
  • Experience using vulnerability management, application security testing or exposure management platforms to support enterprise security operations.
  • Good understanding of risk-based prioritisation using factors such as severity, exploitability, asset exposure, business impact and compensating controls.
  • Able to interpret vulnerability data, perform high-level analysis and present clear insights to both technical and management stakeholders.
  • Familiar with common infrastructure, cloud, web application, API and mobile security risks, including secure configuration and application security testing concepts.
  • Effective stakeholder management skills, with the ability to coordinate remediation across technology, business, vendor, risk and management teams.
  • Able to guide, mentor and provide technical direction to junior team members or peers in vulnerability management activities.
  • Scripting, data handling, dashboarding or automation experience will be an advantage.

Skills Required

  • At least 5 years of experience in IT, Information Security, Vulnerability Management, Application Security, or related cyber assurance functions
  • Experience leading business-as-usual vulnerability management activities
  • Diploma or degree in Computer Science, Cybersecurity, Information Security Management, or a related discipline
  • Professional certification such as CISSP, CISM, OSCP, GPEN, GWAPT, GWEB, CEH, or a cloud security certification
  • Working knowledge of the vulnerability management lifecycle, including discovery, assessment, prioritization, remediation tracking, validation, and reporting
  • Experience using vulnerability management, application security testing, or exposure management platforms
  • Understanding of risk-based prioritization using severity, exploitability, asset exposure, business impact, and compensating controls
  • Ability to interpret vulnerability data, perform high-level analysis, and present insights to technical and management stakeholders
  • Familiarity with infrastructure, cloud, web application, API, and mobile security risks
  • Stakeholder management skills coordinating remediation across technology, business, vendor, risk, and management teams
  • Ability to guide, mentor, and provide technical direction to junior team members or peers
  • Scripting, data handling, dashboarding, or automation experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Singapore, Singapore
2,440 Employees
Year Founded: 1970

What We Do

Income Insurance Limited (Income Insurance) is one of the leading composite insurers in Singapore, offering life, health and general insurance. Established in Singapore to plug a social need for insurance in 1970, Income Insurance continues to put people first by serving the protection, savings and investment needs of individuals, families and businesses today. Its lifestyle-centric and data-driven approach to insurance and financial planning puts the company at the forefront of innovative solutions that empowers the people it serves with better financial well-being. Additionally, Income Insurance is committed to being a responsible business that champions the environment and builds stronger communities by supporting financial inclusion, education for youth-in-need and seniors’ well-being. For more information, please visit www.income.com.sg

Similar Jobs

Circle (circle.so) Logo Circle (circle.so)

Lead Engineer, AI Platform

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees

Circle (circle.so) Logo Circle (circle.so)

Senior Quality Engineer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees
120K-130K Annually

Circle (circle.so) Logo Circle (circle.so)

Lead Engineer, AI Platform

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
43 Locations
250 Employees

Circle (circle.so) Logo Circle (circle.so)

Designer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
In-Office or Remote
18 Locations
250 Employees
100K-120K Annually

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
65 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account