At a Glance
- Tasks: Own and enhance our threat and vulnerability management lifecycle to reduce security risks.
- Company: Join Awaze, Europe's largest managed vacation rentals and holiday resorts business.
- Benefits: Enjoy a competitive salary, annual bonus, 25 days holiday, and hybrid working.
- Other info: Be part of a collaborative team with excellent career growth opportunities.
- Why this job: Shape the future of travel tech while working on high-impact security projects.
- Qualifications: Experience in vulnerability management and strong knowledge of security tools required.
The predicted salary is between 28800 - 48000 £ per year.
We are Awaze, the largest managed vacation rentals and holiday resorts business in Europe, which brings together some of the continent’s most trusted travel brands, including cottages.com, Hoseasons and Novasol.
With over 1.5 million bookings each year, we\'re proud to offer our guests a choice of over 100,000 properties in our portfolio, in 25 countries across Europe.
Position: Security Engineer (Threat & Vulnerability Management)
We’re entering an exciting new phase of our tech and product strategy, with a focus on innovation, experimentation, and conversion at the heart of everything we do. Our mission is to elevate the web and mobile experience for our guests and owners, driving seamless journeys across all our group companies.
To achieve our goals, we’re looking to make some key hires—are you ready to be part of the transformation and help shape the future of the travel industry?
🏡 About the role
We are seeking a Security Engineer (Threat & Vulnerability Management) to own and mature our vulnerability and threat intelligence lifecycle. This role will focus on proactively identifying, assessing, and reducing security risks across our environment. You will lead vulnerability scanning, penetration testing, bug bounty findings, patch management facilitation, and KPI reporting — ensuring our overall vulnerability posture is well understood and continuously improved. As part of a small, hands-on team, you will also contribute to wider security initiatives, incident response, and security awareness across the business.
🏡 Your day-to-day responsibilities
Threat & Vulnerability Management
- Operate and optimize vulnerability management tooling, including PortSwigger BurpSuite Enterprise, CrowdStrike Exposure Management, Wiz and BitSight.
- Facilitate patching cycles: organize and lead vulnerability review and remediation calls with IT/application teams, track progress, and drive accountability.
- Monitor and report on key vulnerability metrics and KPIs, presenting regular updates to security leadership.
- Manage third-party penetration testing activities, track findings, and ensure timely remediation.
- Oversee bug bounty program operations, triage reports, and coordinate with development teams for remediation.
- Continuously assess external attack surface and exposure, driving down risk and reporting posture improvements.
Threat Intelligence
- Monitor relevant threat intelligence sources to identify new vulnerabilities, exploits, and attack vectors.
- Provide actionable intelligence to IT and security teams, ensuring timely patching and mitigation.
- Contribute to the refinement of detection and response based on emerging threats.
Security Operations & Collaboration
- Work closely with IT, development, and product teams to embed vulnerability management into the SDLC.
- Contribute to broader security operations, including incident response, policies, security reviews, and audits.
- Support security awareness efforts by advising stakeholders on risks and mitigation strategies.
- Participate in security automation initiatives to improve efficiency and consistency of vulnerability processes.
🏡 What we’re looking for
- Experience in vulnerability management, threat intelligence, or related information security roles.
- Strong knowledge of vulnerability scanning, patch management, and penetration testing processes.
- Experience with security tools such as BurpSuite Enterprise, Wiz, CrowdStrike, BitSight, or equivalent platforms.
- Familiarity with vulnerability frameworks such as CVSS, OWASP Top 10, MITRE ATT&CK.
- Strong collaboration and influencing skills, able to drive remediation across multiple teams.
- Solid understanding of security best practices across applications, infrastructure, and cloud environments.
- Excellent analytical and problem-solving skills, with ability to prioritize risks and translate technical issues into business impact.
Preferred Qualifications
- Relevant security certifications (e.g., CISSP, CISM, OSCP, CEH, Security+).
- Experience working with bug bounty platforms (e.g., HackerOne, Bugcrowd).
- Familiarity with compliance frameworks such as ISO 27001, CIS Controls or NIST Controls.
- Scripting or automation experience (Python, PowerShell, or similar) to streamline vulnerability processes.
🏡 What will we offer you?
At Awaze, we’re building a world-class data science function at the heart of our growth and innovation strategy. You’ll have the opportunity to work on high-impact projects, shape the future of revenue & pricing, and be part of a forward-thinking, collaborative team.
Plus you\'ll also receive the following:
- Annual Bonus Scheme
- 25 days holidays plus bank holidays
- Holiday Discounts across our network
- Pension contribution scheme
- Private healthcare
- Hybrid working (2 days in Mcr office per week)
- Training & certifications
🏡 Get in touch, we\'d love to chat.
If you\'re excited by the idea of shaping the future of travel tech, we’d love to hear from you. Please send your profile and let’s chat.
Locations
Security Engineer (Threat & Vulnerability Management) in Cheshire, Warrington employer: Awaze
Awaze is an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration within Europe's largest holiday rentals business. Employees benefit from a strong focus on professional growth, with opportunities to influence strategic decisions and modernise finance through cutting-edge technology, all while enjoying the vibrant atmosphere of the travel industry.
StudySmarter Expert Advice🤫
We think this is how you could land Security Engineer (Threat & Vulnerability Management) in Cheshire, Warrington
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Awaze, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Awaze
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Awaze. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Engineer (Threat & Vulnerability Management) in Cheshire, Warrington
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Awaze insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Awaze that you’re committed to staying ahead in the game.
How to prepare for a job interview at Awaze
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Awaze to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Awaze.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.