NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
5 days ago
Apply with autofill
Apply with autofill
Airasia·5 days ago
5 days ago

Senior Manager, Threat and Vulnerability Management

Kuala Lumpur, MalaysiaSenior · 10+ yearsSecurity Analyst

Sign up free to see how well your resume matches this role.

Boost your chances at airasia

How you compare FREE

?
Your scoreYour score: not yet known
→
18
Top 10%Top 10%: 18 out of 100

Top 10% of NextRaise users matched against Security Analyst roles in Malaysia.

Must-have skills for this role

  • vulnerability management
  • penetration testing
  • threat intelligence
  • red teaming

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.
  • Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics.
  • Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.
  • Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.
  • Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises.
  • Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.
  • Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.
  • Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework).
  • Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.
  • Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.
  • Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors.
  • Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.

What they're looking for

  • 10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming.
  • Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling
  • Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.
  • Bachelor's degree in Computer Science, Information Security, or a related technical field.
  • Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights.

Nice to have

  • Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer


Job Description

WHAT YOU'LL DO:

Vulnerability Assessment & Management

  • Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.

  • Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics.

  • Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.

  • Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.

Penetration Testing & Red Teaming

  • Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises.

  • Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.

  • Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.

Threat Intelligence & Threat Hunting

  • Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework).

  • Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.

  • Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.

Stakeholder Management & Strategic Leadership

  • Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors.

  • Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.

  • Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds).

Team Leadership and Development

  • Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers.

  • Provide hands-on technical guidance during complex technical deep-dives, exploit evaluations, and attack surface reviews.

  • Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains.


WHO YOU ARE:

  • 10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming.

  • Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling

  • Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.

  • Bachelor's degree in Computer Science, Information Security, or a related technical field.

  • Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights.

  • Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.

Company

Airasia
Kuala Lumpur, Malaysia

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Airasia's careers site·first seen 17 Sept 2026·last verified 17 Sept 2026·How we source jobs

Similar jobs

  • Cybersecurity Analyst at EricssonSunway, Malaysia–match not yet calculated
  • Senior Threat Detection Engineer at GrabPetaling Jaya, Malaysia–match not yet calculated
  • Cybersecurity Analyst - Monitoring & Incident Response at RochePetaling Jaya, Malaysia–match not yet calculated
  • Senior Security Analyst at logicalisKuala Lumpur, Malaysia–match not yet calculated
  • Security Operations Center Lead at alteraPenang 15, Malaysia–match not yet calculated

Browse more jobs

  • Security Analyst jobs in United States
  • Security Analyst jobs in India
  • Security Analyst jobs in United Kingdom
  • Retail Sales Associate jobs in United States