StarHub Ltd

Lead - VM & App Security Engineer

StarHub Ltd Petaling Jaya, Selangor, Malaysia

Telecommunications · 1,001-5,000 employees

23 h ago
security Senior (5-10 yrs) Full-time Malaysia
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Lead VM & App Security Engineer will manage the end-to-end vulnerability lifecycle, including identification, assessment, and remediation tracking across the organization's technology environment. This role involves collaborating with cross-functional teams to implement risk-based remediation plans and maintaining security scanning platforms.

What they look for

Vulnerability Management Tenable Nessus Qualys Cybersecurity Risk Assessment CVSS Application Security Infrastructure Security DevSecOps Cloud Security OWASP Top 10 Jira ServiceNow Remediation Tracking Threat Intelligence

Requirements

Candidates must possess a degree in Cybersecurity, Computer Science, or a related field, along with hands-on experience in vulnerability management and security operations. Proficiency with scanning tools like Tenable or Qualys and a strong understanding of risk assessment methodologies are essential.

Full description

Vulnerability Management Specialist

We are seeking a Vulnerability Management Specialist to lead the identification, assessment, prioritization, and remediation tracking of security vulnerabilities across our technology environment. This role will work closely with application, infrastructure, cloud, and security teams to reduce cyber risk through a structured, risk-based vulnerability management programme.

Key Responsibilities

  • Operate and maintain vulnerability scanning platforms, preferably including Tenable/Nessus and Qualys.
  • Conduct authenticated and unauthenticated vulnerability scans across servers, endpoints, network devices, cloud workloads, and applications.
  • Analyse scan results, validate findings, eliminate false positives, and assess business and technical risk.
  • Manage the end-to-end vulnerability lifecycle: discovery, triage, prioritisation, assignment, remediation tracking, validation, exception management, and closure.
  • Apply risk-based prioritisation using CVSS, exploitability, asset criticality, internet exposure, business impact, and known active threats.
  • Partner with infrastructure, application, cloud, and DevOps teams to define practical remediation plans and meet agreed remediation timelines.
  • Produce regular vulnerability reports, dashboards, metrics, and management updates, including SLA compliance, overdue findings, vulnerability ageing, and risk trends.
  • Maintain vulnerability management policies, procedures, asset coverage, scan schedules, and evidence for audit and compliance requirements.
  • Support remediation of application and software-supply-chain vulnerabilities through tools and platforms such as JFrog, Bitbucket, SonarQube, Fortify, and CI/CD pipelines.
  • Identify gaps in asset inventory, scanning coverage, and remediation ownership, and recommend process or automation improvements.
  • Stay current on emerging vulnerabilities, exploit activity, vendor advisories, and threat intelligence relevant to the organisation.

Required Qualifications

  • Degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
  • Experience in vulnerability management, security operations, infrastructure security, application security, or a related cybersecurity function.
  • Hands-on experience with vulnerability scanning tools, especially Tenable/Nessus and/or Qualys.
  • Strong understanding of vulnerability management processes, including scanning, validation, CVSS, risk assessment, remediation verification, exception handling, and reporting.
  • Familiarity with common operating systems, networks, cloud environments, and enterprise infrastructure.
  • Understanding of common application vulnerabilities and the OWASP Top 10.
  • Experience working with ticketing and workflow tools such as Jira, ServiceNow, or equivalent.
  • Ability to analyse technical findings and explain risk and remediation actions clearly to technical and non-technical stakeholders.
  • Strong attention to detail, organisation, and follow-through in managing findings through closure.

Preferred Qualifications

  • Experience with application-security or DevSecOps platforms such as JFrog, Bitbucket, SonarQube, Fortify, SAST, DAST, SCA, and container-security tools.
  • Familiarity with cloud-security and cloud-native vulnerability management across AWS, Azure, or Google Cloud.
  • Knowledge of threat intelligence sources, CISA Known Exploited Vulnerabilities, and exploitability assessment.
  • Experience developing vulnerability dashboards, metrics, or automated reporting.
  • Security certifications such as Security+, CEH, CISSP, CISM, CSSLP, or relevant vendor certifications.

Similar roles