Vulnerability Manager
Role Title:
Vulnerability Manager
Business Area:
Dedicated ServicesAbout This Role:
The Vulnerability Manager is responsible for overseeing the end-to-end vulnerability management process, ensuring security vulnerabilities are identified, prioritised, tracked, and remediated in line with agreed SLAs and business risk. The role focuses on governance, coordination, reporting, and continuous improvement rather than hands-on remediation.
Expectations From The Role:
|
Key Responsibilities:
· Own and operate the vulnerability management lifecycle: identify, triage, prioritise, remediate or mitigate, verify, and close · Analyze vulnerability scan outputs and prioritise remediation based on risk, exploitability, asset criticality, and business impact · Coordinate remediation actions across internal resolver teams and third parties; track progress against SLAs · Manage vulnerability exceptions using a documented, risk-based approach · Maintain accurate tracking of vulnerabilities, ownership, SLAs, tickets, and exceptions. · Produce regular operational and executive-level reporting, including trends and aged backlog. · Work with SOC/SIEM teams to correlate vulnerabilities with active threats where applicable. · Ensure alignment with internal security policies and support audit and customer assurance activities.
Key Interfaces · Security Operations Centre (SOC) · Infrastructure, patching, and platform teams · Service Management and Governance · Customer security and IT stakeholders
|
Requirements For A Successful Application:
Essential Experience & Skills · Proven experience managing or coordinating a vulnerability management function. · Strong ability to track and manage high-volume vulnerability data. · Excellent Excel skills and attention to data quality. · Clear communicator, capable of driving action across multiple teams · Risk-based mindset with the ability to distinguish real versus theoretical risk. · Experience producing concise management and executive reporting.
Desirable · Experience in a managed service or SOC environment. · Familiarity with vulnerability scanning tools (e.g. Qualys, Tenable). · Understanding of common security frameworks and controls (e.g. ISO 27001, NIST, CIS). Relevant security certification (e.g. CISSP, CISM, CEH) is an advantage.
Success Measures · Improved remediation compliance and reduced aged vulnerability backlog. · Timely, accurate vulnerability reporting and governance |