The posting
Vulnerability Management
• Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
• Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
• Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions
• Track remediation status and escalate overdue items per defined SLAs
Risk Register & Risk Acceptance
• Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data
• Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
• Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign-off on risk acceptances
• Periodically review accepted risks for continued validity and reassessment
Security Operations Oversight
• Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment
• Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment
• Ensure timely triage and action on vendor-disclosed vulnerabilities affecting in-scope systems
Impact& Risk Analysis
• Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores
• Contextualize CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real-world risk and prioritization
• Provide risk-based recommendations to stakeholders to support remediation prioritization decisions
Reporting& Communication
• Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
• Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding
Required Qualifications
• Bachelor's degree in Information Security, Computer Science, or related field (or equivalent work experience)
• 3–5+ years of experience in IT security operations, vulnerability management, or risk management
• Hands-on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
• Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
• Solid understanding of on-premises infrastructure security (servers, network devices, endpoints)
• Strong understanding of CVSS scoring methodology and practical risk-based prioritization
• Experience developing and managing Risk Registers and Risk Acceptance documentation
• Excellent stakeholder management and communication skills, with ability to work cross-functionally
Preferred Qualifications
• Relevant certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty, or similar
• Experience with GRC tools (e.g., ServiceNow GRC, Archer)
• Familiarity with frameworks such as NIST 800-53, NIST CSF, or ISO 27001
• Experience working in a hybrid on-prem/cloud environment supporting external customers
Interested applicants please send your resume to [email protected]
Venessa Goh Wee Ni
R24124686
Recruit Express Pte Ltd
EA License No: 99C4599
We regret that only shortlisted candidates will be contacted.



