Responsibilities
- Know the vulnerability management lifecycle, including identification, assessment, reporting, prioritization, and remediation.
- Lead the development, implementation, and continuous improvement of vulnerability management processes and tools.
- Serve as the subject matter expert (SME) for vulnerability risk, patching standards, and remediation approaches.
- Oversee vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7) and ensure accurate coverage and tuning.
- Collaborate with SOC, red teams, and threat intelligence to correlate vulnerabilities with real-world threats and exploitability.
- Analyze scan results and contextual risk (e.g., CVSS score, asset criticality, threat intel) to prioritize remediation efforts.
- Track and report on KPIs/KRIs related to vulnerability exposure, patch compliance, and SLA adherence.
- Facilitate remediation meetings with asset owners and stakeholders.
- Collaborate with IT, infrastructure, application owners, and third parties to ensure timely remediation.
- Develop executive dashboards and technical reports for various stakeholders, including senior management and auditors.
- Represent vulnerability management in audits, risk assessments, and incident postmortems.
- Ensure vulnerability management processes align with internal policies and regulatory standards (e.g., ISO 27001, NIST).
Requirements:
. Bachelor's degree in Cybersecurity, Computer Science, or related field.
. 6+ years of experience in cybersecurity, with 3+ years in vulnerability management.
. Experience with enterprise vulnerability scanning platforms (Tenable, Qualys, etc.).
. Strong understanding of CVEs, CVSS, threat modeling, and security frameworks (NIST, CIS, MITRE ATT&CK).
. Demonstrated ability to lead cross-functional teams and drive remediation.
Our Addresses and Working Hours:
Seatrium Pioneer Yard
50 Gul Road Singapore 629351
(Island wide transport provided)
Mon - Thu: 8am - 5:15pm, Fri: 8am to 4:30pm
Interested candidates are invited to send us an updated resume with your current and expected salary and earliest availability.
We regret that only shortlisted candidates will be notified.
Please note that your personal data disclosed to Seatrium Limited and our group of companies, shall be used for the purposes of evaluation, and processing in accordance with our recruitment processes and policies. By providing your personal data, you have consented to the aforesaid purpose under the provisions of the Personal Data Protection Act 2012.