Exposure Manager
On-siteSingapore, Singapore
Job Summary
Coordinate multiple penetration testing engagements from initiation through reporting and remediation tracking, defining objectives, timelines, and resources with application owners and technical experts. Act as the central point of contact for exposure management activities, liaising with internal teams, external vendors, and senior security specialists to validate scopes, clarify findings, and escalate complex issues. Organize scoping sessions to align business needs and security best practices while overseeing vendor deliverables and ensuring adherence to standards and local regulations. Provide process support and guidance to technology teams, reporting adherence to management and maintaining compliance with ServiceNow-tracked vulnerability responses.
Required Qualifications
- Bachelor's degree in computer science, information security, or equivalent practical experience
- 3–5 years of experience in IT/security governance, compliance, or vulnerability management, or technical project management
- Professional proficiency in English
- Foundational understanding of security configuration standards (e.g., OWASP Top 10, CIS benchmarks) and vulnerability management principles
- Familiarity with penetration testing phases and methodologies
- Strong organizational and time-management skills
- Excellent communication and stakeholder management skills
- Proactive and solution-oriented mindset
- Demonstration of appropriate values and behaviours including but not limited to standards on honesty and integrity, due care and diligence, fair dealing (treating customers fairly), management of conflicts of interest, competence and continuous development, adequate risk management, and compliance with applicable laws and regulations
Desired Qualifications
- Experience coordinating penetration testing or security assessment projects
- Familiarity with vulnerability scanning tools (e.g., Nexpose) and exposure management workflows
- Experience working with external vendors
- IT or Security certifications (e.g., Security+, CISM, CISSP, CEH, OSCP)
- Basic understanding of infrastructure security concepts
- Experience in financial services or regulated environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.