- Location
- Kuala Lumpur - RedQ, Malaysia
- Type
- Full-time
- Department
- Human Resources
- Seniority
- Senior
- Experience
- 10+ years
- Education
- Bachelor
- Source
- Workday
Description
Job Description
WHAT YOU'LL DO:
Vulnerability Assessment & Management
Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.
Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics.
Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.
Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.
Penetration Testing & Red Teaming
Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises.
Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.
Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.
Threat Intelligence & Threat Hunting
Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework).
Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.
Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.
Stakeholder Management & Strategic Leadership
Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors.
Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.
Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds).
Team Leadership and Development
Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers.
Provide hands-on technical guidance during complex technical deep-dives, exploit evaluations, and attack surface reviews.
Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains.
WHO YOU ARE:
10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming.
Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling
Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.
Bachelor's degree in Computer Science, Information Security, or a related technical field.
Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights.
Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.