At a Glance
- Tasks: Lead and govern vulnerability management across suppliers, ensuring effective risk prioritisation and reporting.
- Company: Join a dynamic team in a leading security governance role.
- Benefits: Competitive daily rate, hybrid working, and opportunities for professional growth.
- Other info: Work in a complex environment with excellent career advancement opportunities.
- Why this job: Make a real impact on cybersecurity by driving supplier accountability and improving processes.
- Qualifications: Significant experience in vulnerability management and strong stakeholder management skills.
The predicted salary is between 58349 - 71315 £ per year.
Duration: contract to run until 31/03/2027
Location: Inverness or Preston. Hybrid
Rate: up to £644 p/d Umbrella inside IR35
Clearance required: Sole UK Nationality with Active SC Clearance.
Role purpose / summary
The Senior Vulnerability Management Consultant operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of vulnerability management across a complex multi-supplier environment. The role is responsible for ensuring suppliers manage vulnerabilities consistently, effectively, and in accordance with client policy, regulatory requirements, and risk appetite. Working across security, service management, supplier, and client governance functions, the consultant provides a consolidated view of vulnerability risk and drives continuous improvement across the vulnerability management lifecycle. This is a governance, assurance, and supplier management role and does not perform vulnerability scanning, penetration testing, exploit analysis, or technical remediation.
Key Responsibilities:
- Vulnerability Management Governance
- Own and govern the vulnerability management framework across suppliers
- Define and maintain:
- Vulnerability classification standards
- Risk-based prioritisation models
- Remediation timelines
- Exception management processes
- Ensure alignment to client security policies and control requirements
- Supplier Governance & Performance Management
- Act as the primary OI lead for vulnerability management
- Challenge, validate, and assure supplier vulnerability processes
- Drive consistency in reporting, remediation, and evidence standards
- Manage escalations relating to high-risk or overdue vulnerabilities
- Risk Management & Prioritisation
- Ensure suppliers apply risk-based prioritisation methodologies, including:
- CVSS
- Known Exploited Vulnerabilities (KEV)
- Business criticality considerations
- Maintain visibility of enterprise vulnerability exposure
- Oversee risk acceptance and exception management activities
- Reporting & Executive Visibility
- Produce consolidated vulnerability risk reporting across suppliers
- Provide insight into:
- Risk posture
- Remediation effectiveness
- Compliance performance
- Emerging threat exposure
- Support governance boards and client security leadership
- Assurance & Evidence Management
- Define vulnerability management evidence requirements
- Ensure end-to-end traceability of:
- Identification
- Prioritisation
- Remediation
- Validation
- Support audits, assurance reviews, and compliance activities
- Continuous Improvement
- Identify trends, recurring weaknesses, and process improvement opportunities
- Drive maturity improvements across supplier processes
- Support optimisation of reporting, governance, and operating models
- Contribute to security operating model evolution within the SIAM environment
Your skills and experience
Essential
- Significant experience in Vulnerability Management, Cyber Governance, Security Operations Governance, or GRC roles
- Strong understanding of:
- Vulnerability management lifecycle
- Risk-based remediation approaches
- Security governance frameworks
- Experience operating within complex multi-supplier environments
- Strong stakeholder management and supplier challenge capability
- Experience presenting risk information to senior stakeholders
Desirable
- Knowledge of:
- NIST CSF
- NCSC guidance
- ISO 27001
- Secure by Design principles
- Experience in Defence, Government, or highly regulated environments
- Exposure to security assurance and audit activities
Key Deliverables
- Vulnerability Management Framework
- Consolidated supplier vulnerability reporting
- Executive vulnerability risk dashboards
- Vulnerability governance and assurance packs
- Continuous improvement roadmap
- Audit-ready evidence repository
Role Definition
The role governs and assures vulnerability management across suppliers, ensuring vulnerabilities are consistently prioritised, remediated, evidenced, and reported to the client through a risk-based and audit-ready approach, without performing technical remediation activities.
What This Role Does / Does Not Do
Does
- Govern, assure, challenge and coordinate
- Provide enterprise-wide vulnerability risk visibility
- Drive supplier accountability
- Support risk-informed decision making
Does Not
- Operate vulnerability scanners
- Perform technical security testing
- Deploy patches or fixes
- Own remediation engineering activities
All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!
If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
SC Vulnerability Management Lead CGEMJP00351666 in Preston employer: All The Top Bananas
My Four Wheels is an exceptional employer, offering a rewarding career as a Trainee Driving Instructor with flexible working hours and the potential to earn up to £50,000+ annually. With comprehensive training provided through our new Training Academy, employees benefit from ongoing support and resources, ensuring a fulfilling journey towards becoming a qualified instructor while enjoying the satisfaction of teaching locally in Westfield, Surrey.
StudySmarter Expert Advice🤫
We think this is how you could land SC Vulnerability Management Lead CGEMJP00351666 in Preston
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like All The Top Bananas.
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like All The Top Bananas.
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like All The Top Bananas.
We think you need these skills to ace SC Vulnerability Management Lead CGEMJP00351666 in Preston
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives All The Top Bananas a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at All The Top Bananas; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at All The Top Bananas.
How to prepare for a job interview at All The Top Bananas
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with All The Top Bananas for the SC Vulnerability Management Lead CGEMJP00351666, be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at All The Top Bananas.
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the SC Vulnerability Management Lead CGEMJP00351666 role at All The Top Bananas.