обновлено 6 дней назад
Vulnerability Management Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Vulnerability Management Analyst (Cybersecurity): Identifying, assessing, and coordinating remediation of vulnerabilities across a global, multi-product environment with an accent on vulnerability tooling, secure configuration benchmarks, and risk-based prioritisation. Focus on tuning SAST, DAST, SCA, CSPM, and IVS programmes, coordinating penetration testing, and designing remediation metrics and reporting.
Location: Hybrid in Birmingham, England, United Kingdom
Company
operates a global, multi-product business with an information security and data protection function supporting product security and risk management.
What you will do
- Configure, tune, maintain, and integrate vulnerability scanning tools with ticketing systems and CI/CD pipelines.
- Triage vulnerability findings, confirm genuine issues, assess risk, and prioritise remediation based on severity, exploitability, and business impact.
- Develop secure configuration benchmarks and hardening guidance aligned with recognised industry frameworks.
- Work with developers and engineers to explain findings, provide remediation guidance, track overdue actions, and escalate where necessary.
- Coordinate internal vulnerability scanning, web application testing, and penetration testing programmes with external providers.
- Design remediation SLAs, produce regular vulnerability reports, and improve vulnerability management processes and tooling.
Requirements
- At least 2 years of experience in vulnerability management, security operations, development, or a related security or IT role.
- Hands-on experience with vulnerability management tooling such as SAST, DAST, SCA, CSPM, or IVS.
- Knowledge of common vulnerability types and remediation approaches, including the Mitre ATT&CK Framework and OWASP Top 10.
- Experience triaging and risk-assessing findings and coordinating penetration testing or other third-party security engagements.
- Ability to explain technical findings to developers and non-technical stakeholders, manage parallel workstreams, and operate autonomously in an agile enterprise environment.
- Ability to read common programming languages is essential; scripting or coding experience is preferred.
Nice to have
- CompTIA Security+, CompTIA CySA+, GIAC GFACT, GIAC GPEN, or CEH certification.
- Experience developing scripts or code for automation.
Culture & Benefits
- Fully funded training pathway and mentoring support.
- 25 days of holiday plus bank holidays, a paid Wellbeing Day, flexible bank holidays, and the option to buy or carry over up to 5 additional days.
- Enhanced family-friendly leave, wedding or honeymoon leave, and an Employee Assistance Programme.
- Pension scheme, Corporate Medical Cash Plan, electric car salary sacrifice scheme, and payroll giving.
- Professional qualification funding, wellbeing workshops, a paid Volunteer Day, community groups, and employee discounts.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
Cyber Security Analyst
11 дней назад
Cybersecurity Analyst (AWS/Azure)
12 дней назад
Information Security Analyst (SaaS)
60 000 - 65 000GBP
11 дней назад
Lead Security Engineer
75 000 - 100 000GBP
10 дней назад
IT Compliance Analyst (Cybersecurity)
7 дней назад