Hiring.Camp

SL2502 - Vulnerability Management & Penetration Testing Lead

Fpt Asia Pacific Pte Ltd

·

Today

Location
Singapore
Workplace
Hybrid
Type
Full-time
Department
Management
Seniority
Lead
Experience
7+ years
Education
Bachelor
Closing date
Today
Source
CareersPage

Description

Role Overview

We are seeking an experienced Information Security professional to lead Vulnerability Management and Penetration Testing (VMPT) activities across the organisation.

The role covers three core areas: VMPT program management and governance, end-to-end vulnerability management, and penetration testing. The successful candidate will drive a risk-based approach to identifying, assessing, prioritising, and remediating security vulnerabilities across applications, infrastructure, and cloud environments.

Key Responsibilities

Program Management & Governance

  • Build, manage, and continuously improve the Vulnerability Management and Penetration Testing (VMPT) program and capabilities.
  • Develop and enhance policies, processes, standards, and procedures covering vulnerability management, penetration testing, communication, and reporting.
  • Lead the triage and prioritisation of vulnerabilities and penetration testing findings based on threat exposure, compensating controls, business impact, and overall risk.
  • Lead vulnerability and penetration testing governance forums, driving accountability and tracking remediation against defined SLAs.
  • Escalate overdue, critical, or high-risk security findings to relevant stakeholders and management.
  • Manage relationships with external vulnerability management and penetration testing vendors.
  • Establish meaningful metrics and dashboards covering security posture, remediation progress, outstanding risks, and overall program effectiveness.
  • Identify gaps in security processes and drive improvements using Risk-Based Vulnerability Management (RBVM) principles.
  • Research, evaluate, and recommend appropriate vulnerability management and penetration testing tools.
  • Produce clear technical reports and communicate complex security findings to both technical and non-technical stakeholders.
  • Collaborate with cybersecurity teams and stakeholders on vulnerability management, penetration testing, and broader security initiatives.
  • Mentor and provide technical guidance to junior security team members.
  • Maintain security baseline governance using appropriate security tooling.
  • Ensure security activities comply with applicable regulatory and organisational requirements.

Vulnerability Management

  • Own and manage the end-to-end vulnerability management lifecycle from discovery and triage through remediation tracking, verification, and closure.
  • Perform risk-based vulnerability assessments to determine actual exposure and remediation priorities.
  • Identify gaps in vulnerability management processes and drive continuous improvement.
  • Lead security reviews and monitoring of production environments across hybrid infrastructure.
  • Track vulnerability remediation activities and ensure findings are addressed within established timelines.
  • Support vulnerability verification and closure activities.
  • Integrate relevant security and vulnerability information with SIEM and monitoring platforms where required.

Penetration Testing

  • Own and manage the end-to-end penetration testing program, including scoping, rules of engagement, execution oversight, findings management, retesting, and closure.
  • Develop and maintain an annual risk-based penetration testing plan.
  • Coordinate penetration testing across external and internal networks, web applications, mobile applications, APIs, cloud environments, wireless environments, social engineering, and red/purple team exercises.
  • Define and maintain penetration testing standards, methodologies, and rules of engagement.
  • Apply recognised security frameworks and methodologies such as OWASP, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Ensure appropriate quality, coverage, and independence of internally and externally delivered penetration testing.
  • Review, triage, and validate penetration testing findings to determine severity, exposure, and remediation priorities.
  • Retest remediated findings to confirm effective closure.
  • Track security exceptions and residual risks through acceptance or resolution.
  • Coordinate independent, threat-led, and scenario-based security testing where required.
  • Ensure penetration testing activities meet applicable regulatory and industry requirements, including MAS Technology Risk Management (TRM) requirements.

Requirements

  • Minimum 7 years of relevant information security or cybersecurity experience.
  • Extensive experience in information security and/or IT risk management.
  • Proven experience owning or managing vulnerability management and/or penetration testing programs.
  • Strong experience establishing security governance processes and managing remediation activities.
  • Strong hands-on experience with vulnerability management, penetration testing, and security engineering.
  • Strong knowledge of Risk-Based Vulnerability Management (RBVM), including vulnerability triage and risk prioritisation.
  • Experience identifying security risks associated with business processes, technology operations, applications, infrastructure, and technology projects.
  • Experience with industry-standard vulnerability management, penetration testing, and Cloud Security Posture Management (CSPM) solutions.
  • Strong hands-on penetration testing experience across network, web, mobile, API, and cloud environments.
  • Experience managing external penetration testing vendors and validating security findings.
  • Working knowledge of OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, Kali Linux, and Cobalt Strike.
  • Working knowledge of scripting or programming languages such as Python, C++, Java, Ruby, Node.js, Go, or PowerShell.
  • Experience with log configuration, log formats, and integration with SIEM platforms.
  • Experience with process optimisation, automation, and ITSM workflow tools.
  • Strong leadership, project management, and team-building capabilities.
  • Ability to lead security initiatives involving multiple teams and departments.
  • Strong communication and stakeholder management skills with the ability to communicate security risks to technical and non-technical audiences.

Education & Certifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred.
  • Professional certifications such as CISSP, CISM, CISA, or SANS/GIAC certifications are preferred.
  • Penetration testing certifications such as OSCP, GPEN, GWAPT, CREST CRT/CCT, or CEH are preferred.
  • Candidates without the preferred certification may be expected to obtain a relevant certification within the required timeframe.

Skills

PythonJavaRubyNode.jsLinuxCybersecurityPenetration TestingSIEMRisk ManagementProject ManagementProgram ManagementCISSPGo