Vulnerability Management Analyst

1 week ago


Kuala Lumpur, Malaysia Aveva Full time

AVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals and minerals - safely, efficiently and more sustainably.

We’re the first software business in the world to have our sustainability targets validated by the SBTi, and we’ve been recognized for the transparency and ambition of our commitment to diversity, equity, and inclusion. We’ve also recently been named as one of the world’s most innovative companies.

If you’re a curious and collaborative person who wants to make a big impact through technology, then we want to hear from you Find out more at

AVEVA Careers


For more information about our privacy policy and how to manage cookies, visit our

Privacy Policy


Job name: Vulnerability Management Analyst

Organization/department: CISO (Security)

Reports to: Head of Vulnerability Management

Job Overview:
The AVEVA Security team are seeking a skilled individual to join a high performing global vulnerability management team.

The Vulnerability Management Analyst is responsible for proactively identifying and managing the remediation of vulnerabilities affecting AVEVA’s infrastructure and services. This role requires a broad technical understanding and to be responsible for vulnerability detection, assessment and driving vulnerability remediation across the organisation.

Roles and Responsibilities:
- Conduct vulnerability assessments to identify known vulnerabilities and configuration weaknesses and assess the effectiveness of existing controls and recommends remedial action.- Maintain current knowledge and understanding of the threat landscape and emerging security threats and vulnerabilities.- Analyze risks associated with vulnerabilities, provide detailed reporting, and recommend actionable remediation strategies- Support compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks.- Serve as an escalation point on issues, dependencies, and risks related to vulnerability scanning and security testing.- Collaborate with multiple stakeholders to prioritize vulnerabilities based on severity, impact, and exploitability.- Support the development of AVEVA’s Vulnerability management policy, process, and procedures.- Managing the end-to-end vulnerability lifecycle from discovery to closure ensuring the relevant resolver team put in place a plan and timely remediation working with both managed service providers and internal IT and Information Security staff.- Utilising information from external vulnerability reporting tools such as Bitsight, RiskRecon, Security Scorecard and vendor vulnerability briefings determine the priority of remediations needed across the AVEVA estate.- Manage security assessment processes, including performing, tracking remediation, validating controls, measuring residual risk, and writing reports.- Coordinate and oversee remediation efforts to ensure timely and effective resolution of security vulnerabilities.

Qualifications/ Experience:
Educational Qualifications and Experience- Minimum of 5 years information and cyber security experience, and experience in IT Vulnerability Management.- Experience using vulnerability scanning tools such as Qualys, Tenable, Rapid7 and vulnerability management platforms (RiskVision, Kenna Security).- Experience managing vulnerability management findings/services for cloud environments (Amazon Web Services, Microsoft Azure, Google Cloud Platform).- Strong understanding of vulnerability management practices and methodologies. Knowledge of common vulnerability frameworks (CVSS, OWASP Top 10).-
- Working knowledge of one or more of the following - cloud technologies, internet security, networking protocols or experience with software development.- Strong analytical skills and ability to identify advanced vulnerability threats.- Knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls.- Knowledge of and experience in developing and documenting security processes and plans.- Knowledge and experience with implementing common information security management frameworks, such as International Organization for Standardization (ISO) 2700x series, AICPA SOC2 (Service Organization Control), ITIL, COBIT and National Institute of Standards and Technology (NIST) or Centre for Internet Security (CIS) frameworks would be advantageous.

Technical Competency- Having knowledge and experience with as many of the following areas and tools is desired:
- Security certifications such as CEH, GPEN, Security+.-
- Understanding of firewall & networking devices (Cisco, Palo Alto, Checkpoint).-
- Understanding of desktop and server infrastructure (Microsoft, Linux, MacOS).-
- Vulnerability Management tools (Qualys, Tenable/Nessus, Rapid 7 Nexpose).-
- Security rating services such as BitSight, S


  • Vulnerability Analyst

    2 weeks ago


    Kuala Lumpur, Malaysia Avensys Consulting Pvt Ltd Full time

    **Role : Vulnerability Analyst** Client : Disclosed latter Job Type : Permanent Location : Petaling Jaya **KEY RESPONSIBILITIES** - Track all identified vulnerabilities from reporting to remediation and closure. - Facilitate exception handling and escalation for overdue vulnerabilities. - Effectively communicate Vulnerability Management metrics to...


  • Kuala Lumpur, Malaysia Skill quotient Full time

    **Roles and Responsibilities**: - Use intelligence feeds such as vulnerability reports and risk assessments to rate and prioritise vulnerabilities within the AIA environment. - Document vulnerabilities which are discovered within the AIA estate and provide guidance on remediation and mitigations. - Review vulnerabilities with AIA colleagues and technology...


  • Kuala Lumpur, Malaysia Terrabit Consulting Full time

    Good day!!! I came across your profile on Job portal and was immediately impressed with your experience. I think that your expertise would help us in project we’re working on. TERRABIT CONSULTING GROUP is one of the leaders in the IT Consulting industry across Asia Pacific. Founded in 2009, Terrabit Consulting began its operations in Singapore as a...


  • Kuala Lumpur, Malaysia DSS Software Solutions Sdn Bhd Full time

    D19494-Vulnerability Management Assessment Vulnerability Management Assessment **Job Description**: **KEY ACCOUNTABILITIES**: 1. Be part of vulnerability management team in Asia and work closely with Global domain teams across the world. security domain. tools like Qualys (DAST), BurpSuite, Silverline F5 WAF, etc. 4. Analyze and assess the impact from...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Tokio Marine Insurance Group (Asia) Full time

    Tokio Marine Insurance Group (Asia) is looking for a Vulnerability Management Lead to oversee the identification, classification, and remediation of vulnerabilities across the organization.About the JobThis role requires strong leadership skills and the ability to collaborate with cross-functional teams to drive strategic initiatives.Key...


  • Kuala Lumpur, Malaysia Power IT Services Full time

    **Job title: Vulnerability Management Assessment** **EXPERIENCE AND QUALIFICATIONS**: - Experience in Vulnerability Management & Assessment (Infrastructure and Application). - Strong experience in SAST/DAST onboarding and roll out. - Help challenge vulnerability findings from pentest activity conducted by independent third-party assessor. Strong technical...


  • Kuala Lumpur, Malaysia SOFT REFLEXES SDN BHD Full time

    Review, test, document, implement, and track software and operation system updates and security patches in the Asia Pacific region - Provide technical support to diagnose, analyze, research, and resolve computer problems in a Windows enterprise environment - Must be able to analyze data from multiple collection points to identify computers and systems that...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Ekco Group Full time

    About Ekco:Founded in 2016, Ekco is now one of the fastest growing cloud solution providers in EuropeWe specialise in enabling companies to progress along the path of cloud maturity, managing transformation and driving better outcomes from our customers' existing technology investments.In a few words, we take businesses to the cloud and backWe have over 600...

  • Business Analyst

    2 weeks ago


    Kuala Lumpur, Malaysia Skill Quotient Full time

    Role: Business Analyst Working Mode: On Site **Job Type**: CDM (Contract Direct Hire) - after completing 12 months will convert as Perm employee of Skill Quotient Job Location: Kuala Lumpur Experience: More than 5 years of experience as Business Analyst and Cybersecurity in Software Development Industry Only Local Malaysian preferred **JOB...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Prudential Hong Kong Limited Full time

    Job OverviewThe Vulnerability Remediation Expert will be responsible for conducting regular vulnerability assessments to identify potential security risks and prioritise patching based on criticality, urgency, and impact. The successful candidate will also collaborate with the security team to evaluate the risk associated with unpatched vulnerabilities and...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Ekco Group Full time

    Job OverviewThis is a fantastic opportunity to join our fast-growing Exposure Management function.You will be using market-leading vulnerability and attack surface management tools to help reduce client security exposure.As the primary point-of-contact for clients, you will ensure excellent service and drive internal improvements to existing services.Conduct...


  • Kuala Lumpur, Malaysia SSquad Global Full time

    **RESPONSIBILITIES** A cybersecurity analyst protects company hardware, software, and networks from cybercriminals. The analyst's primary role is to understand company IT infrastructure in detail, to monitor it at all times, and to evaluate threats that could potentially breach the network. **RESPONSIBILITIES** **To support regional operation**: -...

  • Security Analyst

    3 weeks ago


    Kuala Lumpur, Malaysia Puncak Rsg Sdn Bhd Full time

    Monitoring security access - Conducting security assessments through vulnerability testing and risk analysis - Performing both internal and external security audits - Analyzing security breaches to identify the root cause - Continuously updating the company’s incident response and disaster recovery plans - Verifying the security of third-party vendors and...

  • Security Analyst L3

    2 weeks ago


    Kuala Lumpur, Malaysia TechBridge Market Full time

    If you are passionate about playing a key role in the success of the region’s largest pure-play cybersecurity expertise and innovation, we want to hear from you! Our client is a well-established brand in the Cybersecurity industry and they are looking for a passionate and driven **Security Analyst L3 **to join their team. This is an exciting opportunity...

  • IT Security Analyst

    2 weeks ago


    Kuala Lumpur, Malaysia RHB Banking Group Full time

    Working Hour - Regular Hours - Monday - Friday- Business Area - Digital Technology- Location - Malaysia - Kuala Lumpur- Description **Primary Objective**: Provides 24x7 continous monitoring and detection of security alerts and escalation of security incident in aligning with the Group’s business objectives and in compliance with regulatory...


  • Kuala Lumpur, Malaysia BSI Full time

    Great that you're thinking about a career with BSI! Due to a huge period of growth within BSI, we are excited to be looking for a Security Operations Analyst to join our Information Security Team at the start of a Global Security transformation programme: - As part of your role you will work alongside the Head of Security Operations as a key part of the...

  • Business Analysts

    4 weeks ago


    Kuala Lumpur, Malaysia GENO Management Full time

    Position : Business Analysts 1 Salary Range : RM 2,500 - RM 3,500 Location : Bukit Jalil Working Hours : 8am - 5pm Working Days : 5 days Job Scope - Responsible in software implementation according to the targeted project timeline on the user requirement study, system setting, user acceptance test, assist end-user in software parallel run and software...


  • Kuala Lumpur, Kuala Lumpur, Malaysia Ekco Group Full time

    About YouWe are looking for candidates with existing experience in vulnerability management, cybersecurity, or related fields.Familiarity with vulnerability management tools (Qualys, Nessus, etc.) is required.Experience with attack surface management tools (Bitsight, CyCognito, etc.) and processes is desirable but not necessary.Good knowledge of fundamental...

  • Security Analyst L2

    1 week ago


    Kuala Lumpur, Malaysia Ensign Infosecurity (Malaysia) Sdn Bhd Full time

    Responsibilities - Monitor third party security feeds, forums, and mailing lists to gather information related to the client through automated means - Produce intelligence outputs to provide an accurate depiction of the current threat landscape and associated risk through the use of customer, community, and open source reporting - Produce actionable...

  • Business Analyst

    2 weeks ago


    Kuala Lumpur, Malaysia GENO Management Full time

    Position : Business Analysts Salary Range : RM 2,500 - RM 3,500 Location : Bukit Jalil Working Hours : 8am - 5pm Working Days : 5 days **Job Scope** - Responsible in software implementation according to the targeted project timeline on the user requirement study, system setting, user acceptance test, assist end-user in software parallel run and software...