StarHub

Lead - Vulnerability Management and Application Security Engineer

StarHub

Singapore · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
1 week ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

We are looking for an experienced Vulnerability Management Specialist to lead efforts in identifying, assessing, prioritizing, and tracking remediation of security vulnerabilities throughout our technology landscape. This position requires close collaboration with teams across applications, infrastructure, cloud, and security domains to implement a risk-focused vulnerability management program that mitigates cyber threats.

Key Responsibilities

  • Manage and operate vulnerability scanning platforms, including tools like Tenable/Nessus and Qualys.
  • Perform both authenticated and unauthenticated scans on servers, endpoints, network devices, cloud workloads, and applications.
  • Evaluate scan outcomes by validating findings, filtering out false positives, and assessing risks from business and technical perspectives.
  • Oversee the complete lifecycle of vulnerabilities: identifying, triaging, prioritizing, assigning, tracking remediation, validating fixes, handling exceptions, and closure.
  • Utilize risk-based prioritization criteria such as CVSS scores, exploitability, asset criticality, exposure, business impact, and active threat intelligence.
  • Work collaboratively with infrastructure, application, cloud, and DevOps teams to develop actionable remediation plans within agreed timelines.
  • Generate vulnerability-focused reports, dashboards, and metrics including compliance with SLAs, overdue issues, aging vulnerabilities, and risk trends for management review.
  • Maintain policies and procedures related to vulnerability management, ensuring comprehensive asset coverage, scan scheduling, and audit-ready evidence.
  • Support remediation efforts of application and software supply chain vulnerabilities using platforms like JFrog, Bitbucket, SonarQube, Fortify, and CI/CD tools.
  • Identify and address gaps in asset inventory, scanning coverage, and remediation responsibilities; recommend enhancements and automation opportunities.
  • Continuously track emerging vulnerabilities, exploits, vendor advisories, and relevant threat intelligence updates.

Required Qualifications

  • Bachelor's degree or equivalent experience in Cybersecurity, IT, Computer Science, or related field.
  • Proven work experience in vulnerability management, security operations, infrastructure or application security, or related cybersecurity areas.
  • Practical knowledge of vulnerability scanning tools, particularly Tenable/Nessus and/or Qualys.
  • Strong grasp of vulnerability management lifecycle processes including scanning, validation, CVSS scoring, risk assessment, remediation confirmation, exception handling, and reporting.
  • Familiarity with standard operating systems, networking, cloud environments, and enterprise infrastructures.
  • Understanding of common application vulnerabilities aligned with OWASP Top 10.
  • Experience using ticketing and workflow platforms such as Jira or ServiceNow.
  • Ability to analyze technical data and communicate risks and remediation steps clearly to both technical and non-technical audiences.
  • Excellent attention to detail and organizational skills to ensure thorough management and closure of findings.

Preferred Qualifications

  • Experience with application security and DevSecOps tools like JFrog, Bitbucket, SonarQube, Fortify, SAST, DAST, SCA, and container security solutions.
  • Knowledge of cloud security and vulnerability management within AWS, Azure, or Google Cloud.
  • Familiarity with threat intelligence sources, including CISA Known Exploited Vulnerabilities and exploitability evaluation.
  • Expertise in developing dashboards, metrics, and automating vulnerability reporting.
  • Certifications in security domains such as Security+, CEH, CISSP, CISM, CSSLP, or vendor-specific qualifications.

Minimum education

Bachelor's Degree

Tools & software

ServiceNow required Atlassian JIRA required Tenable Nessus required

How they work

Communication Teamwork & Collaboration Problem Solving Attention to Detail Organisation

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer