Vulnerability Management Engineer

1 week ago


Singapore ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. Full time

Role: Vulnerability Management Engineer Overview The Vulnerability Management Engineer will oversee the full lifecycle of vulnerabilities—detecting, analyzing, prioritizing, and driving remediation across the organization's applications and infrastructure. This role requires strong technical knowledge of CI/CD pipelines, SSDLC practices, modern scanning technologies, and hands-on automation capabilities to enhance efficiency and coverage. Key Responsibilities Vulnerability Lifecycle Ownership: Lead the end-to-end process from identification and triage to remediation tracking and final reporting, ensuring timely and effective resolution. Tool Integration & Operationalization: Embed and maintain vulnerability scanning capabilities within CI/CD and SSDLC workflows, including solutions for SAST, DAST, secret scanning, and container scanning . Automation Development: Build and maintain automation scripts—preferably in Python —to optimize scanning processes, data collection, analysis, and reporting dashboards. Root Cause & Risk Analysis: Evaluate vulnerabilities to determine underlying causes and recommend practical, long-term security controls. Threat Modeling: Conduct threat modeling sessions using system architecture diagrams and design documents to identify potential attack paths and security gaps. Cross-Team Collaboration: Work closely with engineering, infrastructure, DevOps, and risk teams to support remediation planning and reduce risk exposure. Clear Stakeholder Communication: Translate technical vulnerability details into clear, actionable insights for both technical and non-technical stakeholders, including explanations of business impact and mitigation strategies. Process Improvement: Continuously refine vulnerability management processes, metrics, and tools to strengthen overall security posture and operational efficiency. Requirements Education: Degree in Computer Science, Information Security, or a relevant field. Experience: Hands-on vulnerability management experience within CI/CD or SSDLC environments. Technical Skills: Proficiency with vulnerability scanning tools such as OSS, SAST, and Container Scanning tools . Strong scripting and automation capability, especially using Python . Solid understanding of secure coding standards and common vulnerabilities, including the OWASP Top 10 . Experience performing root cause analysis and developing realistic remediation strategies. Threat Modeling: Familiarity with established threat modeling techniques and tools. Soft Skills: Strong communication skills with the ability to present findings clearly to diverse stakeholders. Effective stakeholder management and the ability to influence remediation decisions. Advantageous: Offensive security certifications such as OSCP, CEH, or GPEN . Experience managing vulnerabilities in large, complex enterprise environments. Knowledge of cloud-native security and securing containerized applications. #J-18808-Ljbffr



  • Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time

    **Executive Summary** Smart IMS Inc provides Digital technology & Cloud transformation services, Application & Infrastructure Management Services, Unified Communications, and Insurance implementation services to customers across the Americas, Europe, Middle East, and Asia-Pacific regions. As the trusted technology and business partner of leading MNCs,...


  • Singapore KRIS INFOTECH PTE. LTD. Full time

    Focal point of contact for Vulnerability Management and related topics - Person will be responsible preparing the Vulnerability Management Plan and the executes plan through all the phases of Vulnerability Management Lifecycle. - Ensures that the Vulnerability scans are scheduled, configured in tool and are executed as per the schedule. Any failure of scans...


  • Singapore NodeFlair Full time

    **Job Summary**: **Salary** S$8,000 - S$14,000 / Monthly EST **Job Type** Permanent **Seniority** Senior Mid **Years of Experience** At least 5 years **Tech Stacks** Docker Go play VMware Java Linux Kubernetes Python - We are seeking a highly motivated Cyber Security Engineer in the Binary Vulnerability Hunting domain to work with our Information...

  • Global Patch

    1 week ago


    Singapore SMART INFORMATION MANAGEMENT SYSTEMS PRIVATE LIMITED Full time

    A dynamic IT services firm in Singapore is looking for a skilled professional in vulnerability management. Responsibilities include planning and coordinating patching for Wintel and Linux servers, handling ad-hoc remediation requests, and collaborating with various teams. The ideal candidate will have a Bachelor's degree, at least 6 years of experience...


  • Singapore ASTEK SINGAPORE INNOVATION TECHNOLOGY PTE. LTD. Full time

    A technology solutions firm in Singapore is seeking a Vulnerability Management Engineer to oversee the full lifecycle of vulnerabilities. The successful candidate will lead vulnerability detection, analysis, and remediation, utilizing tools like OSS and SAST, and will need strong Python scripting skills. Experience in CI/CD environments and effective...


  • Singapore Capgemini Full time

    **_Experience - 7-10 Years_** - Co-ordinate with global VM team to collate APAC vulnerability data for a global bank - Co-ordinate with APAC Technology teams to drive vulnerability remediation in AEJ region - Articulates risk and impact to APAC IT leaders with the proven ability to convey the urgency and need to remediate a vulnerability commensurate with...


  • Singapore Singapore Airlines Full time

    Information Technology - Senior Systems Engineer (Vulnerability Management)Join to apply for the Information Technology - Senior Systems Engineer (Vulnerability Management)role at Singapore Airlines . Job Overview The successful candidate will be part of the Information Security Department within the Information Technology Division. Key Responsibilities...


  • Singapore Jobline Resources Pte Ltd Full time

    **Responsibilities**: - Provide product lifecycle support for customers’ Enterprise IT Network Services - Work closely with Project Manager / Service Delivery Manager to fulfill project deliverables and operational request - Preferably with hands on experience in any of the following areas: - Well-versed in security vulnerability assessments and firmware...


  • Singapore TALENTSIS PTE. LTD. Full time

    A technology services company in Singapore is seeking an AWS Vulnerability Management Engineer to ensure the security of their AWS infrastructure. You will conduct security assessments, implement best practices, and collaborate with teams to address vulnerabilities. Candidates should have strong cloud security experience along with hands-on AWS knowledge....


  • Singapore KRIS INFOTECH PTE. LTD. Full time

    **Responsibilities**: Vulnerability Management: - Conduct regular vulnerability scans and assessments using industry-standard tools and techniques. - Analyze scan results, prioritize vulnerabilities based on risk, and develop comprehensive remediation plans. - Track and report on vulnerability remediation progress, ensuring timely and effective...