POSITION OBJECTIVE
Operate a centralized vulnerability management process: receive and process results from VA/scan, pentest, internal red team, DevSecOps and third-party assessments; triage, track remediation SLA, consolidate metrics/dashboard for all products.
JOB DESCRIPTION
1. Operate Vulnerability Management Process
- Receive and consolidate vulnerabilities from all sources: VA/scan, internal pentest and red team, DevSecOps (SAST/DAST/SCA), and third-party assessments.
- Triage, score CVSS, classify and assign remediation owners.
2. Track SLA and Coordinate Remediation
- Track remediation progress against SLA, escalate overdue cases.
- Coordinate with development/operations teams and stakeholders to ensure remediation.
3. Metrics, Dashboard and Reporting
- Build and maintain vulnerability risk dashboard.
- Provide periodic reports to Product Security Lead/CISO.
4. Coordinate Third-Party Assessments
- Coordinate outsourced assessment rounds (pentest, red team, audit): prepare scope, identify points of contact, track progress.
- Receive, standardize and input findings into vulnerability management system; track remediation.
5. Asset Management and Periodic Scanning
- Maintain asset inventory and periodic vulnerability scanning schedule.
- Update threat intelligence and KEV list.
CANDIDATE PROFILE
1. Education:
- Bachelor's degree in IT, Information Security or related field; equivalent practical experience may substitute.
- CompTIA Security+, GIAC (GEVA/GCVM), CEH (preferred).
- Threat intelligence / AI security certification is an advantage.
2. Experience:
- Minimum 2 years of experience.
3. Knowledge and Professional Skills:
3.1. Professional Skills
- 2+ years of vulnerability management/security operations.
- Vuln scanner: Nessus, Qualys, Rapid7.
- Understand CVSS, CVE, KEV, EPSS; OWASP Top 10.
- Understand container/image vulnerability scanning (e.g. Trivy) and cloud scanning (CSPM).
- Data/dashboard skills (Excel/Power BI/SQL); ITSM process (Jira/ServiceNow).
- Programming/scripting (Python) is an advantage.
3.2. Industry Skills
- Understanding of financial/regulated environment is an advantage.
- Understand ISO 27001, PCI-DSS.
3.3. Digital Skills
- Use AI to classify and prioritize vulnerabilities, automate reporting.
- SBOM and VEX as exposure data sources; threat intelligence.
4. Other Requirements
- Independently operate vulnerability management process and coordinate PSIRT under guidance; prioritize risks based on data; coordinate multiple parties on remediation.
- Good reporting and communication skills.
BENEFITS AND TREATMENT
- Flexible and Competitive Compensation: Receive fixed salary commensurate with capability and attractive performance-based bonuses based on actual contribution to projects.
- Clear career development roadmap
- Benefits and working conditions: Active Cool-down transition mechanism: After campaigns or continuous long-term projects, the company prioritizes creating space and time for you to transition to rest, training and energy recovery, preparing for the next steps.
- Full insurance, healthcare and benefits according to State regulations and the Group's exclusive policies.
- Open, transparent and fully digitalized working environment.
- Premium health insurance package and 24/24 accident insurance beyond BHXH, BHYT, BHTN as per State regulations
- Training programs for personal capability development, team engagement programs, retreats, teambuilding.
