At a Glance
- Tasks: Lead the Vulnerability Management team and oversee risk prioritisation and remediation.
- Company: Join Fitch Group, a leader in global securities markets with a commitment to innovation.
- Benefits: Enjoy a hybrid work environment, comprehensive healthcare, and tuition reimbursement.
- Why this job: Make a real impact in cybersecurity while developing your leadership skills.
- Qualifications: 7-10 years in Information Security with strong leadership and collaboration skills.
- Other info: Be part of a culture that values learning, mobility, and community engagement.
The predicted salary is between 72000 - 108000 ÂŁ per year.
Fitch Group is currently seeking a Director of Vulnerability Risk based out of our Manchester office. We are seeking a Director to lead our Vulnerability Management (VM) team. This role is ideal for an experienced security leader with a risk mindset who can oversee all aspects of vulnerability management, including identification, risk prioritization, and remediation of vulnerabilities discovered. The ideal candidate for this role will bring innovative ideas on how to consistently apply risk prioritization through automation, leveraging AI where appropriate.
Success will look like:
- Application of a risk mindset with consideration for the company’s set of standing security controls
- Ideas on opportunities to strengthen protection of critical assets
- Strong collaboration across the vulnerability management teams and stakeholders
- Delivering real‑time metrics reports
- Remediation aligned with organizational risk priorities
This is a new role to oversee a recently established unified vulnerability management program, covering infrastructure and cloud scanning, application security testing, and penetration testing.
How You’ll Make an Impact:
- Define and execute the strategic roadmap for the Unified Vulnerability Management program, including resource planning, performance tracking, and establishing and reporting on metrics (key performance indicators; key risk indicators; and objectives and key results) for the program.
- Lead the end‑to‑end vulnerability management lifecycle using a consistent, risk‑based assessment methodology that evaluates likelihood, impact, control environment and Fitch specific business context, ensuring timely remediation and compliance with internal policies.
- Govern the intake, normalization, and triage of findings originating from tools and assessments to ensure alignment with a unified lifecycle management process.
- Manage vulnerabilities identified from scanning tools covering open source, custom source code, dynamic application scanning, static application scanning, and cloud security posture management solutions.
- Provide risk‑informed visibility to stakeholders through clear dashboards and other reporting mechanisms which indicate remediation expectations.
- Ensure proper reporting of vulnerabilities to stakeholders and drive remediation efforts from an Information Security perspective.
- Develop strong partnerships with engineering, application development, and infrastructure teams to ensure aligned remediation workflows and streamlined ticketing processes for opening and closing vulnerabilities.
- Maintain and track team workload, ensuring transparency and accountability.
- Collaborate with subject matter experts across InfoSec and Technology to contextualize findings, validate assessments, resolve ambiguity and accelerate closure without compromising risk posture.
- Own and operationalize Fitch’s cyber risk taxonomy, threat intelligence, compensating control analysis, and architectural context to ensure findings are prioritized appropriately.
- Perform contextual analyses for vulnerability risk prioritization based on the following criteria: the business criticality of systems to Fitch, cloud architecture details such as network segmentation and access controls, understanding of system and application architecture, and data confidentiality.
- Produce and maintain dashboards, metrics and trend analyses that facilitate consumption of risk information and enable responses to requests for executive reporting and audit requests.
- Deliver VM team projects on time and on budget, ensuring alignment with department goals, organizational goals, and regulatory requirements.
You May be a Good Fit if:
- The ideal candidate will have 7-10 years of progressive leadership experience in Information Security, with at least 2 years in a dedicated Vulnerability Management role.
- They should demonstrate strong leadership skills, experience managing vulnerabilities across SAST, DAST, SCA, infrastructure, and CSPM solutions, and excellent communication and collaboration abilities for engaging technical teams and senior stakeholders.
What Would Make You Stand Out:
- 7+ years of progressive security experience, with at least 3+ years assessing and managing vulnerability risks for multi‑cloud enterprise systems.
- Experience applying industry frameworks and compliance standards (NIST, DORA) to apply risk classifications during the vulnerability lifecycle management process.
- Experience producing contextual analysis for vulnerability risk prioritization based on business criticality of systems, cloud architecture details such as network segmentation and access controls, understanding of system and application architecture, and data confidentiality.
- Experience coordinating management of multiple vulnerability scanning tools and managing vulnerabilities identified from scanning tools covering open source, custom source code, dynamic application scanning, static application scanning, infrastructure scanning and cloud security posture management solutions.
- Experience managing remediation lifecycles through enterprise ticketing systems for vulnerability tracking and workflow automation.
- Proven ability to create executive‑level dashboards and reports for vulnerability metrics.
- Excellent communication and collaboration skills for engaging technical teams and senior stakeholders.
- Leadership and team management skills, including resource planning, OKR setting, and performance reviews.
- Strong problem‑solving skills and ability to make risk‑based decisions while managing multiple projects simultaneously.
- Experience leveraging or guiding the work to use AI‑powered security tools or platforms to improve vulnerability detection and remediation workflows.
Why Choose Fitch:
- Hybrid Work Environment: 2 to 3 days a week in office required based on your line of business and location.
- A Culture of Learning & Mobility: Dedicated trainings, leadership development and mentorship programs designed to ensure that your time at Fitch will be a continuous learning opportunity.
- Investing in Your Future: Retirement planning, financial wellness and tuition reimbursement programs that empower you to achieve your short and long‑term goals.
- Promoting Health & Wellness: Comprehensive healthcare offerings that prioritize a healthy body & mind.
- Supportive Parenting Policies: Family‑first policies, including a generous global parental leave plan, designed to help you balance career and family life effectively.
- Dedication to Giving Back: Paid volunteer days and support for community engagement initiatives.
Fitch is committed to providing global securities markets with objective, timely, independent and forward‑looking credit opinions. To protect Fitch’s credibility and reputation, our employees must take every precaution to avoid conflicts of interests or any appearance of a conflict of interest. Should you, or your immediate family have any holdings that may conflict with your work responsibilities, you may be asked to divest yourself of them before beginning work. Fitch is proud to be an equal opportunity and affirmative action employer. We evaluate qualified applicants without regard to race, color, national origin, religion, sex, sexual orientation, gender identity, disability, protected veteran status, and other statuses protected by law.
Director, Vulnerability Management (Manchester) employer: Fitch Ratings
Contact Detail:
Fitch Ratings Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Director, Vulnerability Management (Manchester)
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their approach to vulnerability management and think about how your experience aligns with their needs. Tailor your responses to show you're the perfect fit!
✨Tip Number 3
Showcase your skills through real-world examples. When discussing your experience, highlight specific projects where you led vulnerability management initiatives. Use metrics to demonstrate your impact—numbers speak volumes!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in joining our team at Fitch. Let’s get you that interview!
We think you need these skills to ace Director, Vulnerability Management (Manchester)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Director of Vulnerability Management role. Highlight your experience in vulnerability management, risk prioritisation, and any innovative ideas you've implemented in previous roles. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for this role. Share specific examples of your leadership experience and how you've successfully managed vulnerabilities in the past. Remember, we love a good story!
Showcase Your Collaboration Skills: Collaboration is key in this role, so make sure to highlight your experience working with cross-functional teams. Whether it's engineering or application development, let us know how you've built strong partnerships to drive remediation efforts.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!
How to prepare for a job interview at Fitch Ratings
✨Know Your Vulnerability Management Inside Out
Before the interview, make sure you’re well-versed in the latest trends and tools in vulnerability management. Familiarise yourself with SAST, DAST, SCA, and CSPM solutions, as well as how they apply to multi-cloud environments. This will help you demonstrate your expertise and show that you can lead the team effectively.
✨Showcase Your Risk Mindset
Prepare to discuss how you approach risk prioritisation and remediation. Think of specific examples where you've successfully applied a risk-based assessment methodology. Highlight your ability to balance security needs with business objectives, as this is crucial for the role.
✨Collaboration is Key
Fitch Group values strong collaboration across teams. Be ready to share experiences where you’ve worked closely with engineering, application development, or infrastructure teams. Emphasise your communication skills and how you’ve facilitated aligned remediation workflows in past roles.
✨Metrics Matter
Since the role involves delivering real-time metrics reports, come prepared with examples of dashboards or reports you’ve created in previous positions. Discuss how you tracked performance indicators and used them to drive decision-making. This will show your analytical skills and your understanding of the importance of data in vulnerability management.