Search by job, company or skills

Head of Vulnerability Management

Fresher
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

We are currently supporting a global client in seeking a senior cybersecurity leader to drive its enterprise Vulnerability Management capability.

The role will evolve traditional vulnerability management towards a more proactive, threat-informed approach, covering infrastructure, applications, cloud and identity environments.

Key Responsibilities:

  • Own the strategy and roadmap for enterprise vulnerability management.
  • Drive continuous visibility and assessment of the organisation's attack surface across cloud, on-premises, applications and identity.
  • Establish risk-based prioritisation using threat intelligence, exploitability, asset criticality and business impact.
  • Oversee vulnerability scanning, penetration testing, attack-path analysis and breach/attack simulation.
  • Partner with technology teams to drive remediation, address root causes and reduce recurring exposures.
  • Establish vulnerability, remediation and patch-management standards and governance.
  • Develop KRIs, KPIs and management reporting to track exposure and programme effectiveness.
  • Leverage automation, analytics and AI to improve discovery, prioritisation and remediation.
  • Partner with Technology Risk and Audit on assurance and control matters.
  • Build and lead a high-performing team.

Requirements:

  • Extensive cybersecurity experience with senior leadership responsibility across vulnerability management, or cyber assurance.
  • Proven experience building or maturing an enterprise-scale vulnerability management programme.
  • Strong expertise across vulnerability management, attack surface management, penetration testing and exposure validation.
  • Good understanding of threat-informed prioritisation, attack paths and business-criticality-based risk assessment.
  • Experience with threat intelligence, cloud security and security automation.
  • Experience within financial services or another complex regulated environment preferred.
  • Strong senior stakeholder management and communication skills.
  • Relevant certifications such as CISSP, CISM, CRISC, SANS or OffSec would be advantageous.

To apply:

If you're interested to apply or find out more, please share across your CV or reach out to Chen Yi at [Confidential Information] for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.

Reg: R1876389

Lic: 16S8060

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 153737293

Beware of Scammers

We don’t charge money for job offers