Назад
Company hidden
3 дня назад

Vulnerability Manager (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Manager (Cybersecurity): Leading vulnerability management and penetration testing governance across legacy, cloud, containerised, and third-party environments with an accent on risk-based prioritisation, remediation assurance, and audit readiness. Focus on building a high-performing vulnerability management team, improving security coverage and reporting, and translating technical findings into clear business risk narratives.

Location: Liverpool, England, United Kingdom; flexible hybrid working model.

Company

hirify.global operates the Very digital retail platform and serves millions of customers.

What you will do

  • Own and continuously improve the vulnerability management lifecycle across legacy, cloud, containerised, and third-party environments.
  • Coordinate the security penetration testing framework, including scope, frequency, execution, retesting, and closure.
  • Triage, prioritise, and track vulnerabilities and penetration testing findings through remediation.
  • Govern risk acceptance, exceptions, compensating controls, and audit evidence.
  • Report on risk posture, trends, coverage, and performance to senior stakeholders and governance forums.
  • Build, hire, coach, and develop a sustainable vulnerability management team while improving tooling, data quality, asset coverage, and testing scope.

Requirements

  • Strong experience coordinating vulnerability management and security penetration testing in complex enterprise environments.
  • Technical background in application or infrastructure security, cloud security, vulnerability assessment, and remediation validation.
  • Strong understanding of penetration testing methodologies across applications, infrastructure, cloud, and externally exposed services.
  • Experience applying risk-based judgement beyond severity scoring, including exploitability, exposure, and business context.
  • Experience working with engineering teams where remediation ownership sits outside security, with strong stakeholder management and reporting skills.
  • Right to Work checks are required; the role is based in the United Kingdom.

Nice to have

  • Experience aligning vulnerability governance with ISO 27001 and/or NIST.
  • Hands-on experience configuring and operating vulnerability testing tools.
  • Experience with cloud-native and legacy environments.
  • Experience mentoring analysts or leading capability uplift.
  • Understanding of secure SDLC and modern engineering delivery models.

Culture & Benefits

  • Flexible hybrid working model.
  • £1,000 flexible benefits allowance.
  • 30 days of holiday plus bank holidays.
  • LinkedIn Learning access and performance- and business-related bonus potential.
  • Up to 25% discount on Very.co.uk and matched pension contributions up to 6%.
  • Inclusive culture with reasonable adjustments available throughout the recruitment process.

Hiring process

  • Initial Teams call with the hiring team.
  • One-hour formal interview with competency and technical questions.
  • Take-home task as part of the second stage; credit, CIFAS, Right to Work, and potentially DBS checks may apply.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →