Singlife is a leading homegrown financial services company, offering consumers a better way to financial freedom. Through innovative, technology-enabled solutions and a wide range of products and services, Singlife provides consumers coantrol over their financial wellbeing at every stage of their lives.
In addition to a comprehensive suite of insurance plans, employee benefits, partnerships with financial adviser channels and bancassurance, Singlife offers investment and advisory solutions through its GROW with Singlife platform. It also offers the Singlife Account, a mobile-first insurance savings plan.
Singlife is the exclusive insurance provider for the Ministry of Defence, Ministry of Home Affairs and Public Officers Group Insurance Scheme. Singlife is also an official signatory of the United Nations Principles for Sustainable Insurance and the United Nations-supported Principles for Responsible Investment, affirming its commitment to finding a better way to sustainability.
The merger of Aviva Singapore and Singlife was announced in September 2020 and created one of the largest homegrown financial services companies in Singapore in a deal valued at S$3.2 billion. It was the largest insurance deal in Singapore at the time. Singlife was subsequently acquired by Sumitomo Life in March 2024, one of Japan's leading life insurers, which valued Singlife at S$4.6 billion, making the transaction one of the largest insurance deals in Southeast Asia.
About The Role
The Vulnerability Management and Penetration Testing (VMPT) AVP is responsible for developing, running, and continuously improving Singlife's internal Vulnerability Management and Penetration Testing (VMPT) program and capabilities, supporting Singlife's business as well as the security and integrity of its IT operations.
The incumbent will support the VP of Vulnerability Management and Penetration Testing to establish risk-based vulnerability management and penetration testing methodologies, develop the standards and procedures that govern the end-to-end VMPT process in a regulated environment, and champion program improvements that meet business and security requirements.
A core part of the role is program and process management—owning the triage of vulnerabilities and penetration test findings, chairing the governance forum, and driving remediation to closure with internal and external stakeholders.
Responsibilities
The role's responsibilities span three core areas: program management and governance across the combined function, day-to-day vulnerability management, and end-to-end penetration testing.
Program Management & Governance
- Build, run, and continuously improve the internal Vulnerability Management and Penetration Testing (VMPT) program and capabilities within the organization.
- Develop and refine the policies, processes, standards, and procedures for vulnerability management, penetration testing, communication, and reporting.
- Lead the triage of vulnerabilities and penetration test findings, taking into consideration compensating controls, threat exposure, and True Risk to Singlife, and prioritize remediation accordingly.
- Chair the vulnerability and penetration testing governance forum, driving accountability, tracking remediation SLAs, and escalating overdue or high-risk items to management.
- Manage the internal VMPT program and relationships with external VMPT/PT vendors and other stakeholders across Singlife.
- Establish and report meaningful metrics and dashboards on vulnerability and penetration testing posture, remediation progress, and program effectiveness to management and relevant committees.
- Identify gaps in adjacent processes and procedures and drive improvements from a risk-based vulnerability management (RBVM) and penetration testing perspective.
- Research, develop, and recommend appropriate tooling required for effective risk-based vulnerability management and penetration testing.
- Produce high-quality oral and written work products, presenting complex technical matters and findings clearly and concisely.
- Collaborate with supervisors and other cybersecurity team members on vulnerability management and penetration testing status and findings.
- Mentor and guide the technical development of junior VMPT staff and colleagues.
- Collaborate with stakeholders across the organization on security initiatives.
- Ensure compliance with all applicable laws and regulations relating to the above functional activities.
- Operate and maintain compliance with security baseline governance using appropriate tooling.
Vulnerability Management
- Own and manage the end-to-end vulnerability management process, from discovery and triage through remediation tracking, verification, and closure.
- Identify gaps in RBVM processes and procedures and drive continuous improvement.
- Build and lead the security review and monitoring of production environments across the hybrid infrastructure.
Penetration Testing
- Own and manage the end-to-end penetration testing program, from scoping and rules of engagement through execution oversight, findings management, retesting, and closure with external PT vendors and internal stakeholders.
- Define and maintain the annual, risk-based penetration testing plan, covering test types such as external and internal network, web and mobile application, API, cloud, wireless, social engineering, and red/purple team exercises.
- Set and enforce penetration testing standards, methodologies, and rules of engagement (e.g., OWASP, PTES, NIST SP 800-115, MITRE ATT&CK), and assure the quality, coverage, and independence of internal and vendor-delivered testing.
- Validate and retest remediated penetration test findings to confirm effective closure, and track exceptions and residual risk to acceptance or resolution.
- Ensure penetration testing satisfies regulatory and industry requirements (e.g., MAS TRM), and coordinate independent, threat-led and scenario-based testing where required.
Requirements
- Minimum 7 years of relevant security experience.
- Extensive experience in information security and/or IT risk management.
- Proven experience owning and running a vulnerability management and/or penetration testing program, process, and governance forum.
- Demonstrated leadership, project, and team-building skills, including the ability to lead teams and drive projects and initiatives across multiple departments.
- Ability to identify risks associated with business processes, operations, information security programs, and technology projects.
- Ability to communicate with diverse audiences, both technical and non-technical, to build consensus on risk-based vulnerability management and penetration testing.
- Experience with process optimization.
- Experience with process automation and workflow using ITSM tools.
- Hands-on experience with vulnerability management, penetration testing, and security engineering.
- Experience with industry-known vulnerability management, penetration testing, and CSPM solutions.
- Strong knowledge of risk-based vulnerability management, including triage of vulnerabilities to determine True Risk exposure to Singlife.
- Experience in log configuration, formats, and feeding logs into SIEM platforms.
- Strong hands-on penetration testing background across multiple domains (network, web, mobile, API, and cloud), including managing external PT vendors and triaging and validating penetration test findings.
- Working knowledge of recognized penetration testing methodologies and frameworks (OWASP Testing Guide, PTES, NIST SP 800-115, MITRE ATT&CK) and common offensive tooling (e.g., Burp Suite, Nmap, Metasploit, Kali Linux, Cobalt Strike).
- Working knowledge of one or more programming/scripting languages such as Python, C++, Java, Ruby, Node, Go, and/or PowerShell.
Education
- Academic: Bachelor's degree in Computer Science or Information Technology (preferred).
- Professional Certification(s): One or more of CISSP, CISM, CISA, or SANS/GIAC certifications, together with a recognized penetration testing certification such as OSCP, GPEN, GWAPT, CREST (CRT/CCT), or CEH (preferred, or willing to become certified within one year).