Manager, Vulnerability

2 days ago


Hong Kong Island, Hong Kong SAR China IT Channel (Asia) Limited Full time

Manager, Vulnerability & Patch Assurance Analyst This hands‑on Manager role will analyse vendor patches and vulnerabilities, validate patch packages, coordinate testing windows, run post‑patching security scans, and provide actionable risk and compliance reporting. The role is ideal for a junior manager with strong technical skills and a passion for operational security. Responsibilities Analyze CVEs, CVSS/EPSS scores, exploit maturity, KEV catalog entries, and asset exposure. Recommend prioritization (e.g., weaponized, internet‑facing, crown jewels, high business impact). Patch Validation & Testing Review patch metadata, supersedence, prerequisites, and rollback strategy. Coordinate patch validation in UAT/Pilot rings ; verify functional and security outcomes. Document test cases, exceptions, application compatibility notes, and sign‑off criteria. Orchestration Support Ensure maintenance window discipline , change records, and communications are tracked. Post‑Patch Security Assurance Run/validate post‑patching scans (e.g., Qualys/Tenable/Rapid7; Defender for Endpoint). Investigate residual vulnerabilities, misconfigurations, failed installs, and drifts. Contribute to SOPs, standards, and ring & rollback methodologies. Required Skills & Experience 6‑10 years in Information Security/Endpoint Engineering/Vulnerability Management. Hands‑on with one or more patching stacks: Vulnerability scanning tools: Qualys, Tenable, Rapid7 , Nessus; interpretation of findings. Understanding of CVEs, CVSS, EPSS, KEV , exploit chains, and compensating controls. Familiarity with change management (ITIL), maintenance windows, rollback plans. Strong documentation, Excel/Power BI reporting, and stakeholder communication. Requirements Degree holder in Computer Science / Information Technology or equivalent with 6‑10 years of relevant experience. Holder of professional qualification(s) preferred: Microsoft 365, Azure and GenAI Security+, Azure Security Engineer, RHCSA, ITIL Foundation, CISSP (associate). Strong problem solving, management and analytical skills. Excellent communication and interpersonal skill; ability to work effectively under pressure. Understanding of IT operation within Insurance industry. Good command of written English and Chinese; fluent in spoken English. Demonstrated willingness to learn and adopt new IT technologies. #J-18808-Ljbffr



  • Hong Kong Island, Hong Kong SAR China IT Channel (Asia) Limited Full time

    A leading cybersecurity firm in Hong Kong is looking for a Manager in Vulnerability & Patch Assurance. This hands-on role involves analyzing vendor patches and vulnerabilities, coordinating testing, and ensuring compliance reporting. The ideal candidate will have 6-10 years of experience in Information Security, knowledge of patching tools like Qualys and...


  • Hong Kong Island, Hong Kong SAR China PFCC Group Full time

    A leading cybersecurity firm in Hong Kong is seeking a Senior Vulnerability Management Lead. This strategic position involves building and leading a vulnerability management program that safeguards the firm's digital assets from threats. Responsibilities include team leadership, vendor management, and crisis leadership. The ideal candidate has over 12 years...


  • Hong Kong Island, Hong Kong SAR China PFCC Group Full time

    This is a senior leadership position for a Vulnerability Management Lead . It's not just a technical role; it's a strategic one that combines people leadership, vendor management, process orchestration, and executive communication . The core mandate is to build and run a world-class vulnerability management program that protects the firm's entire Enterprise...


  • Hong Kong Island, Hong Kong SAR China HKT Full time

    A telecommunications company in Hong Kong is seeking a Manager – IT Security Control Validation to oversee compliance and vulnerability assessments. The ideal candidate should have over 10 years of experience in IT with significant exposure to security management frameworks like ISO 27001. Strong project management skills and certifications in information...


  • Hong Kong Island, Hong Kong SAR China HKT Full time

    Manager – IT Security Control Validation Monitor internal/external compliance reviews activities and follow up on deficiencies identified and ensure remediation steps have been taken Perform control and vulnerability assessments to identify gaps and weaknesses. Assist in compliance monitoring and recommend remediation actions Provide oversight into...


  • Hong Kong Island, Hong Kong SAR China HKT Full time

    Manager – IT Security Control Validation 5 days ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Monitor internal/external compliance reviews activities and follow up on deficiencies identified and ensure remediation steps have been taken Perform control and vulnerability assessments to identify gaps and...


  • Hong Kong Island, Hong Kong SAR China Jebsen & Co Ltd Full time

    Information Security Manager (Ref. B020) Develop and implement information security strategies, policies, and procedures that align with the organization's business objectives and regulatory requirements. Monitor internal and external policy compliance. He/she will ensure both our vendors and employees understand our cybersecurity risk management policies...

  • Assistant Manager

    1 week ago


    Hong Kong Island, Hong Kong SAR China Rober Walters Hong Kong Full time

    An industry-leading client is hiring an Assistant Manager – Information Security to bring efforts in safeguarding sensitive data and systems. Key responsibilities include conducting risk assessments, managing vulnerabilities, patching, and IT controls, and driving AI adoption in cybersecurity operations. Candidates should have 6+ years of IT security...


  • hong kong, Hong Kong SAR China HKT Full time

    Manager / Senior Specialist – IT Security Control Validation Location: Hong Kong, Hong Kong SAR Responsibilities Monitor internal/external compliance review activities and follow up on deficiencies identified and ensure remediation steps have been taken Perform control and vulnerability assessments to identify gaps and weaknesses. Assist in compliance...


  • Hong Kong Island, Hong Kong SAR China HKT Full time

    A leading tech firm in Hong Kong is seeking a Manager for IT Security Control Validation. The role requires strong oversight of compliance activities, conducting vulnerability assessments, and working with internal and external parties for security assessments. Candidates should hold a degree in IT with at least 10 years in IT, focusing on security. The...