AVP/VP, Cyber Security - Vulnerability Management
- Location
- Singapore
- Salary Package
- Negotiable
- Posted
- 20th Jul 2026
- Consultants
- Elmer Tan
Our client is looking for an AVP/VP to own vulnerability management across the enterprise. This is a hands-on role for someone who wants to be close to the technical work while also engaging stakeholders across IT and business units.
About the Role
You will be responsible for identifying, assessing, and driving remediation of security vulnerabilities across the organisation's infrastructure, applications, and cloud environments. You'll work closely with infrastructure, application, and DevOps teams to ensure vulnerabilities are tracked and closed within agreed timelines, while also shaping how the vulnerability management programme matures over time.
What You'll Do
- Run the end-to-end vulnerability management lifecycle - scanning, triage, risk scoring, remediation tracking, and closure verification
- Prioritise vulnerabilities based on exploitability, business criticality, and threat intelligence, rather than relying on raw severity scores alone
- Partner with infrastructure, application, and cloud teams to drive timely patching and remediation, escalating overdue items to relevant stakeholders
- Maintain and refine vulnerability management policies, SLAs, and reporting frameworks
- Produce regular risk dashboards and reports for technology and business leadership
- Support penetration testing and red team exercises by tracking findings through to remediation
- Evaluate and tune vulnerability scanning tools and processes to improve coverage and reduce noise
- Stay current on emerging threats and CVEs relevant to the organisation's technology stack, and assess exposure proactively
- Contribute to audits and reviews relating to vulnerability and patch management
- Mentor junior analysts and contribute to building out the vulnerability management capability
What We're Looking For
- Solid hands-on experience in vulnerability management
- Working knowledge of vulnerability scanning tools, patch management processes, and risk-based prioritisation approaches
- Familiarity with common vulnerability frameworks and scoring systems (e.g. CVSS)
- Understanding of cloud and on-premise infrastructure security considerations
- Strong stakeholder management skills, with the ability to influence remediation timelines across technical and non-technical teams
- Good written and verbal communication skills, particularly for reporting to senior stakeholders
- A proactive, ownership-driven mindset - comfortable both executing and improving process
EA Licence: 16S8091
EA Reg No.: R1656500