company-logo-image

Senior Manager, Threat and Vulnerability Management

ashley-avatar-image

AI-generated summary

  • Own TVM: run pen tests/red teams and threat hunting across cloud, infra and endpoints; enforce remediation with ICT/SRE.
  • Inclusive, equal-opportunity culture.
  • Build and lead a high-performing offensive security team; influence senior leaders!

Undisclosed

Sepang, Kuala Lumpur

Job Description



Job Description

WHAT YOU'LL DO:

Vulnerability Assessment & Management

  • Own and evolve the end-to-end continuous vulnerability management program across multi-cloud, modern infrastructure, and legacy environments.

  • Define risk-based prioritization logic combining vulnerability severity (CVSS), asset criticality, and active exploitability metrics.

  • Collaborate closely with ICT, SRE, and business unit stakeholders to enforce remediation timelines and drive patching accountability without disrupting business operations.

  • Establish metrics, SLAs, and executive dashboards to communicate enterprise exposure and remediation progress to senior leadership.

Penetration Testing & Red Teaming

  • Define the operational strategy and schedule for penetration testing and objective-based red teaming exercises.

  • Manage internal specialists and external vendors/penetration testers to ensure comprehensive coverage, clear scope definition, and high-quality deliverables.

  • Oversee post-assessment remediation validation to ensure identified security gaps are properly addressed.

Threat Intelligence & Threat Hunting

  • Build and integrate a Cyber Threat Intelligence (CTI) program to gather, analyze, and act upon emerging threat indicators and adversary TTPs (MITRE ATT&CK framework).

  • Direct proactive threat hunting campaigns across endpoints, identity, and cloud environments to uncover hidden, undetected adversaries or security weaknesses.

  • Feed threat intelligence and hunting findings back into detection tools, threat models, and vulnerability prioritization engines.

Stakeholder Management & Strategic Leadership

  • Serve as the primary security partner and strategic interface for system owners, software developers, infrastructure teams, and third-party vendors.

  • Influence and negotiate remediation priorities with senior business and technical leaders, balancing cyber risk reduction against operational impact.

  • Evaluate, implement, and optimize TVM and offensive security technology stacks (scanners, pentesting toolkits, threat intel feeds).

Team Leadership and Development

  • Build, mentor, and lead a high-performing team of vulnerability management analysts, penetration testers, and threat researchers.

  • Provide hands-on technical guidance during complex technical deep-dives, exploit evaluations, and attack surface reviews.

  • Foster a culture of technical rigor, continuous learning, and innovation within the offensive and proactive security domains.


WHO YOU ARE:

  • 10+ years of experience in Cyber Security, with a strong focus on Vulnerability Management, Penetration Testing, Threat Intelligence, and Red Teaming.

  • Technically apt with deep understanding of exploit mechanisms, risk scoring frameworks (CVSS, EPSS), cloud security, network architecture, and security tooling

  • Proven ability to lead and motivate teams, build strong relationships, and influence decision-making at all levels.

  • Bachelor's degree in Computer Science, Information Security, or a related technical field.

  • Excellent communication skills, capable of translating complex attack vectors and security risks into actionable business insights.

  • Relevant industry certifications (e.g., OSCP, GXPN, GPEN, CISSP, CISM, or equivalent) are highly advantageous.


We are all different - one talent to another - that is how we rely on our differences. At AirAsia, you will be treated fairly and given all chances to be your best.We are committed to creating a diverse work environment and are proud to be an equal opportunity employer.

Search Firm Representatives - AirAsia does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place.


Job Requirements


Company Benefits

Comprehensive Benefits Package

The company offers various perks such as travel discounts, which include reduced rates for flights and access to e-coupon schemes.

Career Development Opportunities

The company invests in its employees through training programs, workshops, and skill development initiatives.

Dynamic Work Environment

The company is known for its innovative culture and encourages employees to bring creative ideas to the table.


Additional Info

Company Activity

Last active - few days ago

Job Specialisation


Company Profile

AirAsia X-logo-image

AirAsia X

Now, that dream has sparked half a billion more dreams and will continue to do so through new experiences from Asean fast food and food deliveries to a network of gateways and getaways. Source: https://www.capitala.com/mission_vision.html