Head of Vulnerability Management
We are currently supporting a global client in seeking a senior cybersecurity leader to drive its enterprise Vulnerability Management capability.
The role will evolve traditional vulnerability management towards a more proactive, threat-informed approach, covering infrastructure, applications, cloud and identity environments.
Key Responsibilities:
- Own the strategy and roadmap for enterprise vulnerability management.
- Drive continuous visibility and assessment of the organisation’s attack surface across cloud, on-premises, applications and identity.
- Establish risk-based prioritisation using threat intelligence, exploitability, asset criticality and business impact.
- Oversee vulnerability scanning, penetration testing, attack-path analysis and breach/attack simulation.
- Partner with technology teams to drive remediation, address root causes and reduce recurring exposures.
- Establish vulnerability, remediation and patch-management standards and governance.
- Develop KRIs, KPIs and management reporting to track exposure and programme effectiveness.
- Leverage automation, analytics and AI to improve discovery, prioritisation and remediation.
- Partner with Technology Risk and Audit on assurance and control matters.
- Build and lead a high-performing team.
Requirements:
- Extensive cybersecurity experience with senior leadership responsibility across vulnerability management, or security assurance.
- Proven experience building or maturing an enterprise-scale vulnerability management programme.
- Strong expertise across vulnerability management, attack surface management, penetration testing and exposure validation.
- Good understanding of threat-informed prioritisation, attack paths and business-criticality-based risk assessment.
- Experience with threat intelligence, cloud security and security automation.
- Experience within financial services or another complex regulated environment preferred.
- Strong senior stakeholder management and communication skills.
- Relevant certifications such as CISSP, CISM, CRISC, SANS or OffSec would be advantageous.
To apply:
If you’re interested to apply or find out more, please share across your CV or reach out to Chen Yi at cy@kerryconsulting.com for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.
Reg: R1876389
Lic: 16S8060

A leading global financial services organisation is looking for...
We are partnering with a leading Singapore-based organization seeking a senior Application Security Architecture leader to drive secure-by-design practices, enterprise security architecture and AI security...
We are looking for an AI Security Specialist to strengthen the organisation’s approach to securing AI adoption and leveraging...
Our client is an established international cybersecurity firm supporting enterprises with complex security challenges. As part of its continued growth in the region, the organisation...
Our client is an established international technology organisation providing enterprise software solutions to customers globally. The business works with large organisations across a range of industries,...
We are seeking an experienced cybersecurity leader to oversee the organisation’s governance, risk, and assurance capabilities. This role is responsible for establishing and maintaining an effective...
A leading international financial institution is seeking an...
We are looking for an experienced Cybersecurity & Technology Risk Manager to lead the organisation’s security, technology risk and resilience agenda across enterprise technology, digital platforms...
We are looking for an experienced Cybersecurity & Technology Risk Manager to lead the organisation’s security, technology risk and resilience agenda across enterprise...
We are seeking an experienced Head of IT & Cybersecurity to lead the strategy, operations, and continuous improvement of the organisation’s IT infrastructure and cybersecurity posture. This...
An international financial institution is seeking an experienced leader to head its local Information Security Coordination and Business Continuity function. This role combines team leadership, information...
The Head of Cyber Operations will lead the organisation’s cyber defence capability, overseeing 24×7 Security Operations, Threat Intelligence, Threat Hunting, Detection Engineering and Incident...
An organisation operating within a large, complex and mission-critical environment is seeking an experienced leader to head its Incident Management & Reporting function.
This role is responsible...
We are seeking an experienced Application Security Risk Manager to provide risk oversight and challenge across application security and technology controls.
The...
Our client is an established international technology organisation providing enterprise software solutions to customers globally. The business works with large organisations across...
We are seeking an experienced cybersecurity leader to oversee the organisation’s governance, risk, and assurance capabilities....
We are seeking a Cybersecurity Architect to join a lean and highly collaborative cybersecurity team. This role will be responsible for defining, designing, and driving the implementation of security...
We’re partnering with a leading organisation to hire an experienced Information Security leader to oversee enterprise security capabilities and lead a team responsible for protecting the organisation’s...
A leading multinational organisation is seeking an experienced Security Architect to drive secure architecture and technology initiatives across a regional environment.
This role will be responsible...
An international financial institution is seeking an experienced leader to head its local Information Security Coordination and...
We are seeking an experienced and forward-thinking AI Security Engineering SME to lead the design, development, and implementation of enterprise-grade AI security solutions. This role sits at the intersection...
We are looking for an experienced Lead Data Security Engineer to design, implement, and enhance enterprise data security capabilities across on-premises and cloud environments. This...
