About the Role
We are looking for an experienced Triage Team Lead (Operations Support Engineer) to support the Government of Singapore's Crowdsourced Vulnerability Discovery Programme (CVDP). You will lead a team responsible for validating, triaging, and managing cybersecurity vulnerability reports across government systems, ensuring high-quality and timely handling of security findings.
This role is ideal for cybersecurity professionals with strong hands-on penetration testing experience, leadership capabilities, and expertise in web application security.
Key Responsibilities
- Lead and manage a team of vulnerability triage specialists, ensuring quality, consistency, and timely processing of vulnerability reports.
- Oversee daily operations, workload planning, and resource allocation for the triage team.
- Perform hands-on validation and assessment of vulnerability reports during complex investigations or peak workload periods.
- Act as the technical escalation point for vulnerability validation, severity assessment, and remediation recommendations.
- Mentor and coach team members to maintain high standards in vulnerability analysis, documentation, and reporting.
- Develop and enhance triage processes, SOPs, workflows, and supporting tools.
- Create scripts and automation using Python or workflow tools to improve operational efficiency.
- Collaborate with government agencies, system owners, programme stakeholders, and external security researchers.
- Analyse vulnerability trends and prepare technical reports and presentations for management and stakeholders.
- Support additional cybersecurity programme initiatives as required.
Requirements
Mandatory Skills & Experience
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.
- Minimum 5 years of relevant cybersecurity experience.
- OSCP (Offensive Security Certified Professional) certification is mandatory.
- Hands-on experience identifying and validating web application vulnerabilities.
- Strong knowledge of OWASP Top 10 and common web security vulnerabilities.
- Experience performing vulnerability validation using Burp Suite and Kali Linux.
- Experience conducting vulnerability severity assessment, root cause analysis, and recommending remediation.
- Experience leading or mentoring technical cybersecurity teams.
- Strong written and verbal communication skills.
- Excellent analytical and problem-solving abilities.
Nice to Have
- Experience supporting Bug Bounty, Vulnerability Disclosure Programmes (VDP), or Crowdsourced Vulnerability Discovery Programmes (CVDP).
- Experience developing automation scripts using Python.
- Familiarity with workflow automation and integration platforms.
- Experience working with Government or public sector cybersecurity programmes.
- Experience presenting technical findings to senior stakeholders.
Technical Skills
- Web Application Security
- Vulnerability Assessment & Validation
- Penetration Testing
- OWASP Top 10
- Burp Suite
- Kali Linux
- Python Scripting
- Root Cause Analysis
- Vulnerability Severity Assessment
- Security Reporting
- Stakeholder Management
- Team Leadership