Job Description
Job Description
WHAT YOU'LL DO:
Vulnerability Assessment & Management
Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.
Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics.
Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.
Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.
Penetration Testing & Red Teaming
Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises.
Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.
Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.
Threat Intelligence & Threat Hunting
Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework).
Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.
Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.
Stakeholder Management & Strategic Leadership
Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors.
Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.
Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds).
Team Leadership and Development
Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers.
Provide hands-on technical guidance during complex technical deep-dives, exploit evaluations, and attack surface reviews.
Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains.
WHO YOU ARE:
10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming.
Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling
Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.
Bachelor's degree in Computer Science, Information Security, or a related technical field.
Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights.
Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.
We are all different - one talent to another - that is how we rely on our differences. At AirAsia, you will be treated fairly and given all chances to be your best.We are committed to creating a diverse work environment and are proud to be an equal opportunity employer.
Search Firm Representatives - AirAsia does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place.
More Info
Key Skills
Threat Intel Feeds
Pentesting Toolkits
CVSS
EPSS
TVM
Offensive Security Technology Stacks
Risk Scoring Frameworks
Exploit Mechanisms
Security Tooling
