freehire launches on Product Hunt on 26 August.

Follow →

Senior Vulnerability Management Analyst

Summary

The Senior Vulnerability Management Analyst leads daily vulnerability operations, including scanning, triage, remediation tracking, and reporting. The role involves managing DAST programs, bug bounty activities, and penetration testing while ensuring compliance with regulatory standards like MAS TRM.

Description

  • Lead BAU vulnerability management operations, including vulnerability scanning/discovery, findings triage, remediation SLA tracking, closure follow-up and periodic reporting.
  • Oversee asset coverage and inventory alignment to ensure vulnerability management activities are applied consistently across relevant technology assets.
  • Drive maturity of the DAST testing programme, including onboarding of applications, scan configuration, troubleshooting, authenticated scanning, testing cadence and control improvements.
  • Manage bug bounty and controlled external testing activities, including report review, severity validation, remediation coordination and lessons-learnt analysis.
  • Coordinate annual and ad-hoc penetration testing engagements with internal stakeholders and external vendors, ensuring scope, timelines, deliverables, remediation tracking and closure are managed effectively.
  • Oversee configuration compliance activities, including secure configuration reviews, compliance tracking, exception handling and follow-up with relevant stakeholders.
  • Perform vulnerability risk assessments by considering CVSS, VPR, Asset Exposure Score, DOD/BOD, exploitability, asset criticality, internet exposure, threat intelligence, business impact and existing mitigating controls.
  • Develop and apply risk prioritisation and severity re-classification approaches to ensure remediation efforts focus on the most exploitable and business-critical exposures.
  • Produce vulnerability statistics and high-level analysis, including vulnerability-per-host trends, remediation progress, past-due findings, accepted risks, control gate metrics and programme-level dashboards for management reporting.
  • Escalate overdue, material or high-risk vulnerabilities to relevant technology, business, risk and management stakeholders where remediation progress is not aligned with expected timelines.
  • Support audit and regulatory compliance expectations, including MAS TRM and Cyber Hygiene requirements, by maintaining evidence of regular vulnerability assessment, remediation tracking and risk treatment decisions.
  • Collaborate with threat intelligence and other security teams to act on relevant threat intelligence and emerging vulnerability trends affecting the technology environment.

Qualifications

  • At least 5 years of experience in IT, Information Security, Vulnerability Management, Application Security or related cyber assurance functions, with experience leading BAU vulnerability management activities.
  • Diploma/Degree in Computer Science, Cybersecurity, Information Security Management or related discipline.
  • Professional certifications such as CISSP, CISM, OSCP, GPEN, GWAPT, GWEB, CEH or cloud security certifications will be an advantage.

Skills & Experience

  • Strong working knowledge of vulnerability management lifecycle, including discovery, assessment, prioritisation, remediation tracking, validation and reporting.
  • Experience using vulnerability management, application security testing or exposure management platforms to support enterprise security operations.
  • Good understanding of risk-based prioritisation using factors such as severity, exploitability, asset exposure, business impact and compensating controls.
  • Able to interpret vulnerability data, perform high-level analysis and present clear insights to both technical and management stakeholders.
  • Familiar with common infrastructure, cloud, web application, API and mobile security risks, including secure configuration and application security testing concepts.
  • Effective stakeholder management skills, with the ability to coordinate remediation across technology, business, vendor, risk and management teams.
  • Able to guide, mentor and provide technical direction to junior team members or peers in vulnerability management activities.
  • Scripting, data handling, dashboarding or automation experience will be an advantage.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available