Head of Vulnerability Management Jobs in Singapore

    Head of Vulnerability Management

      顾问:
      职位编号
      注册编号
      R1876389
      许可证编号
      16S8060
      功能
      网络安全与 GRC

    We are currently supporting a global client in seeking a senior cybersecurity leader to drive its enterprise Vulnerability Management capability.

    The role will evolve traditional vulnerability management towards a more proactive, threat-informed approach, covering infrastructure, applications, cloud and identity environments.

    主要职责

    • Own the strategy and roadmap for enterprise vulnerability management.
    • Drive continuous visibility and assessment of the organisation’s attack surface across cloud, on-premises, applications and identity.
    • Establish risk-based prioritisation using threat intelligence, exploitability, asset criticality and business impact.
    • Oversee vulnerability scanning, penetration testing, attack-path analysis and breach/attack simulation.
    • Partner with technology teams to drive remediation, address root causes and reduce recurring exposures.
    • Establish vulnerability, remediation and patch-management standards and governance.
    • Develop KRIs, KPIs and management reporting to track exposure and programme effectiveness.
    • Leverage automation, analytics and AI to improve discovery, prioritisation and remediation.
    • Partner with Technology Risk and Audit on assurance and control matters.
    • Build and lead a high-performing team.

    要求:

    • Extensive cybersecurity experience with senior leadership responsibility across vulnerability management, or security assurance.
    • Proven experience building or maturing an enterprise-scale vulnerability management programme.
    • Strong expertise across vulnerability management, attack surface management, penetration testing and exposure validation.
    • Good understanding of threat-informed prioritisation, attack paths and business-criticality-based risk assessment.
    • Experience with threat intelligence, cloud security and security automation.
    • Experience within financial services or another complex regulated environment preferred.
    • Strong senior stakeholder management and communication skills.
    • Relevant certifications such as CISSP, CISM, CRISC, SANS or OffSec would be advantageous.

    申请

    If you’re interested to apply or find out more, please share across your CV or reach out to Chen Yi at cy@kerryconsulting.com for a discussion. Due to anticipated high volume of applications, we regret to inform that only shortlisted candidates will be notified.

    Reg: R1876389

    Lic: 16S8060

    申请此职位