← Back to job listings
UG
Information Security (Vulnerability and Penetration )
Unison Group · Singapore
About The Role
Requirements
- Minimum 7 years of relevant security experience.
- Extensive experience in information security and/or IT risk management.
- Proven experience owning and running a vulnerability management and/or penetration testing program, process, and governance forum.
- Demonstrated leadership, project, and team-building skills, including the ability to lead teams and drive projects and initiatives across multiple departments.
- Ability to identify risks associated with business processes, operations, information security programs, and technology projects.
- Ability to communicate with diverse audiences, both technical and non-technical, to build consensus on risk-based vulnerability management and penetration testing.
- Experience with process optimization.
- Experience with process automation and workflow using ITSM tools.
- Hands-on experience with vulnerability management, penetration testing, and security engineering.
- Experience with industry-known vulnerability management, penetration testing, and CSPM solutions.
Vulnerability Management
- Strong knowledge of risk-based vulnerability management, including triage of vulnerabilities to determine "True Risk" exposure to Singlife.
- Experience in log configuration, formats, and feeding logs into SIEM platforms.
Penetration Testing
- Strong hands-on penetration testing background across multiple domains (network, web, mobile, API, and cloud), including managing external PT vendors and triaging and validating penetration test findings.
- Working knowledge of recognized penetration testing methodologies and frameworks (OWASP Testing Guide, PTES, NIST SP 800-115, MITRE ATT&CK) and common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Kali Linux, Cobalt Strike).
- Working knowledge of one or more programming/scripting languages such as Python, C++, Java, Ruby, Node, Go, and/or PowerShell.
Education
- Academic: Bachelor's degree in Computer Science or Information Technology (preferred).
- Professional Certification(s): One or more of CISSP, CISM, CISA, or SANS/GIAC certifications, together with a recognized penetration testing certification such as OSCP, GPEN, GWAPT, CREST (CRT/CCT), or CEH (preferred, or willing to become certified within one year).
Similar roles you might like
See all →UG
Security Engineer Tenable
Unison Group
Salary not disclosedPosted today
UG
Security Engineer
Unison Group
Salary not disclosedPosted today
CC
Engineer (Integrated Digital Tower System)
CAA Civil Aviation Authority of Singapore
Salary not disclosedPosted today
CS
Lead Cybersecurity Consultant (Cybersecurity Certification Centre), CSEC
Cyber Security Agency of Singapore (CSA)
Salary not disclosedPosted 1 day ago
P
Security Engineer
Pelago
Salary not disclosedPosted 1 day ago
JS
DevSecOps Engineer - A26320
Salary not disclosedPosted 2 days ago
NT
Assistant Manager (IT System & Cybersecurity)
Nanyang Technological University
Salary not disclosedPosted 5 days ago
N
Senior Manager, Sales Development
Netskope
Salary not disclosedPosted 6 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
