Skip to content

Open nowPosted 2 days ago

Vulnerability Management & Penetration Testing Lead

MyCareersFuture94,028 open roles

Pay
SGD 5,000 – SGD 5,700 a month
Where
Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowVulnerability Management & Penetration Testing LeadMyCareersFuture · Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 2 days ago

The posting

Role Overview

We are seeking an experienced Information Security professional to lead Vulnerability Management and Penetration Testing (VMPT) activities across the organisation.

The role covers three core areas: VMPT program management and governance, end-to-end vulnerability management, and penetration testing. The successful candidate will drive a risk-based approach to identifying, assessing, prioritising, and remediating security vulnerabilities across applications, infrastructure, and cloud environments.

Key Responsibilities

Program Management & Governance

  • Build, manage, and continuously improve the Vulnerability Management and Penetration Testing (VMPT) program and capabilities.
  • Develop and enhance policies, processes, standards, and procedures covering vulnerability management, penetration testing, communication, and reporting.
  • Lead the triage and prioritisation of vulnerabilities and penetration testing findings based on threat exposure, compensating controls, business impact, and overall risk.
  • Lead vulnerability and penetration testing governance forums, driving accountability and tracking remediation against defined SLAs.
  • Escalate overdue, critical, or high-risk security findings to relevant stakeholders and management.
  • Manage relationships with external vulnerability management and penetration testing vendors.
  • Establish meaningful metrics and dashboards covering security posture, remediation progress, outstanding risks, and overall program effectiveness.
  • Identify gaps in security processes and drive improvements using Risk-Based Vulnerability Management (RBVM) principles.
  • Research, evaluate, and recommend appropriate vulnerability management and penetration testing tools.
  • Produce clear technical reports and communicate complex security findings to both technical and non-technical stakeholders.
  • Collaborate with cybersecurity teams and stakeholders on vulnerability management, penetration testing, and broader security initiatives.
  • Mentor and provide technical guidance to junior security team members.
  • Maintain security baseline governance using appropriate security tooling.
  • Ensure security activities comply with applicable regulatory and organisational requirements.

Vulnerability Management

  • Own and manage the end-to-end vulnerability management lifecycle from discovery and triage through remediation tracking, verification, and closure.
  • Perform risk-based vulnerability assessments to determine actual exposure and remediation priorities.
  • Identify gaps in vulnerability management processes and drive continuous improvement.
  • Lead security reviews and monitoring of production environments across hybrid infrastructure.
  • Track vulnerability remediation activities and ensure findings are addressed within established timelines.
  • Support vulnerability verification and closure activities.
  • Integrate relevant security and vulnerability information with SIEM and monitoring platforms where required.

Penetration Testing

  • Own and manage the end-to-end penetration testing program, including scoping, rules of engagement, execution oversight, findings management, retesting, and closure.
  • Develop and maintain an annual risk-based penetration testing plan.
  • Coordinate penetration testing across external and internal networks, web applications, mobile applications, APIs, cloud environments, wireless environments, social engineering, and red/purple team exercises.
  • Define and maintain penetration testing standards, methodologies, and rules of engagement.
  • Apply recognised security frameworks and methodologies such as OWASP, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Ensure appropriate quality, coverage, and independence of internally and externally delivered penetration testing.
  • Review, triage, and validate penetration testing findings to determine severity, exposure, and remediation priorities.
  • Retest remediated findings to confirm effective closure.
  • Track security exceptions and residual risks through acceptance or resolution.
  • Coordinate independent, threat-led, and scenario-based security testing where required.
  • Ensure penetration testing activities meet applicable regulatory and industry requirements, including MAS Technology Risk Management (TRM) requirements.

Requirements

  • Minimum 7 years of relevant information security or cybersecurity experience.
  • Extensive experience in information security and/or IT risk management.
  • Proven experience owning or managing vulnerability management and/or penetration testing programs.
  • Strong experience establishing security governance processes and managing remediation activities.
  • Strong hands-on experience with vulnerability management, penetration testing, and security engineering.
  • Strong knowledge of Risk-Based Vulnerability Management (RBVM), including vulnerability triage and risk prioritisation.
  • Experience identifying security risks associated with business processes, technology operations, applications, infrastructure, and technology projects.
  • Experience with industry-standard vulnerability management, penetration testing, and Cloud Security Posture Management (CSPM) solutions.
  • Strong hands-on penetration testing experience across network, web, mobile, API, and cloud environments.
  • Experience managing external penetration testing vendors and validating security findings.
  • Working knowledge of OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, Kali Linux, and Cobalt Strike.
  • Working knowledge of scripting or programming languages such as Python, C++, Java, Ruby, Node.js, Go, or PowerShell.
  • Experience with log configuration, log formats, and integration with SIEM platforms.
  • Experience with process optimisation, automation, and ITSM workflow tools.
  • Strong leadership, project management, and team-building capabilities.
  • Ability to lead security initiatives involving multiple teams and departments.
  • Strong communication and stakeholder management skills with the ability to communicate security risks to technical and non-technical audiences.

Education & Certifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred.
  • Professional certifications such as CISSP, CISM, CISA, or SANS/GIAC certifications are preferred.
  • Penetration testing certifications such as OSCP, GPEN, GWAPT, CREST CRT/CCT, or CEH are preferred.
  • Candidates without the preferred certification may be expected to obtain a relevant certification within the required timeframe.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.