Vulnerability Management Consultant
Vulnerability Management Consultant - Location: Inverness or Preston, 5 days onsite - £500-568 per day depending upon experience Duration: 31/03/2027
This temporary contract is inside IR35 and will require working under the direction of the client delivery manager as part of a multi-disciplinary team. The successful candidate will follow established delivery processes and working practices.
Due to the secure nature of the position and working environment, you must have, or be eligible to obtain Security Clearance
More details relating to UK Security Clearance can be found here:
United Kingdom Security Vetting: clearance levels - GOV.UK
The Vulnerability Management Consultant operates within the Operational Integrator (OI) function in a multi-supplier (SIAM) environment, supporting the governance and coordination of vulnerability management activities across suppliers. The role supports the governance and visibility of vulnerability management activities across suppliers, ensuring risks are tracked, reported, and evidenced consistently without performing technical vulnerability remediation.
The role assists in ensuring vulnerabilities are identified, tracked, prioritised, and reported in accordance with client policies and agreed remediation timelines. Working with suppliers, service teams and security stakeholders, the consultant provides visibility of vulnerability status and supports the maintenance of accurate reporting and audit evidence.
This is a governance and coordination role and does not perform vulnerability scanning, security testing, patch deployment, or technical remediation activities.
Key Deliverables
Vulnerability reporting packs
Vulnerability status and remediation tracking
Supplier vulnerability performance metrics
Audit-ready evidence and reporting records
Governance inputs to security forums
Vulnerability Tracking & Coordination
Support the monitoring of vulnerabilities from identification through to closure
Ensure vulnerability records are maintained and updated by suppliers
Assist in tracking remediation progress against agreed service levels
Escalate overdue or high-risk vulnerabilities through agreed governance channels
Supplier Engagement (SIAM Model)
Coordinate with suppliers to obtain vulnerability status updates
Support the collection and validation of supplier vulnerability reports
Ensure reporting formats and data standards are applied consistently
Identify gaps in vulnerability information, ownership, or reporting
Vulnerability Reporting & Visibility
Produce routine vulnerability management reports
Support development of dashboards and metrics
Assist in identifying:
Aging vulnerabilities
Recurring issues
SLA breaches
Emerging vulnerability trends
Governance & Process Compliance
Support adherence to agreed vulnerability management processes
Ensure supplier activities align with client policies and standards
Assist with documenting risk acceptance and exception processes
Maintain evidence required for audits and assurance activities
Assurance & Evidence Support
Collect and organise vulnerability management evidence
Support compliance and assurance reviews
Maintain audit-ready documentation and reporting records
Assist in demonstrating process effectiveness to stakeholders
Your skills and experience
Essential
Experience in cyber security, information security, service management, or governance roles
Understanding of vulnerability management principles
Knowledge of basic vulnerability risk concepts including:
CVSS, KEV etc
Risk ratings
Remediation tracking
Strong analytical and reporting skills
Experience working with multiple stakeholders
Desirable
Exposure to SIAM or multi-supplier environments
Familiarity with vulnerability management tooling and reporting outputs
Understanding of cyber security governance and assurance
Experience in regulated or defence environments
Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website.
Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job.
Should the role require the successful candidate to undergo and be eligible for UK Security Vetting. Clearance sponsorship will be provided where required. Due to the nature of the work, candidates should meet the relevant residency requirements. If applicable, Reserved Post nationality restrictions will be confirmed by the client. Damia is committed to inclusive recruitment and welcomes applicants from all backgrounds.
Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.