Onsite Vulnerability Manager

Posted 37 minutes ago

Apply now

About the role

  • Vulnerability Manager managing vulnerability processes in a global security team, ensuring protection against cyber threats. Role includes vulnerability identification, assessment, and remediation guidance.

Responsibilities

  • Be responsible for owning and operating the vulnerability management process for Computacenter.
  • Execute the roadmap for vulnerability management processes and technologies.
  • Be responsible for the day-to-day operation of vulnerability identification, assessment and alerting tooling.
  • Identify, evaluate and prioritise vulnerability remediation activities across the Computacenter group.
  • Provide expert security guidance to support resolver teams in the remediation of technical vulnerabilities and weaknesses.
  • Provide experienced support to the vulnerability analysts.
  • Operate the vulnerability management process across the Computacenter group to ensure cooperation amongst all centralised and regional resolver teams.
  • Remain current on the latest cyber security threats, new vulnerabilities and the Tactics, Techniques, and Procedures (TTPs) used by threat actors exploiting them.
  • Analyse vulnerability intelligence feeds to inform and prioritise vulnerability remediation.
  • Operate as a technical vulnerability SME and support on the Group’s response to new major vulnerabilities affecting Computacenter.
  • Support in vulnerability investigation and analysis on cyber security incidents to support the Computacenter Cyber Security Incident Response Team (CSIRT).
  • Proactively measure the effectiveness of the vulnerability management process through monitoring and conformance to policy and standards (patch, configuration etc).
  • Identify opportunities for the continual improvement of the vulnerability management programme.
  • Prepare regular, accurate and actionable reporting metrics to senior management and organisational stakeholders.
  • Deliver vulnerability exposure reviews to technical resolver groups for their business areas across the group.
  • Support the cyber risk management function by verifying that vulnerability controls are delivered for assets and information systems, identifying where controls are not being met and the cyber exposure that results in for Computacenter.
  • Support penetration testers in their delivery by providing accurate vulnerability analysis pre- and post-assessment.
  • Support CTO with the technical validation of security controls.
  • Support our internal organisation by ensuring vulnerability control requirements are delivered for assets and digital services.

Requirements

  • Demonstrable experience in Information and Cyber Security; especially vulnerability management.
  • Experienced in vulnerability analysis and assessment, including the operation of risk-based vulnerability management.
  • Experienced in the day-to-day operation of specialist security tooling for vulnerability identification and analysis (e.g., Tenable/Qualys/OWASP ZAP/MDE TVM etc.).
  • Experienced in preparing threat and vulnerability briefings for management and technical resolvers.
  • Practical experience in supporting IT operations including asset, configuration and patch management.
  • Understanding of technical IT security best practices including endpoint security, network security, cloud security and the key vulnerabilities and threats affect them.
  • Understanding of common IT enterprise technologies - Windows, Linux, cloud, networking platforms etc. and a desire to deliver success with new and evolving technologies.
  • Information security standards and frameworks including CIS, NIST, ISO 27001, Cyber Essentials (Plus), PCI DSS & GDPR.
  • The MITRE ATT&CK Framework.
  • Cyber threats and vulnerabilities.
  • Advanced Persistent Threats (APT) and their associated Tactics, Techniques, and Procedures (TTP).
  • Incident response and handling methodologies.
  • Risk management processes (e.g., methods for assessing and mitigating risk).
  • Recognised information security and/or information technology industry certification (CISM, CISSP, ISO27001 lead implementer, Nessus/Qualys or equivalent/superior).

Benefits

  • Health insurance
  • Retirement plans
  • Paid time off
  • Flexible work arrangements
  • Professional development opportunities

Job title

Vulnerability Manager

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

Professional Certificate

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job