Threat & Vulnerability Lead | Hybrid IT & Intelligence in Newport

Threat & Vulnerability Lead | Hybrid IT & Intelligence in Newport

Newport Full-Time 47766 - 47766 £ / year (est.) No working from home possible
Intellectual Property Office UK

At a Glance

  • Tasks: Lead vulnerability management and enhance cyber defence capabilities in a dynamic team.
  • Company: Join the Intellectual Property Office, a key player in Cyber Operations.
  • Benefits: Competitive salary, generous leave, hybrid working, and unlimited learning access.
  • Other info: Great career progression opportunities and a collaborative team culture.
  • Why this job: Make a real impact on cybersecurity while developing your skills in a supportive environment.
  • Qualifications: Experience in vulnerability management and excellent communication skills required.

The predicted salary is between 47766 - 47766 £ per year.

This role is for an experienced professional in vulnerability management and threat intelligence to join our Cyber Operations team. You will work closely with colleagues across the organisation to further mature and continuously improve our cyber defence capabilities. Cyber Operations forms part of a wider, well established security function operating within a highly regulated environment.

In this role, you will lead and continuously enhance the management of vulnerability assessments across our hybrid IT estate. You will prioritise remediation activities using a risk based, threat informed approach, collaborating with stakeholders to strengthen the security posture of our systems and services.

You will also develop and mature our threat intelligence capability, identifying and maintaining relevant intelligence sources to inform tactical, operational, and strategic decision making. You will produce and share high quality threat intelligence products with internal and external stakeholders and use this intelligence to support vulnerability management and threat hunting activities.

Additionally, you will contribute to incident response processes and provide support to colleagues responsible for the IPO’s protection, detection, and response capabilities.

If you have strong relevant expertise, excellent communication skills and a collaborative working style we would love to hear from you.

Working Style

This role will be carried out in-line with IPO Hybrid working arrangements where staff are currently expected to spend at least 20% of their time working onsite from one of our offices. This role is based in our Newport Office. The requirement for attendance at an office location can vary by role so we would encourage candidates to discuss working arrangements with the recruiting manager to agree a reasonable balance between working from home and the office.

Main duties consist of but are not limited to:

  • Vulnerability Management (Primary Focus)
  • Lead and enhance the organisation’s vulnerability management programme, including our Penetration Testing programme across a complex hybrid IT environment covering both infrastructure and applications. This will include scoping, scanning, prioritising work, engaging with stakeholders, and ensuring remediation activities happen in a timely fashion.
  • Prioritise vulnerabilities using a risk‑based, threat‑informed approach to support organisational objectives, regulatory requirements, and audit needs.
  • Oversee the full lifecycle of vulnerabilities, including triage, mitigation planning, remediation recommendations, and stakeholder coordination.
  • Develop and maintain vulnerability management policies, procedures, standards, and best practice guidance.
  • Produce high quality tactical, operational, and strategic intelligence assessments and briefings using analysis and interpretation of current threat intelligence. Utilising and liaising with internal stakeholders, commercial sources, open-source intelligence and government partners to provide a rounded, comprehensive view of the current threat landscape.
  • Lead initiatives to strengthen the organisation’s intelligence capability and participate in information sharing communities.
  • Play an integral part in Cyber Security risk management, conducting risk and threat assessments aligned with regulations. Using your knowledge of standards and expertise to support our stakeholders by providing pragmatic and proportionate advice and best practice guidance.
  • Metrics & Reporting
  • Develop and maintain actionable metrics that demonstrate the effectiveness of the organisation’s vulnerability management and threat intelligence capabilities.
  • Contribute to and enhance our incident response processes, representing Cyber Security in operational incident calls, keeping stakeholders informed and liaising with government bodies to ensure timely and effective management of threat intelligence and threat hunting.

Person specification

  • Strong understanding and experience of vulnerability management, threat intelligence and security operations within a complex enterprise environment.
  • Experience of managing and developing penetration testing programs.
  • Knowledge of secure development practices and where security testing for vulnerabilities fits into the Software Development Lifecycle (SDLC).
  • Broad technical knowledge, especially around hybrid and cloud architectures, identity management and application security.
  • Highly organised and self-motivated, able to manage and deliver on multiple concurrent tasks.
  • Excellent communication and interpersonal skills. Ability to interact with stakeholders of all levels with the ability to explain complex security concepts to non-technical audiences.
  • A team player who is enthusiastic about contributing to the overall success of the team and collaborating with stakeholders of all levels.
  • Sense of urgency and an ability to respond to tasks proactively and promptly.
  • Continually stay abreast of emerging security technologies, threats and trends. Self-motivated to drive their learning needs.

Alongside your salary of £47,766, Intellectual Property Office contributes £13,837 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.

Unlimited Pluralsight video learning access.

Access to Microsoft’s ESI training suite.

Hybrid working with no core hours.

Substantial support for career progression.

25 days annual leave moving to 30 days in annual increments.

You will also get 8 days public leave and 1 day privilege leave.

Threat & Vulnerability Lead | Hybrid IT & Intelligence in Newport employer: Intellectual Property Office UK

The Intellectual Property Office (IPO) is an exceptional employer, offering a dynamic work environment in Newport where innovation meets collaboration. With a strong focus on employee growth, we provide unlimited access to learning resources, substantial support for career progression, and a generous leave policy, ensuring a healthy work-life balance. Our hybrid working model fosters flexibility while maintaining a commitment to enhancing our cyber defence capabilities, making it an ideal place for professionals seeking meaningful and rewarding employment in the field of cybersecurity.

Intellectual Property Office UK

Contact Details:

Intellectual Property Office UK Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Threat & Vulnerability Lead | Hybrid IT & Intelligence in Newport

Tip Number 1

Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online communities. The more people you know, the better your chances of landing that dream role.

Tip Number 2

Show off your skills! Create a portfolio or a personal website showcasing your projects, achievements, and any relevant certifications. This is a great way to demonstrate your expertise in vulnerability management and threat intelligence.

Tip Number 3

Prepare for interviews by brushing up on common questions related to cyber security. Practice explaining complex concepts in simple terms, as you'll need to communicate effectively with stakeholders at all levels.

Tip Number 4

Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining our team. Plus, it makes it easier for us to keep track of your application and get back to you quickly.

We think you need these skills to ace Threat & Vulnerability Lead | Hybrid IT & Intelligence in Newport

Vulnerability Management
Threat Intelligence
Penetration Testing
Risk Assessment
Stakeholder Engagement
Incident Response
Cyber Security Operations

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the role of Threat & Vulnerability Lead. Highlight your experience in vulnerability management and threat intelligence, and don’t forget to showcase your communication skills and collaborative approach!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re the perfect fit for our Cyber Operations team. Share specific examples of how you've enhanced security capabilities in previous roles.

Showcase Your Technical Skills:We want to see your technical prowess! Be sure to include any relevant certifications or experiences related to penetration testing, hybrid IT environments, and secure development practices in your application.

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity. We can’t wait to hear from you!

How to prepare for a job interview at Intellectual Property Office UK

Know Your Vulnerability Management Inside Out

Make sure you brush up on your knowledge of vulnerability management and threat intelligence. Be ready to discuss specific methodologies you've used in the past, especially in hybrid IT environments. This will show that you not only understand the theory but also have practical experience.

Prepare for Scenario-Based Questions

Expect questions that ask you to solve hypothetical situations related to vulnerability assessments or incident responses. Practise articulating your thought process clearly, as this will demonstrate your analytical skills and ability to collaborate with stakeholders effectively.

Showcase Your Communication Skills

Since the role requires explaining complex security concepts to non-technical audiences, prepare examples of how you've successfully communicated technical information in the past. This could be through presentations, reports, or team meetings.

Stay Updated on Emerging Threats

Familiarise yourself with the latest trends in cybersecurity and emerging threats. Being able to discuss current events or recent vulnerabilities will not only impress your interviewers but also show your commitment to staying informed in a rapidly evolving field.