Skip to content

JobShark: Find the Right Job

 

Job Application

 
 
 

Please answer the following questions in order to process your application.

 
 
Email Address *
 
Select your working status in the UK *
 
 
 
File Attachments:
(2MB file maximum. doc, docx, pdf, rtf or txt files only)
 
Attach a CV * 
 
Cover letter 
OR
Clear covering letter
 
 
 * denotes required field
 
 
 
Additional Information:
 
First Name
 
Last Name
 
Address
 
Country
 
Home Telephone
 
Mobile/Cell
 
Availability/Notice
 
Salary Expectation GBP
 
Approximately how far are you willing to travel to work (in miles) ?
 
 
 

Key Privacy Information

When you apply for a job, JobShark will collect the information you provide in the application and disclose it to the advertiser of the job.

If the advertiser wishes to contact you they have agreed to use your information following data protection law.

JobShark will keep a copy of the application for 90 days.

More information about our Privacy Policy.

 

Job Details

 

Head of Vulnerability Management (Permanent)

Location: London Country: UK
 

Head of Vulnerability Management is required by a leading financial technology and data science firm. The Head of Vulnerability Managementwill be responsible for leading a "greenfield" global vulnerability management programme, identifying, assessing, and mitigating vulnerabilities in systems, networks, and applications. This role blends technical expertise with operational management, requiring close coordination with internal stakeholders to ensure the timely and efficient remediation of vulnerabilities.

The role entails managing and overseeing both the technical aspects of vulnerability identification and prioritisation, as well as the non-technical side involving communication, and coordination with cross-functional teams to ensure timely patching and remediation, compliance and reporting. Your role will include evaluating vulnerabilities for exploitability, aligning patching schedules, and overseeing, and ensuring the integrity of pre- and post-patch checks. The position reports directly to the Head of Security.

  • Lead the Vulnerability Management Programme: Oversee vulnerability scanning, analysis, prioritisation, and remediation efforts, ensuring alignment with corporate security goals and compliance.
  • Stakeholder Coordination: Collaborate with IT, Cloud, engineering, business and security teams to schedule patching and remediation activities. Ensure patching causes minimal disruption to business operations
  • Communication: Draft and send out clear communications on upcoming patching activities, vulnerability disclosures, and remediation plans. Report regularly to stakeholders on the status of vulnerability management efforts, including producing detailed management reports and metrics to track progress, highlight key issues, and ensure transparency in remediation actions.
  • Pre and Post-Patch Verification: Ensure all patches are properly tested before deployment and verify the success of patches post-deployment using relevant tools and methods.
  • Vulnerability Assessment and Exploitability Analysis: Assess which vulnerabilities are most critical to the business, prioritising them based on potential exploitability and risk.
  • Collaboration: Work with security teams globally, aligning efforts and sharing best practices to maintain a secure and resilient environment.
  • Continuous Improvement: Stay updated on the latest vulnerability trends, attack vectors, and cybersecurity threats by following industry news, participating in relevant forums, and maintaining vendor relationships. Recommend and implement tools, automation, and processes to improve the efficiency and accuracy of vulnerability detection, analysis, and remediation
  • External Penetration Testing Coordination: Collaborate with external vendors to schedule and coordinate penetration testing activities. Ensure that the scope of the tests aligns with organizational security goals and regulatory requirements. Communicate test results to relevant stakeholders, including producing reports that detail findings, metrics, and recommended remediation actions. Track the resolution of identified vulnerabilities to ensure timely mitigation
  • Incident Response Support: Collaborate with the incident response team to investigate and drive remediation of vulnerabilities with stakeholders that are being actively exploited or pose significant risks to the business. Provide vulnerability data, security research and context during security incidents to support containment, remediation, and recovery efforts
  • Collaboration with Product Security Team: Work closely with the product security team to ensure vulnerabilities in internally developed applications are effectively tracked and remediated. Regularly produce reports and metrics on the status of application vulnerabilities and remediation progress, ensuring visibility across teams and stakeholders

Your present skill set

  • Minimum 5 years of experience in vulnerability management or a similar security role, with at least 2 years in a leadership capacity
  • Strong technical knowledge with hands on experience using vulnerability scanning/assessment tools
  • Familiarity with both on-premise and cloud environments (AWS, Azure) and hybrid setups.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Experience in coordinating patch management processes across a large organisation and time zones, ensuring minimal business disruption
  • Ability to evaluate vulnerabilities based on risk and exploitability, guiding patching priorities.
  • Strong organisational skills to manage patch schedules, stakeholder coordination, and compliance requirements

Desirable:

  • Certifications such as CISSP, CISM, or relevant security qualifications
  • Experience working in a fast-paced, globally distributed organisation
  • Familiarity with regulatory requirements and security standards (eg, ISO 27001, NIST)


Posted Date: 11 Oct 2024 Reference: JS-BBBH114880 Employment Agency: Etonwood Contact: Matt O'Hare