Lead - Vulnerability Management and Application Security Engineer
Singapore · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are looking for an experienced Vulnerability Management Specialist to lead efforts in identifying, assessing, prioritizing, and tracking remediation of security vulnerabilities throughout our technology landscape. This position requires close collaboration with teams across applications, infrastructure, cloud, and security domains to implement a risk-focused vulnerability management program that mitigates cyber threats.
Key Responsibilities
- Manage and operate vulnerability scanning platforms, including tools like Tenable/Nessus and Qualys.
- Perform both authenticated and unauthenticated scans on servers, endpoints, network devices, cloud workloads, and applications.
- Evaluate scan outcomes by validating findings, filtering out false positives, and assessing risks from business and technical perspectives.
- Oversee the complete lifecycle of vulnerabilities: identifying, triaging, prioritizing, assigning, tracking remediation, validating fixes, handling exceptions, and closure.
- Utilize risk-based prioritization criteria such as CVSS scores, exploitability, asset criticality, exposure, business impact, and active threat intelligence.
- Work collaboratively with infrastructure, application, cloud, and DevOps teams to develop actionable remediation plans within agreed timelines.
- Generate vulnerability-focused reports, dashboards, and metrics including compliance with SLAs, overdue issues, aging vulnerabilities, and risk trends for management review.
- Maintain policies and procedures related to vulnerability management, ensuring comprehensive asset coverage, scan scheduling, and audit-ready evidence.
- Support remediation efforts of application and software supply chain vulnerabilities using platforms like JFrog, Bitbucket, SonarQube, Fortify, and CI/CD tools.
- Identify and address gaps in asset inventory, scanning coverage, and remediation responsibilities; recommend enhancements and automation opportunities.
- Continuously track emerging vulnerabilities, exploits, vendor advisories, and relevant threat intelligence updates.
Required Qualifications
- Bachelor's degree or equivalent experience in Cybersecurity, IT, Computer Science, or related field.
- Proven work experience in vulnerability management, security operations, infrastructure or application security, or related cybersecurity areas.
- Practical knowledge of vulnerability scanning tools, particularly Tenable/Nessus and/or Qualys.
- Strong grasp of vulnerability management lifecycle processes including scanning, validation, CVSS scoring, risk assessment, remediation confirmation, exception handling, and reporting.
- Familiarity with standard operating systems, networking, cloud environments, and enterprise infrastructures.
- Understanding of common application vulnerabilities aligned with OWASP Top 10.
- Experience using ticketing and workflow platforms such as Jira or ServiceNow.
- Ability to analyze technical data and communicate risks and remediation steps clearly to both technical and non-technical audiences.
- Excellent attention to detail and organizational skills to ensure thorough management and closure of findings.
Preferred Qualifications
- Experience with application security and DevSecOps tools like JFrog, Bitbucket, SonarQube, Fortify, SAST, DAST, SCA, and container security solutions.
- Knowledge of cloud security and vulnerability management within AWS, Azure, or Google Cloud.
- Familiarity with threat intelligence sources, including CISA Known Exploited Vulnerabilities and exploitability evaluation.
- Expertise in developing dashboards, metrics, and automating vulnerability reporting.
- Certifications in security domains such as Security+, CEH, CISSP, CISM, CSSLP, or vendor-specific qualifications.
Minimum education
Bachelor's Degree
Skills
Tools & software
ServiceNow
required
Atlassian JIRA
required
Tenable Nessus
required
How they work
Communication
Teamwork & Collaboration
Problem Solving
Attention to Detail
Organisation