Senior Manager, Threat and Vulnerability Management
Tentang pekerjaan
Rangkuman Get Karier, bukan salinan iklan aslinyaAirAsia mencari Senior Manager Threat and Vulnerability Management di Sepang, Selangor. Tugasnya memegang program manajemen kerentanan di lingkungan multi-cloud dan sistem lama, mengatur penetration testing dan red teaming, membangun program threat intelligence dan threat hunting, serta memimpin tim analis kerentanan dan penetration tester. Iklannya tidak menyebut angka gaji.
Kualifikasi
Yang perlu kamu siapkan, versi ringkas- Wajib: 10+ tahun di cyber security, fokus pada vulnerability management, penetration testing, threat intelligence, dan red teaming.
- Paham mekanisme exploit, kerangka skor risiko (CVSS, EPSS), keamanan cloud, dan arsitektur jaringan.
- Wajib: sarjana ilmu komputer, keamanan informasi, atau bidang teknis terkait.
- Terbukti memimpin tim dan memengaruhi keputusan di semua level.
- Sangat diutamakan: sertifikasi seperti OSCP, GXPN, GPEN, CISSP, atau CISM.
Deskripsi & syarat asli
Teks asli dari perusahaan, apa adanya. Tidak kami terjemahkan atau ubah.Job Description WHAT YOU'LL DO: Vulnerability Assessment & Management Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments. Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics. Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.
Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership. Penetration Testing & Red Teaming Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises. Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.
Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed. Threat Intelligence & Threat Hunting Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework). Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.
Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines. Stakeholder Management & Strategic Leadership Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors. Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.
Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds). Team Leadership and Development Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers. Provide hands-on technical guidance during complex technical deep-dives, exploit evaluations, and attack surface reviews.
Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains. WHO YOU ARE: 10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming. Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.
Bachelor's degree in Computer Science, Information Security, or a related technical field. Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights. Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous. We are all different - one talent to another - that is how we rely on our differences.
At AirAsia, you will be treated fairly and given all chances to be your best.We are committed to creating a diverse work environment and are proud to be an equal opportunity employer. Search Firm Representatives - AirAsia does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place will be deemed the sole property of our company.
No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place.
Keyword CV dan Analisis Get Karier
Dua bagian, kekunci bareng
Dua bagian ini buat member
Hard skill dan soft skill yang diminta lowongan ini, siap disalin ke CV kamu. Plus analisis Get Karier: jalur visa dan aturan izin kerja di negaranya, bukti yang perlu terlihat di CV, dan langkah persiapannya, lengkap dengan sumbernya.
Masuk atau daftar gratisKeyword buat CV kamu
Diambil langsung dari deskripsi asli di atasSistem ATS menyaring lamaran dengan mencocokkan kata. CV yang isinya bagus pun bisa gugur kalau kata yang dicari tidak ada di dalamnya. Klik keyword mana pun untuk menyalin, lalu pakai yang memang kamu kuasai.
Analisis Get Karier
Status visa & sponsorshipAnalisisnya belum bisa dimuat
Coba muat ulang halaman ini. Kalau masih kosong, kabari hi@getkarier.com.
Dari Get Karier
99 CV Siap Pakai
99 contoh CV per role dan level. Sesuaikan dengan keyword lowongan ini.
