At a Glance
- Tasks: Lead vulnerability assessments and collaborate with teams to enhance security.
- Company: Join John Lewis Partnership, a leading employee-owned retailer in the UK.
- Benefits: Enjoy hybrid working, a supportive culture, and a focus on work-life balance.
- Why this job: Shape security strategies while working with cutting-edge tools in a collaborative environment.
- Qualifications: Experience in Vulnerability Management and knowledge of security best practices required.
- Other info: Opportunities for personal growth and innovation in a dynamic team.
The predicted salary is between 42000 - 58000 £ per year.
You will need to login before you can apply for a job.
View more categories View less categories Sector Retail and Wholesale Role Senior Executive Contract Type Permanent Hours Full Time
About the role
Join the Information Security Engineering team at John Lewis Partnership to help build a secure future for an iconic brand. We work to protect our customers, Partners, and business against an ever-evolving cyber threat landscape.
The John Lewis Partnership\’s Information Security strategy is bold and ambitious. We provide a collection of security services, delivered via people, processes and technology. Working collaboratively, these services ensure that customers can shop with us efficiently, safely and securely, every single day.
Our Threat Defence team is at the forefront of our cyber resilience, proactively monitoring threats, identifying vulnerabilities, and engineering robust security defences.
As a Senior Information Security Analyst focusing on Vulnerability Management, you\’ll be instrumental in identifying, assessing, and driving the remediation of vulnerabilities across our diverse technology estate.
You\’ll empower our Security Operations Centre to stay ahead of the latest threats by ensuring we understand and address our risk posture effectively. This is a pivotal role where your expertise will directly strengthen our defences and protect millions of customers and Partners.
This is a great opportunity to directly shape our security posture, getting hands-on with leading vulnerability management tools. You\’ll thrive in an agile, supportive, and highly collaborative team where innovation isn\’t just encouraged, it\’s expected.
At a Glance
- Salary: £50,000 – £70,000 depending on experience
- Contract type: Permanent
- Hybrid Working: Based at our Bracknell Head Office with a flexible hybrid model (typically 1 day per week in the office, primarily Tuesdays, with ad-hoc visits as required by business needs). We support a healthy work-life balance.
What You\’ll Be Doing:
In this hands-on technical analysis role, you will:
- Lead the identification and assessment of vulnerabilities across our applications, infrastructure, and cloud environments using our established tooling
- Develop, refine, and optimise vulnerability scanning profiles, dashboards and reports to ensure comprehensive coverage and actionable insights
- Analyse vulnerability data to prioritise risks, identify trends, and provide clear, actionable remediation guidance to relevant technology teams
- Collaborate closely with development, operations, and infrastructure teams to ensure timely and effective remediation of identified vulnerabilities
- Contribute to the continuous improvement of our vulnerability management processes, policies, and procedures, aligning with industry best practices
- Provide vulnerability context and analysis to support incident response activities.
What You\’ll Have (Essential Skills):
- Extensive proven experience in a Vulnerability Management role
- Proven hands-on experience with vulnerability management platforms, such as Qualys
- Strong understanding of vulnerability assessment methodologies and risk scoring (e.g. CVSS)
- Strong collaboration skills working with application and infrastructure teams within a security context
- In-depth working knowledge of security best practices and frameworks (e.g., Mitre ATT&CK, OWASP Top 10, NIST).
Even Better If You Have (Desirable Skills):
- Knowledge of cloud security vulnerabilities and associated scanning techniques (specific experience with Google Cloud vulnerabilities would be of particular benefit)
- Experience with scripting or automation to enhance vulnerability management processes (e.g. Python) and to drive efficiency and innovation
- Familiarity with patch management processes and tools
- Relevant Information Security certifications (e.g. CompTIA Security+, CySA+, CEH, CISSP) or a related degree.
Ready to Apply?
- Simply upload your CV and complete our application questions.
We advise saving the application questions to a separate document before entering on Workday for future reference.
- Internal Applicants – Please click here to view the job outline – Job Outline – SENIOR INFORMATION SECURITY ANALYST.pdf
#LI-HEADOFFICE
#LI-Hybrid
#LI-LS1
The Partnership
We\’re the largest employee owned business in the UK and home of our cherished brands, John Lewis and Waitrose. We\’re not just employees, we\’re Partners, driven by our purpose to build a happier world. As we look to our future, there\’s never been a more exciting time to join us.
We\’re ruthlessly focused on being brilliant at retail. We continue to innovate, adapt and diversify. Never Knowingly Undersold on price, quality and service in John Lewis and passionately serving food-lovers in Waitrose.
As Partners we all share the responsibility of ownership and in its rewards. We use our voices to contribute to our success, working together through the good and challenging times, holding true to our behaviours and treating everyone with kindness and respect.
We all own making the Partnership somewhere we belong. Embracing our differences and creating an environment where we\’re free to be ourselves and can THRIVE. Growing ourselves individually, and as a collective.
As Partners, we make all the difference. And, we all own it.
Important points to note:
It\’s important to note that some of our roles are subject to pre-employment vetting (which may include DBS checks for successful candidates). If required, you\’ll be informed and provided with information about vetting during the recruitment process and we encourage you to complete any vetting documents quickly to avoid delays. Any DBS checks required will be carried out by a third-party registered body and financial probity checks may also be required for some of our roles.
We also recommend that you apply as soon as possible as vacancies can close early if we see a high number of applicants.
We want all of our Partners to have a good work-life balance and we support flexible working. This might mean flexible or compressed hours, job sharing or shorter hour contracts, where possible. Please discuss this further with the hiring manager during your interview.
Company
Learn more about this company
Visit this company’s hub to learn about their values, culture, and latest jobs.
Visit this company’s hub to learn about their values, culture, and latest jobs.
Create a job alert and receive personalised job recommendations straight to your inbox.
#J-18808-Ljbffr
Senior Vulnerability Management Analyst employer: ENGINEERINGUK
Contact Detail:
ENGINEERINGUK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Vulnerability Management Analyst
✨Tip Number 1
Familiarise yourself with the specific vulnerability management tools mentioned in the job description, such as Qualys. Having hands-on experience or even a solid understanding of how these tools work will give you an edge during discussions.
✨Tip Number 2
Stay updated on the latest trends in cybersecurity and vulnerability management. Being able to discuss recent vulnerabilities or incidents can demonstrate your passion and knowledge in the field during interviews.
✨Tip Number 3
Network with professionals in the cybersecurity field, especially those who work in vulnerability management. Engaging in relevant forums or attending industry events can provide insights and potentially lead to referrals.
✨Tip Number 4
Prepare to discuss your collaboration skills, as the role requires working closely with various teams. Think of examples from your past experiences where you successfully collaborated to resolve security issues.
We think you need these skills to ace Senior Vulnerability Management Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your extensive experience in Vulnerability Management. Include specific examples of tools you've used, like Qualys, and methodologies you're familiar with, such as CVSS.
Craft a Strong Cover Letter: In your cover letter, express your passion for information security and how your skills align with the role. Mention your collaborative experience with development and operations teams to showcase your teamwork abilities.
Highlight Relevant Skills: Clearly outline your understanding of security best practices and frameworks, such as Mitre ATT&CK and OWASP Top 10. If you have knowledge of cloud security vulnerabilities, be sure to include that as well.
Prepare for Application Questions: Before applying, save the application questions to a separate document. This will help you formulate thoughtful responses that reflect your expertise and fit for the role.
How to prepare for a job interview at ENGINEERINGUK
✨Showcase Your Technical Expertise
As a Senior Vulnerability Management Analyst, it's crucial to demonstrate your extensive experience with vulnerability management platforms like Qualys. Be prepared to discuss specific tools and methodologies you've used in previous roles, as well as any relevant certifications you hold.
✨Understand the Company’s Security Strategy
Familiarise yourself with John Lewis Partnership's Information Security strategy and their approach to cyber resilience. This will not only show your interest in the company but also allow you to align your answers with their goals during the interview.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills in real-world situations. Think about past experiences where you identified vulnerabilities and how you collaborated with teams to remediate them effectively.
✨Emphasise Collaboration Skills
Highlight your ability to work closely with development, operations, and infrastructure teams. Provide examples of how you've successfully communicated technical information to non-technical stakeholders, ensuring timely remediation of vulnerabilities.