Search by job, company or skills

Vulnerability Response Specialist

  • Posted a day ago
  • Be among the first 10 applicants

Job Description

Role: Vulnerability Response Specialist

Business Function: Security Vulnerability Lifecycle Management

Location: KL

Open to Local Candidate only

Job Type: 12 Months+ Contract

Role Summary

The Vulnerability Response Specialist is part of the Vulnerability Response Squad, an operational extension of the Vulnerability Advisory (VA) and Security Vulnerability Lifecycle Management (SVLM) functions, established to provide enhanced response capability and 24x7 coverage for notable vulnerability events. Following assessment and prioritisation by VA, the squad assumes end-to-end ownership of high-risk vulnerabilities, including zero-day, out-of-band (OOB), actively exploited, and other critical threats. Leveraging Incident Management processes, the role drives stakeholder coordination, communications, escalation, risk mitigation, and remediation activities through to closure, ensuring timely reduction of cyber risk exposure.

The ideal candidate combines strong vulnerability management knowledge, incident coordination experience, analytical thinking, and stakeholder management skills, with the ability to analyse large volumes of vulnerability and threat intelligence data, translate technical risk into business impact, and drive timely remediation in a fast-paced 24x7 cyber response environment. Regular on-site presence is required to support stakeholder engagement, operation and incident coordination, and management of critical vulnerability events.

Role Purpose

Act as the operational response arm of the VA and SVLM functions by providing 24x7 coverage and end-to-end management of notable vulnerabilities. Following assessment by VA, the role leverages Incident Management processes to coordinate stakeholders, drive communications, escalate risks, and accelerate mitigation and remediation activities through to closure, ensuring timely reduction of cyber risk exposure.

Key Responsibilities

  • Vulnerability Response Management
  • Assume operational ownership of notable vulnerabilities following VA assessment and prioritisation.
  • Drive end-to-end response activities for zero-day, out-of-band (OOB), actively exploited, and other high-profile vulnerabilities.
  • Coordinate cross-functional stakeholders to execute mitigation and remediation activities.
  • Establish and lead vulnerability response bridges, action tracking, and escalation activities.
  • Drive execution of vulnerability response playbooks and response procedures
  • Maintain continuous oversight of vulnerability response activities until risk mitigation or remediation is completed.
  • Incident Management & Stakeholder Coordination
  • Leverage Incident Management processes to accelerate remediation and stakeholder mobilisation.
  • Coordinate Cyber Defence, Platform Teams, Asset Owners, Technology SMEs, and Incident Management teams during vulnerability events.
  • Drive stakeholder communications, executive updates, situation reporting, and escalation activities.
  • Escalate critical risks, blockers, and delayed remediation activities through appropriate governance channels.
  • Support post-incident reviews and continuous improvement initiatives.
  • Remediation Oversight
  • Drive remediation activities through to closure, ensuring accountability and timely execution.
  • Track remediation commitments, milestones, dependencies, and residual risks.
  • Challenge and escalate overdue actions where required.
  • Validate completion of agreed mitigation and remediation actions.
  • Support management reporting on remediation progress and risk reduction outcomes.
  • 24x7 Vulnerability Response Coverage
  • Participate in on-call, weekend, after-hours, and follow-the-sun support arrangements.
  • Provide operational coordination during high-severity vulnerability events outside standard business hours.
  • Support continuous vulnerability response coverage for critical cyber threats.
  • Ensure timely stakeholder mobilisation during active exploitation and major vulnerability incidents.

Key Skills & Experience

  • Vulnerability Management
  • Strong understanding of vulnerability management concepts, CVE, CVSS, exploitability assessment, threat intelligence, and cyber risk management.
  • Ability to understand vulnerability assessments and translate risk into actionable remediation plans.
  • Knowledge of vulnerability prioritisation, attack surface exposure, and threat landscape trends.
  • Incident & Crisis Management
  • Experience coordinating Major Incident, Cyber Incident, or Technology Incident response activities.
  • Strong understanding of escalation management, crisis communications, and stakeholder coordination.
  • Experience leading bridge calls, action tracking, executive reporting, and operational response activities
  • Remediation Governance & Oversight
  • Experience driving remediation activities across multiple technology and infrastructure teams.
  • Understanding of remediation governance, risk reduction strategies, compensating controls, and risk treatment plans.
  • Ability to influence stakeholders and drive accountability for remediation outcomes.

Professional Competencies

  • Strong problem-solving skills with the ability to analyse complex cyber risk scenarios, identify response strategies, and drive issues to resolution.
  • Excellent communication and stakeholder management skills with the ability to engage technical teams, senior management, and incident stakeholders during high-pressure situations.
  • Strong analytical capability with experience interpreting and correlating large volumes of vulnerability, threat intelligence, asset inventory, remediation, and operational data to support risk-based decision making.
  • Ability to translate technical vulnerability information into clear business risk, operational impact, and remediation priorities.
  • Up-to-date knowledge of vulnerability management practices, emerging threats, vulnerability intelligence, exploit trends, and cyber threat landscape developments.
  • Self-driven, proactive, and capable of operating independently within a fast-paced 24x7 response environment.
  • Strong execution focus with the ability to coordinate multiple stakeholders and drive timely remediation outcomes.
  • Ability to remain calm under pressure and make sound decisions during critical cyber events.
  • Comfortable working in ambiguous situations and making risk-based decisions with incomplete information.
  • Highly collaborative with a strong sense of ownership and accountability.

Preferred Experience

  • 10+ years of experience in Vulnerability Management, Security Operations, Incident Response, Technology Risk, Cyber Defence, or related cyber security disciplines.
  • Experience supporting 24x7 security operations, on-call rotations, or major incident management activities.
  • Experience managing critical cyber incidents, zero-day vulnerabilities, and actively exploited threats.

Experience working within a highly regulated environment such as financial services.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 153338709

Beware of Scammers

We don’t charge money for job offers