At a Glance
- Tasks: Conduct vulnerability assessments and collaborate with teams to remediate risks.
- Company: Join a leading retailer in their Global Threat & Vulnerability function.
- Benefits: Gain hands-on experience, competitive salary, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on innovation and collaboration.
- Why this job: Make a real impact by closing the loop on cyber vulnerabilities.
- Qualifications: 1-2 years in vulnerability management and knowledge of cloud environments.
The predicted salary is between 36000 - 60000 £ per year.
We’re supporting a household-name retailer to hire a hands-on Cyber Vulnerability Analyst into their Global Threat & Vulnerability function. You’ll run scanning across cloud, networks and apps, turn findings into risk-based actions, and partner with SOC, AppSec, Networks and Cloud to land fixes fast. If you enjoy closing the loop—from discovery to remediation—and automating the boring bits, you’ll love this.
Responsibilities
- Conduct comprehensive vulnerability assessments on systems, networks, and applications.
- Analyse and interpret vulnerability scan results, prioritise findings using risk-based prioritisation methodology, and provide actionable recommendations for remediation.
- Evaluate and manage vulnerabilities, including prioritisation, investigation, and tracking remediation activities.
- Evaluate new tools and techniques in security testing and articulate their value and impact.
- Operate vulnerability and configuration scanning tools, like Tenable, Qualys, InsightVM.
- Perform technical and non-technical risk and vulnerability assessments of relevant technology focus areas.
- Define, create and implement various SOPs (Standard Operating Procedures) and SOMs (Service Operating Models).
- Use asset risk profiles, vulnerability severity ratings, and threat information to communicate remediation priorities.
- Support incident response in investigations and response at all stages.
- Assist and work closely with our offensive security team, SOC team, Network Team, AppSec team.
- Generate and distribute operational-level reports and key vulnerability reporting metrics along with KPIs, KRIs and monthly/weekly reporting.
- Maintain communication with the Vulnerability Management Lead and other internal & external stakeholders for collaboration and information sharing.
- Maintain knowledge of applicable policies, regulations, and compliance documents.
- Engage in team working and demonstrate a professional, motivated attitude.
- Collaborate with the security compliance team to meet compliance and regulation requirements.
- Leverage threat intelligence sources to inform on exposure to vulnerabilities.
- Assist in automated or manual patching remediation processes.
Essential
- 1-2 years experience in vulnerability management role or equivalent.
- Hands-on experience with vulnerability assessments, management, and remediation strategies.
- Project management skills to help deliver vulnerability programs.
- Understanding of cloud environments (AWS, Azure, GCP) and their unique vulnerabilities.
- Detailed understanding of Windows, Linux/Unix, and other OS vulnerabilities.
- Ability to perform risk analysis and prioritise vulnerabilities based on severity and impact.
- Aptitude for analysing complex technical information and cyber threats.
- Security Framework Knowledge: Familiarity with common security frameworks like CIS, NIST.
Vulnerability Management Analyst employer: InfoSec People Ltd
Contact Detail:
InfoSec People Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Vulnerability Management Analyst
✨Tip Number 1
Network, network, network! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just chat with people on LinkedIn. You never know who might have a lead on that perfect Vulnerability Management Analyst role.
✨Tip Number 2
Show off your skills! Create a portfolio or a personal project that highlights your vulnerability management expertise. Whether it’s a blog post about a recent tool you’ve used or a case study of a vulnerability you tackled, let your work speak for itself.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each job. Research the company and mention how your experience aligns with their specific needs, especially in areas like cloud environments or risk analysis. We want to see that you’re genuinely interested!
✨Tip Number 4
Finally, don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step to engage with us directly.
We think you need these skills to ace Vulnerability Management Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Vulnerability Management Analyst role. Highlight your experience with vulnerability assessments and any tools you've used, like Tenable or Qualys. We want to see how your skills match what we're looking for!
Showcase Your Experience: In your cover letter, don’t just list your past jobs—tell us about specific projects where you’ve conducted vulnerability assessments or collaborated with teams. We love hearing about real-life examples that demonstrate your hands-on experience.
Be Clear and Concise: When writing your application, keep it clear and to the point. Use bullet points for key achievements and avoid jargon unless it's relevant. We appreciate straightforward communication that gets right to the heart of your qualifications.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to track your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at InfoSec People Ltd
✨Know Your Tools
Familiarise yourself with the vulnerability scanning tools mentioned in the job description, like Tenable and Qualys. Be ready to discuss your hands-on experience with these tools and how you've used them to conduct assessments and manage vulnerabilities.
✨Understand Risk Prioritisation
Brush up on risk-based prioritisation methodologies. Be prepared to explain how you would analyse and interpret scan results, and how you would prioritise findings based on their severity and potential impact on the organisation.
✨Showcase Collaboration Skills
This role involves working closely with various teams like SOC, AppSec, and Networks. Think of examples from your past experiences where you successfully collaborated with different teams to achieve a common goal, especially in vulnerability management.
✨Stay Updated on Security Frameworks
Make sure you're familiar with security frameworks like CIS and NIST. During the interview, demonstrate your understanding of how these frameworks apply to vulnerability management and compliance, and be ready to discuss any relevant experiences.