{"id":1318534,"url":"https://alion.io/job/cmcglobal-vulnerability-manager","title":"Vulnerability Manager","company":{"id":3827704,"name":"CMC Global","domain":"cmcglobal.com.vn","url":"https://alion.io/company/cmcglobal","size_band":"201-500","is_staffing_agency":false,"employer_type":"staffing","is_intermediary":false,"listed_via":null,"ats_vendor":"Career site","truth_index":{"grade":"C","score":66,"open_postings":100,"ghost_share":0.57,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-28T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Vietnam"],"countries":["VN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":10000,"max_usd":28000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":309},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"OWASP","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"GCP","optional":true},{"name":"Kubernetes","optional":true}],"status":"live","first_seen_at":"2026-06-11T06:35:37Z","employer_posted_date":"2026-09-26","last_verified_at":"2026-09-26T23:32:15Z","board_verified":false,"closed_at":null,"days_open":109,"trust":{"level":"ghost","repost_count":0,"flags":["stale","company_stale"],"days_open":108},"description":"JOB DESCRIPTION\nWe are looking for an experienced Vulnerability Manager to lead our efforts in identifying, assessing, and mitigating security vulnerabilities in various software products. The ideal candidate will have a deep understanding of application security, risk assessment, and mitigation strategies, along with a proven track record of driving security initiatives within complex software environments.\nKey Responsibilities\nThreat Analysis: Analyze and prioritize identified vulnerabilities based on potential impact and exploitability, and provide actionable recommendations to development teams for remediation. \nMitigation Planning: Collaborate with cross-functional teams to develop and implement effective mitigation strategies, including providing guidance on secure coding practices and architectural improvements. \nRisk Management: Assess security risks associated with vulnerabilities and track them through resolution. Provide clear risk communication to technical and non-technical stakeholders. \nCompliance and Standards: Stay up-to-date with industry security standards, regulations, and best practices. Ensure that our software products adhere to relevant security standards. \nIncident Response: Contribute to the development and enhancement of incident response plans and processes, ensuring timely and effective responses to security incidents. \nVulnerability Assessment: Conduct regular and comprehensive vulnerability assessments on our platforms and software applications to identify potential security weaknesses and threats. \nReporting: Generate regular reports for executive leadership, summarizing the security posture of our software applications, ongoing vulnerability management efforts, and progress toward resolution. \nREQUIREMENTS\nBachelor’s or Master’s degree in Computer Science, Information Security, or a related field. \nProven experience (2+ years) in vulnerability management, application security, and secure coding practices, preferably in the fintech industry. \nSolid understanding of common application vulnerabilities (OWASP Top Ten), as well as security standards and frameworks (ISO 27001, NIST, etc.). \nExperience with security assessment tools, penetration testing techniques, and vulnerability scanning tools. \nFamiliarity with secure software development lifecycle (SDLC) principles. \nProfessional certifications such as CISSP, CISM, CEH, or related certifications are a plus. \nStrong communication and interpersonal skills, with the ability to collaborate effectively with technical and non-technical teams. \nProven ability to manage multiple projects, prioritize tasks, and meet deadlines. \nPreferred qualifications:\nKnowledge of container-based environments (Kubernetes). \nKnowledge of cloud-based platforms (AWS, Azure, GCP). \nFundamental knowledge on DLT (Distributed Ledger Technology) is highly desirable. \nRelevant certifications (e.g., SANS, CISSP, etc.) is a plus\nBENEFITS\nAttractive compensation package: 14-month salary scheme plus annual bonus and additional allowances\nAnnual bonus package tailored based on performance and contribution\nYoung, open, and dynamic working environment that promotes innovation and creativity\nOngoing learning and development with regular professional training and opportunities to enhance both technical and soft skills\nExposure to cutting-edge technologies and diverse real-world enterprise projects\nVibrant company culture with regular team-building activities, sports tournaments, arts events, Family Day, and more\nFull compliance with Vietnamese labor laws, plus additional internal perks such as annual company trips, special holidays, and other corporate benefits\nHOW TO APPLY\nPlease send your application via email: \n*By submitting your application to , you acknowledge that you have read, understood, and agreed to CMC Global’s REGULATIONS ON THE PROTECTION OF CANDIDATES’ PERSONAL INFORMATION.\nThe post Vulnerability Manager appeared first on CMC Global.","description_format":"text","description_chars":4010,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Web3 & dApps"],"lifecycle":[{"event":"open","at":"2026-09-26T20:13:45Z"}],"liveness":{"score":5,"band":"cold","label":"Long shot","p_open":1,"p_active":0.179,"p_room":0.28,"age_days":108,"expected_fill_days":30,"reasons":["conf:30","stale_co","velocity","ghost","win:tail","crowd:junior,brand"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/cmcglobal-vulnerability-manager","json_url":"https://alion.io/job/cmcglobal-vulnerability-manager.json","meta":{"generated_at":"2026-09-29T02:59:43Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2659,"day_limit":5000,"remaining_today":2341,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}