Vulnerability Management Engineer
YOU SHOULD ONLY APPLY IF YOU HAVE SC CLEARANCE - YOU MUST BE BASED IN THE UK
Job Title: Find & Fix Vulnerability Engineer / Vulnerability Management Engineer
Location: Remote (UK) – occasional client site travel
Preferred location: South of England or South West England
Salary: £50,000 per annum
Clearance: Eligible for UK Security Clearance (SC)
Interview process: One stage
Start date: ASAP
Job description
We are hiring a Find & Fix Vulnerability Engineer to deliver hands‐on vulnerability management and remediation across cloud and on‐premises environments.
This role is focused on identifying, prioritising and fixing vulnerabilities, not report‐only security work. You will work across Azure, AWS and Microsoft security tooling, partnering with infrastructure, cloud and application teams to improve security posture and reduce risk.
The role is remote‐first, with occasional travel to client sites. All travel and food expenses are fully reimbursed.
Key responsibilities
- End‐to‐end vulnerability management lifecycle: identify, validate, prioritise, remediate, verify and close
- Cloud security remediation across Microsoft Azure and AWS
- Use Microsoft Defender for Cloud, Azure Advisor, Microsoft Cloud Security Benchmark (MCSB), AWS Inspector and AWS Security Hub
- Perform on‐prem vulnerability scanning, configuration assessments and remediation (Windows and Linux)
- Translate vulnerability findings and security advisories into practical remediation actions
- Coordinate patching, configuration hardening and compensating controls, validating fixes via rescans
- Work closely with cloud, infrastructure, DevOps and application teams using change control processes
- Maintain remediation evidence and reporting on vulnerability trends, SLAs and residual risk
- Deploy remediations at scale using DevOps practices and Infrastructure as Code (Terraform)
- Support continuous improvement of vulnerability management processes and secure configuration baselines
Required skills and experience
- Proven experience as a Vulnerability Engineer, Vulnerability Management Engineer, Security Engineer or Cloud Security Engineer
- Hands‐on vulnerability remediation across Azure, AWS and on‐prem environments
- Strong experience with Microsoft Defender, Defender for Cloud, Tenable/Nessus, AWS Inspector or Security Hub
- Experience supporting vulnerability assessments and penetration testing
- Strong understanding of secure configuration, cloud security posture management and remediation
- Experience using Terraform / Infrastructure as Code
- Windows and Linux security experience
- Strong analytical, documentation and communication skills
Qualifications (desirable)
- Degree in Computer Science, Information Technology or equivalent experience
- Azure or AWS certifications
- Experience working in regulated or security‐cleared environments
Additional information
- Must be eligible to pass UK Security Clearance (SC)
- Occasional out‐of‐hours work may be required
- Responsibilities may evolve in line with business needs