Cybersecurity Vulnerability Management Team Lead
Singapore · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Degree in Cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Position Overview
The Triage Team Lead is responsible for overseeing daily vulnerability triage operations by managing and guiding a team of specialists. This role requires ensuring that vulnerability reports are evaluated with accuracy, consistency, and timeliness. It combines leadership duties, hands-on vulnerability validation, process enhancement, automation, and collaboration with multiple stakeholders.
Key Duties
- Lead a focused team of triage specialists, maintaining high standards for quality, consistency, efficiency, and timely processing of vulnerability reports.
- Manage team workload, performance, resource allocation, and set operational priorities.
- Conduct vulnerability triage and validation directly during busy periods, particularly complex cases or escalations.
- Act as the escalation point for difficult vulnerability validations, classifications, and severity assessments.
- Coach and develop triage team members on analysis techniques, assessment approaches, documentation, and reporting standards.
- Take ownership of triage standard operating procedures, workflows, processes, and tools, driving continuous improvements.
- Oversee integration and upkeep of key platforms that support vulnerability triage functions.
- Create scripts and automate processes using Python and workflow automation platforms to enhance triage and reporting efficiency.
- Coordinate with government bodies, system owners, security researchers, and other stakeholders to promote effective vulnerability handling and mitigation.
- Support program coordination by managing interactions with internal and external stakeholders linked to Coordinated Vulnerability Disclosure Programs (CVDP).
- Analyze vulnerability patterns and significant findings; prepare comprehensive reports and presentations for leadership and stakeholders.
- Perform additional tasks as required to assist in meeting program goals.
Qualifications and Experience
- Degree in Cybersecurity, Computer Science, Information Technology, or a related technical field.
- Certified OSCP (Offensive Security Certified Professional).
- Solid understanding of web application vulnerabilities, particularly the OWASP Top 10 risks.
- Experience or strong expertise in vulnerability validation, severity rating, categorization, root cause investigation, and remediation guidance.
- Proficiency with security testing and vulnerability validation tools such as Burp Suite and Kali Linux.
- Strong analytical, investigative, and problem-solving abilities.
- Experience in mentoring or coaching junior team members.
- Excellent communication skills and ability to manage diverse stakeholders effectively.
- Collaborative leadership approach dedicated to team development and support.
- Preferred background includes bug bounty programs, vulnerability disclosures, penetration testing, or work in government or regulated environments.
- Willingness to arrange leave around the scheduled Government Bug Bounty Program (GBBP) and Pre-GBBP cycles to align with operational needs.
Minimum education
Bachelor's Degree
Skills
How they work
Communication
Teamwork & Collaboration
Problem Solving
Leadership