jobs in Ensign InfoSecurity

Ensign InfoSecurity Hiring! Full Time Vulnerability Operations Engineer in - Ricebowl

Vulnerability Operations Engineer

Undisclosed

Singapore

Share
Save

Working Location

  • Singapore

Job Description

Responsibilities

As a Vulnerability Ops Engineer, you will play a crucial role in implementing Ensign's cybersecurity vision by running our enterprise vulnerability management programme and driving its evolution into Continuous Threat Exposure Management (CTEM). Reporting to the Information Security Office, you will be at the operational centre of how we find, prioritise, and eliminate exposures across our infrastructure, applications, and cloud estate, assessing inherent risk and driving remediation decisions together with system owners.


Your primary focus is enterprise-wide impact analysis, risk-based prioritisation, and the rapid coordination of remediation. By leveraging advanced automation and frontier AI models, you will accelerate vulnerability research and analysis while maintaining the validation discipline that keeps AI-assisted work trustworthy and auditable. You will thrive in a dynamic, operationally focused environment where your work directly reduces the organisation's exposure to real-world adversaries.


Responsibilities

  • Enterprise Vulnerability Management: Operate and continuously improve our vulnerability management platforms and scanning infrastructure, ensuring reliable assessment coverage across on-premise, cloud, and application estates.
  • Exposure Management (CTEM): Drive the evolution from point-in-time vulnerability management to Continuous Threat Exposure Management: scope the attack surface, discover exposures across software vulnerabilities, cloud and configuration posture, and external attack surface, validate exploitability, and mobilise remediation through ticketed workflows with measurable programme metrics.
  • Risk & Impact Analysis: Prioritise exposures using threat-informed, risk-based methods. Assess threat actor intelligence, exploit code, and proof-of-concept code to determine realistic attack vectors.
  • Cloud Security Posture: Monitor and remediate cloud misconfigurations through Cloud Security Posture Management (CSPM) tooling, partnering with infrastructure teams to keep secure configurations in place across a cloud-majority estate.
  • Coverage Assurance & Asset Reconciliation: Reconcile scanner-discovered assets against the asset register to close visibility gaps, report coverage ratios, and ensure no critical system sits outside assessment scope.
  • Remediation Coordination: Act as the coordination point between system owners, operations teams, and external vendors to drive timely risk reduction; manage remediation through ticketing workflows, track service-level agreement (SLA) compliance, and maintain the risk-exception register.
  • AI-Assisted Security Operations: Leverage frontier AI models and advanced automation to accelerate vulnerability research, root-cause analysis, and workflow efficiency, validating AI outputs before action and handling operational data according to its classification.
  • Operational Reporting: Maintain comprehensive tracking of remediation performance, time-to-patch, exceptions, and exposure metrics, providing actionable management reporting to senior technology leadership.


Requirements

  • Degree in Cybersecurity, Computer Science, Information Systems, or an equivalent technical field of study.
  • Minimum 3 years of experience in vulnerability management, security operations, or exposure management.
  • Hands-on experience with enterprise vulnerability management platforms (Tenable strongly preferred), including scan architecture, authenticated scanning, and coverage tuning.
  • Strong foundation in vulnerability management methodologies and risk-based prioritisation frameworks (CVE, CVSS, KEV, EPSS).
  • Strong understanding of cloud environments (public, private, and hybrid) and familiarity with cloud security posture management.
  • Experience managing remediation through ticketing workflows (Jira / Jira Service Management or equivalent), including SLA tracking and exception handling.
  • Experience with frontier AI models (e.g. Anthropic, OpenAI, or similar) and the demonstrated ability to conduct AI-assisted vulnerability research, log analysis, or script generation, with strong output-validation habits.
  • Proficiency in scripting and automation to integrate security platforms and streamline operations.
  • Clear written and verbal communication skills for cross-team coordination and management reporting.
  • Operationally focused mindset with the ability to thrive in a dynamic, fast-paced environment centred on timely risk reduction.


Additional Experience/Knowledge (Good to haves)

  • Experience integrating automated security checks and vulnerability testing into CI/CD pipelines and the software development lifecycle, with knowledge of DevOps tooling (Git, Docker, Kubernetes).
  • Aptitude for vulnerability research and exploit development, demonstrated professionally or through Capture the Flag (CTF) challenges.
  • Experience with external attack surface management (EASM) or automated security validation tools.
  • Comfort working with data through APIs, JSON, and query languages (e.g. SQL) to automate reporting and analysis.
  • Professional certifications in vulnerability management or offensive security (e.g. Tenable certifications, CISSP, GIAC, OSCP).
  • Experience in a Linux environment, deploying applications to the cloud, or an intermediate understanding of N-tier architecture.


Important Information

Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.

Learn More