Vulnerability Management Analyst
Vulnerability Management Analyst
Preston - hybrid working (2 days per week onsite)
Up to £47,000 + excellent corporate benefits package
Sole UK Nationals only/No Dual Nationals - Eligibility for SC clearance required
Finding a vulnerability is only the beginning. The real challenge is making sure somebody fixes it.
We're looking for a Vulnerability Management Analyst to join a growing cyber security team supporting a major client programme. You'll take identified vulnerabilities and help drive them through prioritisation, remediation and closure-working with suppliers and technical teams to ensure nothing important is overlooked or left unresolved.
This isn't a Penetration Tester role, and you won't spend your days running vulnerability scans. It's ideal for someone working as a Vulnerability Analyst, Vulnerability Remediation Analyst, Cyber Security Analyst, Security Governance Analyst or Vulnerability Management Coordinator who is comfortable combining cyber knowledge with reporting, organisation and plenty of stakeholder engagement.
What you'll be doing
- Tracking vulnerabilities from identification through to remediation and closure.
- Working with suppliers and technical owners to agree actions and timescales.
- Prioritising issues using severity, CVSS scores, risk ratings and remediation SLAs.
- Escalating high-risk, overdue or repeatedly unresolved vulnerabilities.
- Producing dashboards and reports covering vulnerability ageing, trends and SLA performance.
- Maintaining accurate records and audit-ready evidence.
- Supporting security governance, assurance and risk-exception processes.
- Helping improve the effectiveness of the wider vulnerability management service.
What we're looking for
- Previous experience within vulnerability management, cyber security, information security or security governance.
- Experience coordinating or tracking vulnerability remediation.
- A good understanding of CVSS, vulnerability severity, risk ratings and remediation processes.
- Familiarity with tools such as Qualys, Tenable, Brinqa, Rapid7 InsightVM or similar.
- Strong reporting, data interpretation and documentation skills.
- Confidence engaging suppliers and technical stakeholders-and following actions through to completion.
- Experience working within a structured, regulated or multi-supplier environment would be particularly useful.
- Vulnerability management or security qualifications would be advantageous.
Location and security requirements
You'll work on a hybrid basis, attending the client site in Preston two to three days per week.
Due to the security requirements of the programme, applicants must:
- Sole UK citizen
- Be eligible to obtain Security Check clearance (SC).
- Lived continuously in the UK for the past five years.
There are several positions available, making this a great opportunity to join an expanding team and build your career within a large, established cyber security environment.
If you understand vulnerabilities but are equally good at working with people, keeping track of actions and making sure risks are properly resolved, we'd love to hear from you.
RSG Plc is acting as an Employment Agency in relation to this vacancy.