I10 - Vulnerability Analyst (030)
Perform vulnerability scanning and validation to verify remediation actions
The Vulnerability Management Analyst conducts vulnerability scanning, validates findings, and tracks remediation across applications, infrastructure, and technology platforms. They manage external penetration testing vendors, maintain VA scan scripts to reduce false positives, and generate dashboards for department heads. The role includes compliance checks on organizational assets, preparing quarterly reports, and supporting bug bounty progra...
Why This Role?
Opportunity to manage external penetration testing vendors and support bug bounty programs
Key Responsibilities
- Perform vulnerability scanning and discovery across applications and infrastructure
- Validate vulnerability findings and track remediation actions with SLA monitoring
- Manage and coordinate external vendors conducting penetration tests and assessments
- Maintain and amend VA scan scripts to reduce false positives
- Generate dashboards and share VA scan results with department heads in weekly meetings
- Conduct compliance and hardening checks on organizational assets including cloud environments
Requirements
- Bachelor's Degree in Cyber Security or information security
- More than 3 years of experience in vulnerability management or similar security roles
- Experience with vulnerability assessment, infrastructure security, or penetration testing
- Relevant industry certifications such as CISSP, OSCP, or SANS preferred
Required Skills
Keywords
View Original Description from Manatal Career Pages
Original description from Manatal Career Pages
Description The Vulnerability Management Analyst is responsible for vulnerability scanning, validation of findings, remediation tracking, and oversight of external penetration testing vendors across applications, infrastructure, and technology platforms. This role will come under the IT Risk and Security department, reporting to the Senior Manager of Cyber Assurance. Key Responsibilities Perform vulnerability scanning, discovery, remediation tracking, SLA monitoring, and verification of vulnerability fixes. Review and communicate vulnerability assessment findings to affected teams, and follow up on queries and remediation actions. Manage and coordinate external vendors performing vulnerability assessments and penetration tests, including support for tooling, product issues, and related queries from internal teams. Maintain and amend the VA scan scripts when necessary to reduce the false positives. Generate Dashboard and share the VA scan results with Department HOD and team manager on issues and concerns in the weekly team meeting. On monthly basis, perform reconciliation on any agents that are not reporting and any new servers. Compliance and hardening checks on organisation assets, including cloud to ensuring alignment with CIS or other applicable standards. Prepare VA statistics and reports in the quarterly management meetings. Support the compliant standards and SOP to conduct VA scan to cover MS Azure Cloud and Google cloud tenant Perform risk assessment on vulnerability and penetration test findings, and recommend remediation or compensating controls where direct remediation is not feasible. Review vendor penetration testing scope, methodology, and findings to assess technical accuracy, exploitability, business impact, and remediation priority. Experienced in Bug Bounty Program, validating severity and business impact, tracking remediation closure, managing researcher communications and support maintenance of scope, outcomes reporting Undertake other projects and tasks that may be assigned by management. Qualifications / Requirements Bachelor's Degree with more than 3 years of experience in Cyber Security or information security. Experienced in vulnerability management, vulnerability assessment, infrastructure security, or similar information security roles. Open to consider candidates with at least 2 years of relevant experience Relevant industry certifications such as CISSP, OSCP, CREST CPSA CRT, SANS certifications preferred. Competencies Hands-on experience on vulnerability assessment tools with Tenable Vulnerability Management / Tenable One / Nessus is a must. Good understanding of vulnerability management standards, remediation SLAs, and the ability to follow up with stakeholders to drive timely closure of findings. Working knowledge of vulnerability scoring and prioritisation models such as CVSS, Tenable VPR, and EPSS. Experienced in conducting technical risk assessments, including assessment of preventive and detective controls. Working knowledge of vulnerability management procedures, remediation tracking, and service level agreement monitoring. Strong understanding of penetration testing methodologies and Web/API application security, Mobile and AI/LLM. OWASP top 10 Understanding of CIS security hardening standards and baseline controls for servers, operating systems, databases, and for cloud environments such as AWS, Azure. Able to engage stakeholders effectively, follow up on remediation actions, and drive closure of vulnerabilities within required timelines.
Salary Context
Similar Data & Analytics roles on LokerDollar pay around $115k/yr (range $26.292k–999.999k/yr, n=86 active listings).
Hiring at FPT Asia Pacific
FPT Asia Pacific has 139 other active roles on LokerDollar and has been hiring here since Aug 10, 2026 — across Data & Analytics, Design, Engineering.
- M08- UX Designer
- M08 - Software Developer (PowerBuilder - Sybase Migration Specialist)
- M07 - UX Researcher & Service Designer
Openness not stated by employer — check the listing
Frequently asked questions
- Is I10 - Vulnerability Analyst (030) at FPT Asia Pacific a remote job?
- This role is based in Remote. See the listing for remote/onsite details.
- What type of employment is I10 - Vulnerability Analyst (030) at FPT Asia Pacific?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at FPT Asia Pacific.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Remote ≠ Remote: The Skills That Open Global Work to Indonesians (2026)12,891 remote listings: the highest-paid coding skills are the most geo-locked for Indonesia-based applicants. CC BY 4.0 aggregate dataset.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- EnableComp: Remote DRG VP & the RiseEnableComp is hiring a remote VP DRG. Salary is undisclosed, but what does this mean for the growing trend of overemployment? We dive in.
- Freelance Remote USD 2026: Apa yang PerluCari kerja remote USD? Simak seluk-beluk gig economy, rate terkini, dan tips jadi freelancer sukses di Agustus 2026.
- Remote Jobs with Clear Salaries in 2026Explore remote job opportunities with transparent salaries in 2026, including positions at Automation Anywhere, Binance, Bree, and more.
This apply link is not verified yet.