Checking job availability...
Original
Simplified
- Establish metrics and KPIs: Develop clear metrics (e.g., average time-to-patch, severity-based closure rates) and set targets for improving your organization’s risk posture.
- Draft and maintain policies, standards, and procedures that articulate how the organization identifies, prioritizes, and remediates vulnerabilities.
- Analyse, prioritize, and collate vulnerability scan results for APAC, EMEA, and North America.
- Collaborate with regional Risk Remediation Leads to ensure vulnerabilities are addressed.
- Act as the Risk Remediation Lead in specific regions when required (e.g., Singapore).
- Work closely with various IT and security teams to implement fixes.
- Perform and operate monthly vulnerability scans across the global enterprise.
- Configure scans optimally, providing justifications for scan settings and recommendations.
- Schedule and troubleshoot scans while ensuring they do not cause system outages.
- Track and report on Known Exploited Vulnerabilities (KEV) and other Critical and High severity vulnerabilities.
- Provide quantifiable metrics and visual reporting (graphs, statistics) to demonstrate remediation progress and quantities of vulnerabilities.
- Ensure the vulnerability management program operates efficiently.
- Identify and implement vulnerability management program enhancements annually to improve risk reduction.
- Bachelor’s Degree in Information Technology / Cybersecurity and Forensics or equivalent professional experiences.
- Possessed cybersecurity professional certifications such as; CISSP, CEH, SANS GIAC, Microsoft, Cisco & etc.
- 5 to 7 years of progressive experience in at least one of the following disciplines:
- Vulnerability Management (program design, scanning, reporting, remediation coordination
- Network Security & Architecture (TCP/IP, firewalls, IDS/IPS, endpoint security)
- Risk Prioritization & Scoring (e.g., CVSS, zero-day threat analysis, environment-specific risk ranking)
- IT/Security Engineering (securing Windows, Linux, and cloud platforms, deploying security tools)
- Compliance & Regulatory Frameworks (PCI-DSS, ISO 27001, NIST, etc.)
- Demonstrated ability to translate technical vulnerabilities and remediation actions into clear, actionable tasks for diverse audiences (IT, DevOps, leadership).
- Experience working with vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7) and application security testing (SAST, DAST) is highly preferred.
- Familiar with cloud environments (AWS, Azure, GCP) and scripting/automation (e.g., Python, PowerShell, or API integrations) is a plus.
- Establish metrics and KPIs: Develop clear metrics (e.g., average time-to-patch, severity-based closure rates) and set targets for improving your organization’s risk posture.
- Draft and maintain policies, standards, and procedures that articulate how the organization identifies, prioritizes, and remediates vulnerabilities.
- Analyse, prioritize, and collate vulnerability scan results for APAC, EMEA, and North America.
- Collaborate with regional Risk Remediation Leads to ensure vulnerabilities are addressed.
- Act as the Risk Remediation Lead in specific regions when required (e.g., Singapore).
- Work closely with various IT and security teams to implement fixes.
- Perform and operate monthly vulnerability scans across the global enterprise.
- Configure scans optimally, providing justifications for scan settings and recommendations.
- Schedule and troubleshoot scans while ensuring they do not cause system outages.
- Track and report on Known Exploited Vulnerabilities (KEV) and other Critical and High severity vulnerabilities.
- Provide quantifiable metrics and visual reporting (graphs, statistics) to demonstrate remediation progress and quantities of vulnerabilities.
- Ensure the vulnerability management program operates efficiently.
- Identify and implement vulnerability management program enhancements annually to improve risk reduction.
- Bachelor’s Degree in Information Technology / Cybersecurity and Forensics or equivalent professional experiences.
- Possessed cybersecurity professional certifications such as; CISSP, CEH, SANS GIAC, Microsoft, Cisco & etc.
- 5 to 7 years of progressive experience in at least one of the following disciplines:
- Vulnerability Management (program design, scanning, reporting, remediation coordination
- Network Security & Architecture (TCP/IP, firewalls, IDS/IPS, endpoint security)
- Risk Prioritization & Scoring (e.g., CVSS, zero-day threat analysis, environment-specific risk ranking)
- IT/Security Engineering (securing Windows, Linux, and cloud platforms, deploying security tools)
- Compliance & Regulatory Frameworks (PCI-DSS, ISO 27001, NIST, etc.)
- Demonstrated ability to translate technical vulnerabilities and remediation actions into clear, actionable tasks for diverse audiences (IT, DevOps, leadership).
- Experience working with vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7) and application security testing (SAST, DAST) is highly preferred.
- Familiar with cloud environments (AWS, Azure, GCP) and scripting/automation (e.g., Python, PowerShell, or API integrations) is a plus.