Vulnerability Management & Penetration Testing Lead

FPT ASIA PACIFIC PTE. LTD.Singaporemycareersfuturepublished 09/30/2026
Must-have:PythonJavaRubyNode.jsCloudMobileSecurityLeadJuniorHybrid

Role Overview

We are seeking an experienced Information Security professional to lead Vulnerability Management and Penetration Testing (VMPT) activities across the organisation.

The role covers three core areas: VMPT program management and governance, end-to-end vulnerability management, and penetration testing. The successful candidate will drive a risk-based approach to identifying, assessing, prioritising, and remediating security vulnerabilities across applications, infrastructure, and cloud environments.

Key Responsibilities

Program Management & Governance

  • Build, manage, and continuously improve the Vulnerability Management and Penetration Testing (VMPT) program and capabilities.
  • Develop and enhance policies, processes, standards, and procedures covering vulnerability management, penetration testing, communication, and reporting.
  • Lead the triage and prioritisation of vulnerabilities and penetration testing findings based on threat exposure, compensating controls, business impact, and overall risk.
  • Lead vulnerability and penetration testing governance forums, driving accountability and tracking remediation against defined SLAs.
  • Escalate overdue, critical, or high-risk security findings to relevant stakeholders and management.
  • Manage relationships with external vulnerability management and penetration testing vendors.
  • Establish meaningful metrics and dashboards covering security posture, remediation progress, outstanding risks, and overall program effectiveness.
  • Identify gaps in security processes and drive improvements using Risk-Based Vulnerability Management (RBVM) principles.
  • Research, evaluate, and recommend appropriate vulnerability management and penetration testing tools.
  • Produce clear technical reports and communicate complex security findings to both technical and non-technical stakeholders.
  • Collaborate with cybersecurity teams and stakeholders on vulnerability management, penetration testing, and broader security initiatives.
  • Mentor and provide technical guidance to junior security team members.
  • Maintain security baseline governance using appropriate security tooling.
  • Ensure security activities comply with applicable regulatory and organisational requirements.

Vulnerability Management

  • Own and manage the end-to-end vulnerability management lifecycle from discovery and triage through remediation tracking, verification, and closure.
  • Perform risk-based vulnerability assessments to determine actual exposure and remediation priorities.
  • Identify gaps in vulnerability management processes and drive continuous improvement.
  • Lead security reviews and monitoring of production environments across hybrid infrastructure.
  • Track vulnerability remediation activities and ensure findings are addressed within established timelines.
  • Support vulnerability verification and closure activities.
  • Integrate relevant security and vulnerability information with SIEM and monitoring platforms where required.

Penetration Testing

  • Own and manage the end-to-end penetration testing program, including scoping, rules of engagement, execution oversight, findings management, retesting, and closure.
  • Develop and maintain an annual risk-based penetration testing plan.
  • Coordinate penetration testing across external and internal networks, web applications, mobile applications, APIs, cloud environments, wireless environments, social engineering, and red/purple team exercises.
  • Define and maintain penetration testing standards, methodologies, and rules of engagement.
  • Apply recognised security frameworks and methodologies such as OWASP, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Ensure appropriate quality, coverage, and independence of internally and externally delivered penetration testing.
  • Review, triage, and validate penetration testing findings to determine severity, exposure, and remediation priorities.
  • Retest remediated findings to confirm effective closure.
  • Track security exceptions and residual risks through acceptance or resolution.
  • Coordinate independent, threat-led, and scenario-based security testing where required.
  • Ensure penetration testing activities meet applicable regulatory and industry requirements, including MAS Technology Risk Management (TRM) requirements.

Requirements

  • Minimum 7 years of relevant information security or cybersecurity experience.
  • Extensive experience in information security and/or IT risk management.
  • Proven experience owning or managing vulnerability management and/or penetration testing programs.
  • Strong experience establishing security governance processes and managing remediation activities.
  • Strong hands-on experience with vulnerability management, penetration testing, and security engineering.
  • Strong knowledge of Risk-Based Vulnerability Management (RBVM), including vulnerability triage and risk prioritisation.
  • Experience identifying security risks associated with business processes, technology operations, applications, infrastructure, and technology projects.
  • Experience with industry-standard vulnerability management, penetration testing, and Cloud Security Posture Management (CSPM) solutions.
  • Strong hands-on penetration testing experience across network, web, mobile, API, and cloud environments.
  • Experience managing external penetration testing vendors and validating security findings.
  • Working knowledge of OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK.
  • Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, Kali Linux, and Cobalt Strike.
  • Working knowledge of scripting or programming languages such as Python, C++, Java, Ruby, Node.js, Go, or PowerShell.
  • Experience with log configuration, log formats, and integration with SIEM platforms.
  • Experience with process optimisation, automation, and ITSM workflow tools.
  • Strong leadership, project management, and team-building capabilities.
  • Ability to lead security initiatives involving multiple teams and departments.
  • Strong communication and stakeholder management skills with the ability to communicate security risks to technical and non-technical audiences.

Education & Certifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred.
  • Professional certifications such as CISSP, CISM, CISA, or SANS/GIAC certifications are preferred.
  • Penetration testing certifications such as OSCP, GPEN, GWAPT, CREST CRT/CCT, or CEH are preferred.
  • Candidates without the preferred certification may be expected to obtain a relevant certification within the required timeframe.