Jobless Developer
govtech logo

Posted 6 days ago

Open

CVDP Triage Team Lead

SingaporeOn-site

AI Summary

Leads the triage team for Singapore's government bug bounty and vulnerability disclosure programmes, managing daily operations, specialist performance, and vulnerability report processing across whole-of-government systems.

About this role

We are seeking an experienced cybersecurity professional to lead our Crowdsourced Vulnerability Discovery Programme (CVDP) triage team. This role encompasses managing daily operations, leading a team of triage specialist, and ensuring effective handling of vulnerability reports across government systems for the Government Bug Bounty Programme (GBBP), Vulnerability Disclosure Programme (VDP), and Vulnerability Rewards Programme (VRP) across Whole-of-Government (WoG) systems.

What you'll do

  • Lead a lean team of triage specialists, ensuring quality, efficiency, and timely processing of vulnerability reports
  • Manage team performance, workload, and resource planning and perform hands-on triage and validation when required, particularly during peak periods or complex escalations
  • Act as escalation point for complex vulnerability validation and severity rating decisions
  • Mentor and train triage specialists on analysis, assessment, and documentation standards
  • Own and continuously improve triage SOPs, workflows, and tools, including integration and maintenance of key triage platforms
  • Develop scripts and automation (e.g., Python, workflow tools) to streamline triage processes, reporting, and platform integrations
  • Liaise with government agencies, system owners, and security researchers, and support the Programme Team in facilitating smooth internal-external collaboration
  • Analyze vulnerability trends, deliver presentations on notable findings, and prepare reports for management and stakeholders
  • Undertake additional responsibilities as required to support programme objectives

What you need

  • Degree in Cybersecurity, Computer Science, or related technical field
  • OSCP certification
  • Familiarity with web vulnerabilities (e.g. OWASP Top 10), including severity rating, vulnerability categorisation, root cause analysis, and remediation options
  • Familiarity with Burp Suite and Kali Linux to validate vulnerabilities
  • Good command of English (Oral and Written)
  • Experience mentoring junior team members
  • Strong analytical and problem-solving capabilities
  • Outstanding communication and stakeholder management skills
  • Collaborative leadership style with a strong commitment to mentoring and fostering a supportive team environment
  • Bug bounty or government/regulated environment experience preferred
  • Ability to plan leave around scheduled GBBP and Pre-GBBP cycles

Why join us

Lead a specialised team in a high-impact government cybersecurity programme, with direct exposure to complex vulnerability work and a clear pathway to senior security leadership roles.

Skills

Bug BountyBurp SuiteGBBPKali LinuxOSCPOWASP Top 10PythonRoot Cause AnalysisSeverity RatingSOP DevelopmentVDPVRPVulnerability TriageWorkflow Automation

Explore related jobs

Browse these categories

Market data for this role

All reports →