Senior/Vulnerability Analyst

1 week ago


Singapore INCOME INSURANCE LIMITED Full time
Roles & Responsibilities

The vulnerability analyst will be responsible for performing vulnerability discovery on our internal and external IT infrastructure, web, mobile and web service applications, leveraging both automated tools and manual techniques, and liaising with systems & applications owners on follow up actions.

Key Responsibilities

  • Perform vulnerability scanning/discovery, tracking of remediation SLA and follow up on closure of findings
  • Support private bug bounty and public vulnerability disclosure program by performing triaging and follow up on reports received
  • Coordinate with external vendors on penetration testing program
  • Conduct meetings to communicate the findings and implications to stakeholders
  • Perform vulnerability fix verification in support of the remediation
  • Perform risk assessment and recommend mitigations on vulnerability findings when remediation is not possible
  • Conduct compliance audit on hardening standards
  • Administer security tools and service providers

Qualifications

  • At least 2 - 5 years of experience in Cyber/Information Security
  • Bachelor of Computer Science, Information Technology, Information Security Management or Business Information Systems
  • CISSP, CISM certified is preferred
  • OSCP, CRT, GPEN, GWAPT, CHFI certified is an advantage
  • Hands-on experience on vulnerability assessment tools (eg TenableOne, Qualys, Rapid7)
  • Working knowledge on industry standard scoring models such as CVSS, EPSS
  • Working knowledge on SAST, DAST, IAST, SCA and DevSecOps
  • Familiarity with penetration testing techniques is an advantage (eg web application proxies, packet capture analysis software, browser extensions, penetration testing Linux distributions, static source code analyzers, SoapUI, etc)
  • Basic structured programming or scripting skills as C, Java, Python, Javascript, Powershell
Tell employers what skills you have

Web Service
Remediation
Risk Assessment
Qualys
Powershell
Scripting
JavaScript
Information Technology
Penetration Testing
Hardening
Information Security Management
Java
Vulnerability Assessment
Linux
CISSP
  • Senior Threat

    11 hours ago


    Singapore ALLEN & OVERY LLP Full time

    **It’s Time** Allen & Overy is a leading global law firm operating in over thirty countries. By turning our insight, technology and talent into ground-breaking solutions, we’ve earned a place at the forefront of our industry. Our lawyers are leaders in their field - and the same goes for our support teams. Ambitious, driven and open to fresh...


  • Singapore SEARCH STAFFING SERVICES PTE. LTD. Full time

    We are currently working with a German MNC client; looking for a Vulnerability Analyst, IT with cybersecurity work experience to join them. **Vulnerability Analyst, IT **Responsibilities**: - As part of the vulnerability management team you will help to identify, prioritize, and track findings - Work closely with many different departments in order to...


  • Singapore INCOME INSURANCE LIMITED Full time

    Roles & Responsibilities The vulnerability analyst will be responsible for performing vulnerability discovery on our internal and external IT infrastructure, web, mobile and web service applications, leveraging both automated tools and manual techniques, and liaising with systems & applications owners on follow up actions. Key Responsibilities Perform...


  • Singapore UOB Full time

    Overview Manager, Vulnerability Mgt Analyst role at UOB We are looking for a skilled Vulnerability Management Analyst to join our team. The successful candidate will be responsible for identifying, assessing, and mitigating potential security risks in our systems and networks. This role requires a strong understanding of network protocols, system...


  • Singapore UOB Full time

    Overview Manager, Vulnerability Mgt Analyst role at UOB We are looking for a skilled Vulnerability Management Analyst to join our team. The successful candidate will be responsible for identifying, assessing, and mitigating potential security risks in our systems and networks. This role requires a strong understanding of network protocols, system...


  • Singapore SEDHA CONSULTING PTE. LTD. Full time

    **Vulnerability Assessment Analysts** **Job Scope**: - Perform scans and audits of systems to identify and categorize vulnerabilities. - Utilize various tools and software to systematically evaluate the security posture of IT infrastructures. - Analyse vulnerability reports and prioritize findings based on risk. **Qualifications**: - Strong understanding...


  • Singapore Randstad Singapore Full time

    Security Vulnerability Management Analyst | APAC | Regional Join us to apply for the Security Vulnerability Management Analyst | APAC | Regional role at Randstad Singapore . Job Details 2 days ago | Be among the first 25 applicants Get AI-powered advice on this job and access more exclusive features. Responsibilities Own the full vulnerability...


  • Singapore Randstad Singapore Full time

    Security Vulnerability Management Analyst | APAC | Regional Join us to apply for the Security Vulnerability Management Analyst | APAC | Regional role at Randstad Singapore . Job Details 2 days ago | Be among the first 25 applicants Get AI-powered advice on this job and access more exclusive features. Responsibilities Own the full vulnerability...


  • Singapore beBeeInformation Full time $90,000 - $120,000

    Job Title: Senior Information Security AnalystOur organization seeks a highly skilled Senior Information Security Analyst to lead efforts in vulnerability management and ensure the execution of information security directives.The ideal candidate will possess strong analytical skills, advanced proficiency with Microsoft Office, and excellent written and...


  • Singapore Income Insurance Limited Full time

    Responsibilities Perform vulnerability scanning/discovery, tracking of remediation SLA and follow up on closure of findings Support private bug bounty and public vulnerability disclosure program by performing triaging and follow up on reports received Coordinate with external vendors on penetration testing program Conduct meetings to communicate the findings...