Editorial summary

The company is seeking an Information Security Engineer (VA/PT) responsible for vulnerability management and penetration testing. The role involves program management, governance, and executing vulnerability assessments and penetration tests to enhance security posture. Key requirements include experience in vulnerability management, penetration testing, and developing security policies. The position offers a salary of 6,000.

This summary is AI-generated and may contain inaccuracies. Please refer to the full job description below.

Job description

[This job id 22615 first appeared in Job-Q.com on 30 Jul 2026]

Role: Information Security (Vulnerability Management and Penetration Testing)

Responsibilities

The role's responsibilities span three core areas: program management and governance across the combined function, day-to-day vulnerability management, and end-to-end penetration testing.

Program Management & Governance

• Build, run, and continuously improve the internal Vulnerability Management and Penetration Testing (VMPT) program and capabilities within the organization.

• Develop and refine the policies, processes, standards, and procedures for vulnerability management, penetration testing, communication, and reporting.

• Lead the triage of vulnerabilities and penetration test findings, taking into consideration compensating controls, threat exposure, and "True Risk" to Singlife, and prioritize remediation accordingly.

• Chair the vulnerability and penetration testing governance forum, driving accountability, tracking remediation SLAs, and escalating overdue or high-risk items to management.

• Manage the internal VMPT program and relationships with external VMPT/PT vendors and other stakeholders across Singlife.

• Establish and report meaningful metrics and dashboards on vulnerability and penetration testing posture, remediation progress, and program effectiveness to management and relevant committees.

• Identify gaps in adjacent processes and procedures and drive improvements from a risk-based vulnerability management (RBVM) and penetration testing perspective.

• Research, develop, and recommend appropriate tooling required for effective risk-based vulnerability management and penetration testing.

• Produce high-quality oral and written work products, presenting complex technical matters and findings clearly and concisely.

• Collaborate with supervisors and other cybersecurity team members on vulnerability management and penetration testing status and findings.

• Mentor and guide the technical development of junior VMPT staff and colleagues.

• Collaborate with stakeholders across the organization on security initiatives.

• Ensure compliance with all applicable laws and regulations relating to the above functional activities.

• Operate and maintain compliance with security baseline governance using appropriate tooling.

Vulnerability Management

• Own and manage the end-to-end vulnerability management process, from discovery and triage through remediation tracking, verification, and closure.

• Identify gaps in RBVM processes and procedures and drive continuous improvement.

• Build and lead the security review and monitoring of production environments across the hybrid infrastructure.

Penetration Testing

• Own and manage the end-to-end penetration testing program, from scoping and rules of engagement through execution oversight, findings management, retesting, and closure with external PT vendors and internal stakeholders.

• Define and maintain the annual, risk-based penetration testing plan, covering test types such as external and internal network, web and mobile application, API, cloud, wireless, social engineering, and red/purple team exercises.

• Set and enforce penetration testing standards, methodologies, and rules of engagement (e.g., OWASP, PTES, NIST SP 800-115, MITRE ATT&CK), and assure the quality, coverage, and independence of internal and vendor-delivered testing.

• Validate and retest remediated penetration test findings to confirm effective closure, and track exceptions and residual risk to acceptance or resolution.

• Ensure penetration testing satisfies regulatory and industry requirements (e.g., MAS TRM), and coordinate independent, threat-led and scenario-based testing where required.

Requirements

• Minimum 7 years of relevant security experience.

• Extensive experience in information security and/or IT risk management.

• Proven experience owning and running a vulnerability management and/or penetration testing program, process, and governance forum.

• Demonstrated leadership, project, and team-building skills, including the ability to lead teams and drive projects and initiatives across multiple departments.

• Ability to identify risks associated with business processes, operations, information security programs, and technology projects.

• Ability to communicate with diverse audiences, both technical and non-technical, to build consensus on risk-based vulnerability management and penetration testing.

• Experience with process optimization.

• Experience with process automation and workflow using ITSM tools.

• Hands-on experience with vulnerability management, penetration testing, and security engineering.

• Experience with industry-known vulnerability management, penetration testing, and CSPM solutions.

Vulnerability Management

• Strong knowledge of risk-based vulnerability management, including triage of vulnerabilities to determine "True Risk" exposure to Singlife.

• Experience in log configuration, formats, and feeding logs into SIEM platforms.

Penetration Testing

• Strong hands-on penetration testing background across multiple domains (network, web, mobile, API, and cloud), including managing external PT vendors and triaging and validating penetration test findings.

• Working knowledge of recognized penetration testing methodologies and frameworks (OWASP Testing Guide, PTES, NIST SP 800-115, MITRE ATT&CK) and common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Kali Linux, Cobalt Strike).

• Working knowledge of one or more programming/scripting languages such as Python, C++, Java, Ruby, Node, Go, and/or PowerShell.

Education

• Academic: Bachelor's degree in Computer Science or Information Technology (preferred).

• Professional Certification(s): One or more of CISSP, CISM, CISA, or SANS/GIAC certifications, together with a recognized penetration testing certification such as OSCP, GPEN, GWAPT, CREST (CRT/CCT), or CEH (preferred, or willing to become certified within one year).

If you are keen to explore the above role, please send across your updated resume to email address and we can discuss to proceed further.

EA Personnel Registration Number: R1112410

Singapore Employment Agency Licence No: 11C3373

Scam prevention reminder: You should not make any pre-payment when applying for any job.

Illegal practices reminder: It is illegal for recruiter to collect payment (kickback) from the worker https://www.mom.gov.sg/-/media/mom/documents/publications/foreign-workers/what-are-kickbacks.pdf

Login is optional, you may send application via email

Login to Save Login to Apply

Get AI to assess your suitability to this job

Assess My Fit with AI Beta — Free during trial period

Login to upload your resume and get an instant match score, strengths, and gaps.


Or use your preferred AI chat tool manually:

Use AI chat of your choice: ChatGPT, Gemini, Claude — and:

  1. Paste this into the prompt:
    I am a jobseeker. Below is a job posting. Please: 1. Give a match score (0–100) based on my resume vs the job requirements 2. List my 3–5 key strengths that align with this role 3. List 2–3 areas to improve or gaps to address before applying 4. Give a one-sentence verdict: should I apply, apply with adjustments, or skip? Job posting URL: https://singapore.job-q.com/jobs/detail/information-security-engineer-va-pt-22615 After reading the job, ask me to upload or paste my resume.
  2. Upload your resume in the same chat.

Similar Jobs

Information Security Engineer

ROLE: Information Security (Security Engineer)Responsibilities Security Measures Implementation and Performance Trackingo Develop...

On site

Contract

HELIUS TECHNOLOGIES PTE. LTD.

Senior Oracle Database Migration Engineer

We are seeking a highly accomplished Senior Oracle Database Migration Engineer to...

On site

Full Time

IKAS INTERNATIONAL (ASIA) PTE. LTD.

Software Engineer (Fullstack Java+ Angular)

Avensys is a reputed global IT professional services company headquartered in Singapore....

On site

Contract

AVENSYS CONSULTING PTE. LTD.

Job Summary

  • Published on: 30 Jul, 2026
  • Category: Information Technology (IT)
  • Vacancy: 1
  • Job type: Contract
  • Salary: 6000
  • Location: On site
  • Job Nature: Contract

Company Details