jobs in Job Expert

全职 Vulnerability Response Specialist 工作, 薪水, Job Expert Federal Territory 公司招聘中 - Ricebowl

Vulnerability Response Specialist

Undisclosed

KL City, Federal Territory

分享
保存

工作地点

  • Kuala Lumpur Federal Territory Malaysia

职位描述

岗位职责

About the Role

We are looking for an experienced Vulnerability Response Specialist to support a major banking and financial services environment in Kuala Lumpur.

This role focuses on the operational response to critical and high-profile vulnerabilities, including zero-day vulnerabilities, actively exploited threats, and out-of-band (OOB) security events.

The successful candidate will take ownership of vulnerability response activities after assessment and prioritisation, coordinate multiple technical and business stakeholders, and drive remediation through to closure.

This is a highly operational role requiring strong experience in Vulnerability Management, Cyber Incident Response, Remediation Governance, Threat Intelligence, and Major Incident Management.

Key ResponsibilitiesVulnerability Response Management

  • Take operational ownership of notable vulnerabilities following vulnerability assessment and prioritisation.
  • Drive end-to-end response for zero-day, actively exploited, OOB, and other critical vulnerabilities.
  • Coordinate mitigation and remediation activities across multiple technology teams.
  • Establish and lead vulnerability response bridge calls.
  • Execute vulnerability response playbooks and established response procedures.
  • Maintain oversight of critical vulnerabilities until risks are successfully mitigated or remediated.
  • Track actions, owners, deadlines, dependencies, and outstanding risks.

Cyber Incident & Crisis Management

  • Leverage Incident Management processes to accelerate vulnerability remediation.
  • Coordinate with Cyber Defence, Platform Teams, Asset Owners, Technology SMEs, and Incident Management teams.
  • Lead operational response meetings and bridge calls during critical vulnerability events.
  • Provide clear situation reports and executive-level updates.
  • Escalate critical risks, blockers, and delayed remediation activities through appropriate governance channels.
  • Support post-incident reviews and continuous improvement initiatives.

Remediation Governance

  • Drive remediation activities from identification through closure.
  • Track remediation commitments, milestones, dependencies, and residual risks.
  • Challenge and escalate overdue remediation actions.
  • Validate completion of agreed mitigation and remediation activities.
  • Support management reporting on vulnerability exposure, remediation progress, and risk reduction.
  • Support compensating controls and risk treatment plans where immediate remediation is not possible.

24x7 Vulnerability Response

  • Participate in on-call, weekend, after-hours, and follow-the-sun support arrangements.
  • Coordinate response activities during high-severity vulnerability events outside normal business hours.
  • Ensure timely stakeholder mobilisation during zero-day or actively exploited vulnerability events.
  • Support continuous response coverage for critical cyber threats.

Requirements

  • 5–8 years of experience in Vulnerability Management, Cybersecurity Operations, Incident Response, Cyber Defence, Technology Risk, or related areas.
  • Strong knowledge of:
  • Vulnerability Management
  • CVE & CVSS
  • Vulnerability prioritisation
  • Exploitability assessment
  • Threat Intelligence
  • Cyber Risk Management
  • Attack surface exposure
  • Experience translating vulnerability assessments into actionable remediation plans.
  • Experience managing or coordinating Major Incidents, Cyber Incidents, or Technology Incidents.
  • Experience leading bridge calls, action tracking, escalation, and executive reporting.
  • Proven ability to drive remediation across multiple infrastructure and technology teams.
  • Strong understanding of remediation governance, compensating controls, residual risk, and risk treatment.
  • Excellent analytical, problem-solving, communication, and stakeholder management skills.
  • Ability to translate highly technical security vulnerabilities into understandable business risks and remediation priorities.
  • Ability to remain calm and make risk-based decisions during high-pressure security events.
  • Comfortable working independently in a fast-paced, 24x7 operational environment.

Work Location: In person

重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多