Vulnerability Engineer in London

Vulnerability Engineer in London

London Full-Time No working from home possible
C

Work-mode : Hybrid - 3 days weekly from office

Skills : Vulnerability, Qualys, PowerShell and Microsoft SCCM/MECM

We at Coforge are looking for Vulnerability Engineer in London, UK.

Scope & Description of Required Work

  • Own the technical investigation and remediation of complex endpoint vulnerabilities across the workstation estate.
  • Analyse and prioritise findings from Qualys and other approved security platforms, considering technical impact, business risk and remediation feasibility.
  • Perform structured root cause analysis for vulnerabilities, failed deployments, recurring non-compliance and endpoint health issues.
  • Design, test and deliver sustainable engineering fixes that remove underlying causes and reduce repeated manual remediation.
  • Create, test, peer review and deploy enterprise application packages, security updates and configuration changes through Microsoft SCCM/MECM and related endpoint tooling.
  • Develop and maintain PowerShell automation for detection, remediation, validation, reporting and operational health checks.
  • Troubleshoot SCCM/MECM client health, software distribution, content delivery, deployment status and patch installation failures.
  • Use controlled pilot groups, technical validation and rollback planning to reduce deployment risk.
  • Work with the End User Platform and Security teams to agree remediation strategy, technical ownership and delivery priorities.
  • Recommend improvements to packaging standards, deployment controls, vulnerability workflows, reporting and endpoint engineering processes.
  • Produce clear technical documentation, remediation records, runbooks, knowledge articles and audit evidence.
  • Provide accurate progress, risk and dependency updates for vulnerability, compliance and service reporting.
  • Support remediation across physical workstations, laptops and Citrix virtual desktop environments.
  • Apply ITIL best practice across Incident, Request, Problem and Change management activities.
  • Perform system administration and advanced troubleshooting within Windows, Active Directory, Group Policy and Microsoft 365 environments.
  • Ensure solutions comply with TMHCC security policies, technical standards, controls and agreed service levels.

Out of Scope

  • Activities not explicitly listed in the Scope & Description of Required Work.
  • Changes to production services that have not completed the required TMHCC change control and approval process.
  • Ownership of security policy, risk acceptance decisions or business risk sign-off.
  • Work on unsupported platforms or systems outside the agreed endpoint estate unless separately authorised.

Deliverables & Delivery Milestones

  • Prioritised vulnerability remediation backlog based on approved security data and agreed delivery priorities.
  • Tested and peer-reviewed SCCM/MECM packages, security updates and configuration changes.
  • Production-ready PowerShell detection, remediation and validation scripts.
  • Root cause analysis records for recurring vulnerabilities, failed deployments and endpoint health issues.
  • Pilot, validation and rollback evidence for controlled deployments.
  • Runbooks, knowledge articles, remediation records and audit evidence.
  • Regular progress, risk, dependency and outcome reporting.
  • Delivery milestones and target dates to be agreed during onboarding and maintained through the applicable planning and change processes.

Acceptance Criteria

  • Agreed vulnerability remediation activities are completed in line with approved priorities, change controls and service levels.
  • Delivered packages, scripts and configuration changes pass agreed testing, peer review, pilot and technical validation requirements before production deployment.
  • Remediation includes clear evidence of outcome, validation results and rollback arrangements where applicable.
  • Root causes and recurring failure patterns are documented, with permanent engineering actions or technical debt items recorded where required.
  • Technical documentation, runbooks, knowledge articles, remediation records and audit evidence are complete, accurate and stored in the agreed TMHCC location.
  • Progress, risks, dependencies and blockers are reported accurately through the agreed governance process.
  • Solutions comply with TMHCC security policies, technical standards and operational processes.
  • Deliverables are accepted by the TMHCC Hiring Manager or nominated technical owner.

#J-18808-Ljbffr

Vulnerability Engineer in London employer: Coforge

Coforge is an excellent employer that fosters a collaborative and innovative work culture, particularly for those in the tech space. Located in London, employees benefit from a vibrant city atmosphere, ample professional growth opportunities, and a commitment to cutting-edge technology, ensuring that team members are at the forefront of industry advancements. With a focus on employee development and a supportive environment, Coforge stands out as a rewarding place to build a meaningful career in data architecture.

C

Contact Details:

Coforge Recruitment Team