Senior Vulnerability Management Engineer

Senior Vulnerability Management Engineer

Full-Time 60750 - 74250 £ / year (est.) Home office (partial)
HCLTech

At a Glance

  • Tasks: Lead the vulnerability management programme and drive continuous improvement across technology domains.
  • Company: Join a $13+ billion global tech leader with a startup mindset.
  • Benefits: Enjoy hybrid work, competitive salary, and opportunities for professional growth.
  • Other info: Dynamic environment with excellent career growth opportunities and mentorship.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: 3-6 years in vulnerability management and a degree in Computer Science or Cybersecurity.

The predicted salary is between 60750 - 74250 £ per year.

We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products. HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here.

The L2 Senior Vulnerability Management Engineer owns the organisation's end-to-end vulnerability management programme, spanning EUC, Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement of the VM programme.

KEY RESPONSIBILITIES

  • Own and operate the enterprise vulnerability management programme across all technology domains (endpoints, servers, network devices, web applications, cloud).
  • Design and maintain scan policies, asset groups, and scanning schedules in Qualys VMDR / Tenable Security Centre / Rapid7 InsightVM to ensure full coverage.
  • Perform risk-based vulnerability prioritisation: correlate CVSS scores with asset criticality, exposure, threat intelligence (EPSS, CISA KEV), and business context.
  • Translate vulnerability findings into actionable remediation tasks for patch management teams across EUC, Data Center, Networks, and Application Infra; define acceptance criteria for closure.
  • Define, publish, and enforce the VM SLA policy; escalate breaches to asset owners and management.
  • Lead the vulnerability exception and risk acceptance process: assess compensating controls, document residual risk, and obtain formal sign-off.
  • Integrate VM tooling with SIEM (Splunk, Microsoft Sentinel), ITSM (ServiceNow VR module), and CMDB for automated ticket creation and asset correlation.
  • Automate vulnerability reporting and remediation tracking using Python, REST APIs (Qualys/Tenable API), or ServiceNow workflows.
  • Conduct threat-informed vulnerability analysis: monitor NVD, CISA KEV, vendor security advisories, and threat intelligence feeds to identify exploitable CVEs requiring emergency response.
  • Lead response to zero-day vulnerabilities: assess impact across the estate, co-ordinate emergency patching or compensating controls, and communicate status to security leadership.
  • Own web application vulnerability management: integrate DAST/SAST findings (Burp Suite, Checkmarx, Veracode) into the unified VM programme.
  • Manage cloud vulnerability posture: AWS Inspector, Microsoft Defender for Cloud, or Prisma Cloud for hybrid cloud environments.
  • Produce monthly VM programme dashboards, KPIs, and trend analysis for CISO and management review.
  • Act as L2 escalation for L1 analysts; mentor team members and review scan configurations and reports.
  • Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence.

TECHNICAL SKILLS

  • ServiceNow VR module configuration.
  • SIEM integration: Splunk, Microsoft Sentinel – correlating vulnerability data with threat events.
  • CMDB-driven asset correlation: ServiceNow CMDB, ensuring VM data reflects accurate asset inventory.
  • Network and infrastructure knowledge sufficient to assess vulnerability exploitability (firewall rules, segmentation, exposure).
  • Patch management workflow knowledge across Windows (SCCM/Intune), Linux (Satellite/Ansible), and network devices – to drive effective remediation co-ordination.
  • Threat intelligence: experience consuming TI feeds (MISP, OpenCTI, commercial TI platforms) to contextualise vulnerabilities.
  • Familiarity with compliance frameworks: ISO 27001, NIST CSF, CIS Controls, PCI DSS, SOC 2 – as they relate to vulnerability management.

PREFERRED CERTIFICATIONS

  • Qualys Certified Specialist – VMDR / TruRisk
  • Tenable Certified Security Engineer (TCSE)
  • Certified Information Systems Security Professional (CISSP) – or working towards
  • Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP)
  • CompTIA CySA+ or PenTest+
  • GIAC Vulnerability Assessor (GEVA)
  • Microsoft Certified: Security Operations Analyst (SC-200) – advantageous for Azure environments
  • ITIL 4 Foundation or Managing Professional

Senior Vulnerability Management Engineer employer: HCLTech

HCLTech is an excellent employer for those looking to advance their careers in cloud and infrastructure migration. With a strong focus on professional development, employees benefit from competitive compensation and a collaborative work culture that encourages innovation and growth. Located in a dynamic environment, HCLTech offers unique opportunities to work on cutting-edge technology projects while ensuring a supportive atmosphere for personal and professional advancement.

HCLTech

Contact Details:

HCLTech Recruitment Team

We think you need these skills to ace Senior Vulnerability Management Engineer

Vulnerability Management
Information Security
Qualys VMDR
Tenable Security Centre
Rapid7 InsightVM
Risk-Based Prioritisation
Automation of Workflows