Search Jobs

Search by job, company or skills

Senior Manager, Threat and Vulnerability Management

Senior Manager, Threat and Vulnerability Management

Air Asia
Fresher
  • Posted 20 hours ago
  • Be among the first 10 applicants

Job Description



Job Description

WHAT YOU'LL DO:

Vulnerability Assessment & Management

  • Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.

  • Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics.

  • Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.

  • Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.

Penetration Testing & Red Teaming

  • Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises.

  • Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.

  • Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.

Threat Intelligence & Threat Hunting

  • Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework).

  • Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.

  • Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.

Stakeholder Management & Strategic Leadership

  • Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors.

  • Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.

  • Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds).

Team Leadership and Development

  • Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers.

  • Provide hands-on technical guidance during complex technical deep-dives, exploit evaluations, and attack surface reviews.

  • Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains.


WHO YOU ARE:

  • 10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming.

  • Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling

  • Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.

  • Bachelor's degree in Computer Science, Information Security, or a related technical field.

  • Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights.

  • Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.


We are all different - one talent to another - that is how we rely on our differences. At AirAsia, you will be treated fairly and given all chances to be your best.We are committed to creating a diverse work environment and are proud to be an equal opportunity employer.

Search Firm Representatives - AirAsia does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place.

More Info

Job Type:
Function:
Employment Type:

Key Skills

Threat Intel Feeds

Pentesting Toolkits

CVSS

EPSS

TVM

Offensive Security Technology Stacks

Risk Scoring Frameworks

Exploit Mechanisms

Security Tooling

About Company

Similar Jobs

Malaysia, Kuala Lumpur
Skills:
security automation , Orchestration, AI augmentation, Emerging Technologies, Security tooling, Infrastructure-as-code
Malaysia
Skills:
Apis, Version Control, Power Platform, Security Controls, Python, workflow orchestration tools, low-code platforms, connectors, Claude, configuration-as-code, Code LLM integrations, deployment patterns, AI-assisted tooling, CI/CD, Copilot Studio