Unison Group
109 open roles
Information Security (Vulnerability and Penetration )
Singapore, SGKuala Lumpur, Federal Territory of Kuala Lumpur, MYPosted Aug 27, 2026
Job description
Requirements
- Minimum 7 years of relevant security experience.
- Extensive experience in information security and/or IT risk management.
- Proven experience owning and running a vulnerability management and/or penetration testing program, process, and governance forum.
- Demonstrated leadership, project, and team-building skills, including the ability to lead teams and drive projects and initiatives across multiple departments.
- Ability to identify risks associated with business processes, operations, information security programs, and technology projects.
- Ability to communicate with diverse audiences, both technical and non-technical, to build consensus on risk-based vulnerability management and penetration testing.
- Experience with process optimization.
- Experience with process automation and workflow using ITSM tools.
- Hands-on experience with vulnerability management, penetration testing, and security engineering.
- Experience with industry-known vulnerability management, penetration testing, and CSPM solutions. Vulnerability Management
- Strong knowledge of risk-based vulnerability management, including triage of vulnerabilities to determine "True Risk" exposure to Singlife.
- Experience in log configuration, formats, and feeding logs into SIEM platforms. Penetration Testing
- Strong hands-on penetration testing background across multiple domains (network, web, mobile, API, and cloud), including managing external PT vendors and triaging and validating penetration test findings.
- Working knowledge of recognized penetration testing methodologies and frameworks (OWASP Testing Guide, PTES, NIST SP 800-115, MITRE ATT&CK) and common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Kali Linux, Cobalt Strike).
- Working knowledge of one or more programming/scripting languages such as Python, C++, Java, Ruby, Node, Go, and/or Power. Shell.
Education
- Academic: Bachelor's degree in Computer Science or Information Technology (preferred).
- Professional Certification(s): One or more of CISSP, CISM, CISA, or SANS/GIAC certifications, together with a recognized penetration testing certification such as OSCP, GPEN, GWAPT, CREST (CRT/CCT), or CEH (preferred, or willing to become certified within one year).
Description copied from Unison Group's careers page. Read the full posting before you apply.
More jobs at Unison Group
Full Stack Dotnet Developer - Work Location Malaysia, KL Hybrid Mode
Unison Group· Kuala Lumpur, Federal Territory of Kuala Lumpur, MYFLEXCUBE Techno-Functional Consultant
Unison Group· IN (Remote)Ofsaa Ifrs 9 Functional Consultant (Llfp)
Unison Group· Delhi, DL, INProject Manager - Wholesale Banking & Channels
Unison Group· Singapore, SGProject Manager - Wholesale Banking
Unison Group· Singapore, SG