Digital Business Analyst – Crowdsourced Vulnerability Discovery Programme (CVDP)

Full-time Job Type
On-site Work Arrangement
Mid-Level Experience
Apply Now Posted 3 weeks ago

On-site, remote mid-level role with Assurity Trusted Solutions, a subsidiary of GovTech. The position focuses on managing the Crowdsourced Vulnerability Discovery Programme, working with government agencies and security researchers to enhance cybersecurity.

Skills / Requirements

  • AI-assisted Development
  • Bug Bounty
  • Contract Administration
  • Data Analysis
  • GovTech Platforms
  • Penetration Testing
  • Process Improvement
  • Programme Reporting
  • Project Management
  • Technical Communication
  • Vendor Management
  • Vibe Coding
  • Vulnerability Management

Why Apply

The role leverages vibe coding techniques and GovTech platforms like Ownself Gather and Opus to automate workflows and improve reporting. This makes it ideal for candidates experienced in AI-assisted development.

What You'll Be Doing

Manage the planning and execution of vulnerability discovery programs, coordinate with government agencies, and oversee vendor relationships. You'll also support procurement processes and drive stakeholder communications.

Pay and Career Growth

The role offers competitive remuneration based on qualifications and experience, with the same benefits for contract staff as permanent employees. The company promotes a learning culture, supporting career growth and development.

Benefits and Perks

  • Career Growth
  • competitive salary
  • Learning culture
  • Same benefits for contract staff

Is This Role Right for You?

Good fit if you...

  • Experienced in managing IT or technology programs with a focus on cybersecurity.
  • Skilled in project management and vendor relationship management.
  • Comfortable using AI tools to streamline operations and improve efficiency.

May not be for you if...

  • Lacks experience in cybersecurity program management or bug bounty programs.
  • Uncomfortable working on-site and prefers fully remote roles.
  • Struggles with vendor management and contract administration.

Original Job Description

Assurity Trusted Solutions (ATS) is a wholly owned subsidiary of the Government Technology Agency (GovTech). As a Trusted Partner over the last decade. ATS offers a comprehensive suite of products and services ranging from infrastructure and operational services, governance and assurance services as well as managed processes. In a dynamic digital & cyber landscape where trust & collaboration is key, ATS continues to drive mutually beneficial business outcomes through collaboration with GovTech, government agencies and commercial partners to mitigate cyber risks and bolster security postures.
The Crowdsourced Vulnerability Discovery Programmes (CVDP) comprises three programmes: the Government Bug Bounty Programme (GBBP), the Vulnerability Rewards Programme (VRP), and the Vulnerability Disclosure Programme (VDP). The Programme Manager will lead the planning, execution, and monitoring of these programmes, working closely with government agencies, security researchers, and the appointed bug bounty vendor to ensure the programmes run successfully.
Responsibilities:
Plan, schedule, and oversee GBBP, VRP, and VDP runs
Coordinate with government agencies on programme participation and scoping timelines, including following up to ensure required data and documentation are submitted on time
Manage the CVDP vendor relationship, including contract administration, performance monitoring, and issue escalation, covering end-to-end preparation of each GBBP run and onboarding of researchers (recruitment, vetting, test account provisioning)
Support the triage team in preparing reports, and coordinate with agencies on programme matters if disputes arise
Support procurement and tender exercises, including drafting requirement specifications and evaluating vendor proposals
Prepare programme reporting, dashboards, and management updates for management and stakeholders
Drive stakeholder communications and programme outreach such as Agencies’ briefings to raise awareness and grow agency participation rates
Proactively identify and propose process improvement opportunities across CVDP operations, and lead their implementation — including leveraging vibe coding techniques and GovTech platforms (e.g. Ownself Gather, Opus) to automate workflows, improve reporting, and enhance programme efficiency

At least five (5) years of experience managing IT or technology programmes/projects; experience managing a bug bounty, vulnerability disclosure, or related cybersecurity programme is a strong plus
Strong project management skills to plan, execute, and monitor programme operations
Good verbal and written communication skills in English, with the ability to explain technical findings to non-technical stakeholders
Experience managing vendors or contracts, including tracking deliverables and service levels
Comfortable working with data to track programme metrics and produce reports for management
Demonstrated ability to propose and implement process improvements, including using AI-assisted development (vibe coding) or GovTech-approved platforms to streamline operations

Preferred
Project Management Professional (PMP), Certified IT Project Manager (CITPM), or equivalent certification
Familiarity with vulnerability management, penetration testing, or bug bounty concepts
Experience working with or within the public sector

Join us and discover a meaningful and exciting career with Assurity Trusted Solutions!
The remuneration package will commensurate with your qualifications and experience. Interested applicants, please click “Apply Now”.
We thank you for your interest and please note that only shortlisted candidates will be notified.
By submitting your application, you agree that your personal data may be collected, used and disclosed by Assurity Trusted Solutions Pte. Ltd. (ATS), GovTech and their service providers and agents in accordance with ATS’s privacy statement which can be found at:  https://www.assurity.sg/ or such other successor site.

A wholly-owned subsidiary of GovTech.
We promote a learning culture and encourage you to grow and learn.
Contract Staff enjoys the same benefits as Permanent Employees.