SL2502 - Vulnerability Management & Penetration Testing Lead
Fpt Asia Pacific Pte Ltd
·Today
- Location
- Singapore
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Management
- Seniority
- Lead
- Experience
- 7+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- CareersPage
Description
Role Overview
We are seeking an experienced Information Security professional to lead Vulnerability Management and Penetration Testing (VMPT) activities across the organisation.
The role covers three core areas: VMPT program management and governance, end-to-end vulnerability management, and penetration testing. The successful candidate will drive a risk-based approach to identifying, assessing, prioritising, and remediating security vulnerabilities across applications, infrastructure, and cloud environments.
Key Responsibilities
Program Management & Governance
- Build, manage, and continuously improve the Vulnerability Management and Penetration Testing (VMPT) program and capabilities.
- Develop and enhance policies, processes, standards, and procedures covering vulnerability management, penetration testing, communication, and reporting.
- Lead the triage and prioritisation of vulnerabilities and penetration testing findings based on threat exposure, compensating controls, business impact, and overall risk.
- Lead vulnerability and penetration testing governance forums, driving accountability and tracking remediation against defined SLAs.
- Escalate overdue, critical, or high-risk security findings to relevant stakeholders and management.
- Manage relationships with external vulnerability management and penetration testing vendors.
- Establish meaningful metrics and dashboards covering security posture, remediation progress, outstanding risks, and overall program effectiveness.
- Identify gaps in security processes and drive improvements using Risk-Based Vulnerability Management (RBVM) principles.
- Research, evaluate, and recommend appropriate vulnerability management and penetration testing tools.
- Produce clear technical reports and communicate complex security findings to both technical and non-technical stakeholders.
- Collaborate with cybersecurity teams and stakeholders on vulnerability management, penetration testing, and broader security initiatives.
- Mentor and provide technical guidance to junior security team members.
- Maintain security baseline governance using appropriate security tooling.
- Ensure security activities comply with applicable regulatory and organisational requirements.
Vulnerability Management
- Own and manage the end-to-end vulnerability management lifecycle from discovery and triage through remediation tracking, verification, and closure.
- Perform risk-based vulnerability assessments to determine actual exposure and remediation priorities.
- Identify gaps in vulnerability management processes and drive continuous improvement.
- Lead security reviews and monitoring of production environments across hybrid infrastructure.
- Track vulnerability remediation activities and ensure findings are addressed within established timelines.
- Support vulnerability verification and closure activities.
- Integrate relevant security and vulnerability information with SIEM and monitoring platforms where required.
Penetration Testing
- Own and manage the end-to-end penetration testing program, including scoping, rules of engagement, execution oversight, findings management, retesting, and closure.
- Develop and maintain an annual risk-based penetration testing plan.
- Coordinate penetration testing across external and internal networks, web applications, mobile applications, APIs, cloud environments, wireless environments, social engineering, and red/purple team exercises.
- Define and maintain penetration testing standards, methodologies, and rules of engagement.
- Apply recognised security frameworks and methodologies such as OWASP, PTES, NIST SP 800-115, and MITRE ATT&CK.
- Ensure appropriate quality, coverage, and independence of internally and externally delivered penetration testing.
- Review, triage, and validate penetration testing findings to determine severity, exposure, and remediation priorities.
- Retest remediated findings to confirm effective closure.
- Track security exceptions and residual risks through acceptance or resolution.
- Coordinate independent, threat-led, and scenario-based security testing where required.
- Ensure penetration testing activities meet applicable regulatory and industry requirements, including MAS Technology Risk Management (TRM) requirements.
Requirements
- Minimum 7 years of relevant information security or cybersecurity experience.
- Extensive experience in information security and/or IT risk management.
- Proven experience owning or managing vulnerability management and/or penetration testing programs.
- Strong experience establishing security governance processes and managing remediation activities.
- Strong hands-on experience with vulnerability management, penetration testing, and security engineering.
- Strong knowledge of Risk-Based Vulnerability Management (RBVM), including vulnerability triage and risk prioritisation.
- Experience identifying security risks associated with business processes, technology operations, applications, infrastructure, and technology projects.
- Experience with industry-standard vulnerability management, penetration testing, and Cloud Security Posture Management (CSPM) solutions.
- Strong hands-on penetration testing experience across network, web, mobile, API, and cloud environments.
- Experience managing external penetration testing vendors and validating security findings.
- Working knowledge of OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
- Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, Kali Linux, and Cobalt Strike.
- Working knowledge of scripting or programming languages such as Python, C++, Java, Ruby, Node.js, Go, or PowerShell.
- Experience with log configuration, log formats, and integration with SIEM platforms.
- Experience with process optimisation, automation, and ITSM workflow tools.
- Strong leadership, project management, and team-building capabilities.
- Ability to lead security initiatives involving multiple teams and departments.
- Strong communication and stakeholder management skills with the ability to communicate security risks to technical and non-technical audiences.
Education & Certifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred.
- Professional certifications such as CISSP, CISM, CISA, or SANS/GIAC certifications are preferred.
- Penetration testing certifications such as OSCP, GPEN, GWAPT, CREST CRT/CCT, or CEH are preferred.
- Candidates without the preferred certification may be expected to obtain a relevant certification within the required timeframe.
Skills
PythonJavaRubyNode.jsLinuxCybersecurityPenetration TestingSIEMRisk ManagementProject ManagementProgram ManagementCISSPGo