Crowdsourced Vulnerability Discovery Programme Operations Manager

3 days ago


Singapore Public Service Division Full time

(What the role is)GovTech is the lead agency driving Singapore's Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government's capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity. At GovTech, we offer you a purposeful career to make lives better where we empower our people to master their craft through robust learning and development opportunities all year round. Play a part in Singapore's vision to build a Smart Nation and embark on your meaningful journey to build tech for public good. Join us to advance our mission and shape your future with us todayLearn more about GovTech at tech.gov.sg. (What you will be working on)Do you want to play a critical role in securing our smart nation initiatives by uncovering weaknesses in various domains of cybersecurity programs even before the real threat actors come to play? And are you up to race against the real threat actors before organisations are compromised?We seek an experienced cybersecurity professional to lead our Crowdsourced Vulnerability Discovery Programme (CVDP) triage team. The role encompasses managing daily operations, leading a team of triage specialists, and ensuring effective handling of vulnerability reports across government systems for the Government Bug Bounty Programme (GBBP), Vulnerability Disclosure Programme (VDP), and Vulnerability Rewards Programme (VRP) for Whole-of-Government (WoG). Key Responsibilities Team Leadership & Operations Lead and mentor a team of CVD triage specialists, providing technical guidance and ensuring optimal performance in vulnerability assessment and management Operational planning of day-to-day tasks and development of the team's technical capabilities and soft skills Foster a supportive and collaborative team environment with strong commitment to mentoring team members Programme Management Lead the conduct of 6 runs of GBBP and Pre-GBBP per year Lead continuous VDP and VRP operations Lead the CVD team in performing technical and impact analysis of reported vulnerabilities for GBBP, VDP and VRP Lead the CVD team in performing in-depth testing on agencies' patches for all CVD programmes Technical & Strategic Functions Prepare and present materials for bounty approval Develop and deliver presentations on notable vulnerabilities identified through programmes for cross‐team sharing, SLM sharing, or forums Conduct technical sharing of vulnerabilities arising from the programmes to internal and external stakeholders Perform analysis on data and payloads of reports to derive insights, statistics, and trends to advise various stakeholders Devise global solutions for recurring vulnerabilities Process & Documentation Review and maintain standard operating procedures (SOPs) for the vulnerability triage process Continuously improve existing processes and SOPs Develop comprehensive documentation for triage processes Prepare regular vulnerability trends and operational metrics reports Stakeholder Management Interface with agencies for clarification Manage stakeholder relationships across government agencies, system owners, and security researchers Provide technical support to the Programme Team Oversee integration and maintenance of key platforms What we are looking for Degree in Cybersecurity, Computer Science, Information Systems, Computer Engineering, Information Security, or related technical field OSCP certification (mandatory)Minimum 3-5 years' experience in cybersecurity, penetration testing, or web penetration testing At least 2 years' team leadership or management experience Technical experience in performing web penetration testing or similar skills Understanding of basic cybersecurity principles and concepts Must have legal authorisation to work in Singapore Advantageous Qualifications Professional certifications ( OSWE, GPEN, CISSP)Experience with bug bounty programmes or vulnerability coordination Previous experience with government systems Background in technical team leadership Required Skills Comprehensive understanding of web application security and vulnerability assessment Experience with vulnerability management platforms and bug tracking systems Excellent project management and team leadership abilities Strong analytical and problem‐solving capabilities Outstanding communication and stakeholder management skills Good command of English (oral and written)Ability to perform under pressure and manage critical incidents Positive attitude and collaborative leadership style Demonstrated ability to foster a supportive and collaborative team environment Strong commitment to mentoring team members and promoting mutual support within the team GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe that diversity is the foundation to innovation. Our employee benefits are based on a total rewards approach, offering a holistic and market‐competitive suite of perks. These include leave benefits to meet your work‐life needs and employee wellness programmes. We champion flexible work arrangements (subject to your job role) and trust that you will manage your own time to deliver your best, wherever you are, and whatever works best for you. Learn more about life inside GovTech at go.gov.sg/GovTechCareers. Stay connected with us on social media at go.gov.sg/ConnectWithGovTech. #J-18808-Ljbffr



  • Singapore Capgemini Full time

    **_Experience - 7-10 Years_** - Co-ordinate with global VM team to collate APAC vulnerability data for a global bank - Co-ordinate with APAC Technology teams to drive vulnerability remediation in AEJ region - Articulates risk and impact to APAC IT leaders with the proven ability to convey the urgency and need to remediate a vulnerability commensurate with...


  • Singapore Ensign InfoSecurity Full time

    Ensign is hiring ! **Responsibilities**: - Develop and enhance processes and tools for the discovery and triage of vulnerabilities - Research into new vulnerability discovery techniques and processes - Requirements: - Bachelor's degree in a computer science or engineering field or equivalent a minimum of 3 years of relevant experience - Up-to-date...


  • Singapore Government Technology Agency Full time $120,000 - $200,000 per year

    [What the role is]GovTech is the lead agency driving Singapore's Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government's capabilities in Data Science & Artificial Intelligence, Application Development, Smart City...


  • Singapore Income Insurance Limited Full time

    Responsibilities Perform vulnerability scanning/discovery, tracking of remediation SLA and follow up on closure of findings Support private bug bounty and public vulnerability disclosure program by performing triaging and follow up on reports received Coordinate with external vendors on penetration testing program Conduct meetings to communicate the findings...


  • Singapore MATRIX PROCESS AUTOMATION PTE. LTD. Full time

    The Vulnerability and Patch Management Specialist will play a leading role in driving information security analysis and vulnerability remediation. This position will report to the Head of Operations. This role is a key business enabler to provide information security risk analysis and strategic recommendations for the ongoing improvement of Information...


  • Singapore TENTEN Partners Pte. Ltd. Full time

    **An eminent Asian banking institution is seeking a seasoned Vulnerability Management Specialist to fortify its cybersecurity operations. If you're a driven leader with expertise in threat and vulnerability management, this could be your opportunity to make a substantial impact.** **Responsibilities**: - Own and drive a comprehensive vulnerability...


  • Singapore ITCAN Pte Ltd Full time

    Has experience with Vulnerability Management - Is a self-starter and a team-player - Has working knowledge of EASM Space - Technical Skills: - 3-5 years of experience in IT with a recent focus on cyber security or related fields - Strong knowledge of network protocols, architecture, and security measures. - Proficiency in configuring and managing firewalls,...


  • Singapore KRIS INFOTECH PTE. LTD. Full time

    **Responsibilities**: Vulnerability Management: - Conduct regular vulnerability scans and assessments using industry-standard tools and techniques. - Analyze scan results, prioritize vulnerabilities based on risk, and develop comprehensive remediation plans. - Track and report on vulnerability remediation progress, ensuring timely and effective...

  • Programme Manager

    4 days ago


    Singapore HOME FOR GOOD, SINGAPORE LTD. Full time

    **Job Title: Programme Manager** **Location: Singapore (Hybrid Work Arrangement)** **Organisation: Home for Good, Singapore (HFG-SG)** **About Us**: Home for Good, Singapore (HFG-SG) is an IPC-registered charity committed to building a strong, supportive network of foster families, alongside dedicated volunteers, to provide safe and nurturing homes for...


  • Singapore SEATRIUM (SG) PTE. LTD. Full time $120,000 - $240,000 per year

    ResponsibilitiesKnow the vulnerability management lifecycle, including identification, assessment, reporting, prioritization, and remediation.Lead the development, implementation, and continuous improvement of vulnerability management processes and tools.Serve as the subject matter expert (SME) for vulnerability risk, patching standards, and remediation...