At a Glance
- Tasks: Lead a global team in identifying and mitigating security vulnerabilities.
- Company: Join ION, a dynamic leader in financial technology with a diverse workforce.
- Benefits: Enjoy competitive salary, inclusive culture, and opportunities for professional growth.
- Why this job: Make a real impact on global security while working with cutting-edge technology.
- Qualifications: 10+ years in cybersecurity, with strong leadership and vulnerability management experience.
- Other info: Be part of a supportive environment that values diverse backgrounds and perspectives.
The predicted salary is between 54000 - 84000 £ per year.
The Vulnerability Management Manager is a global role within ION's central services division and will support the Group Security strategy and operational excellence through the identification, mitigation and remediation of information security vulnerabilities, misconfigurations and risks to the business. This role reports to the Global Head of IT Security, who reports to the Group Chief Information Security Officer (CISO).
Responsibilities
- This role may require work-out of hours in support of 24x7 globally coordinated operation.
- Personnel Management
- Ensure team members have clear objectives/development plans.
- Align Teams' objectives to OKRs.
- Be the escalation point for security Tooling issues and critical security breaches.
- Responsible for team development, upskilling & mentoring.
- Manage Vulnerability Management tooling to ensure coverage/availability/efficacy.
- Drive improvements and feature enhancement to ensure ROI.
- Configure, tune, maintain & operate key vulnerability management controls.
- Management reporting - real-time metrics and scheduled reports.
- Drive process/procedure changes accordingly.
- Ensure quality of ticketing & runbook maintenance.
- Cultivate and maintain strong vendor relationships.
- Have an attitude of continuous improvement.
Further Information
As a member of the ION Security team, you will build and lead a team of Security professionals specialising in Vulnerability Management along with managing the partners and technology vendor deliverables and of course building and owning the strategy to deliver a world class Vulnerability Management program. The candidate must understand their role in the broader vulnerability management program and your team will regularly perform discovery scanning, risk/exposure assessments, mitigation support activities, continuous validation assessments, and lessons learned workshops and improvement projects to continuously improve our process across Group Security and all other Verticals.
We are looking for a diligent, dedicated, creative and motivated individual. Excellent communication skills are a must, and the role holder will be expected to cultivate working relationships with other teams and colleagues of varying technical ability. The role would suit a technically strong candidate with an extensive cybersecurity background, at least 10+ years working in a security role, with focus on Vulnerability Management.
Qualifications
- Degree/diploma/certifications in a technology-related field and/or relevant working experience; highly desired certifications include: Security+, CCSP, CEH, GCIH, GMON, CASP, or CISSP.
- 10 years' experience in Vulnerability Management within large organizations with at least 5 years in a senior leadership role.
- Excellent track record of building and leading a Vulnerability Management program on a global scale with knowledge on vulnerability assessments, remediation and mitigation activities.
- Technical Security/Engineering/Compliance background with a track record of building and running global teams.
- Previous track record of building risk management framework and applying to an existing vulnerability management program.
- Strong technical expertise in implementing a Prioritization formula to vulnerabilities and misconfigurations and translating these into risks.
- Excellent knowledge of Vulnerability Management frameworks such as NIST/SANS.
General Characteristics
- A team player with the ability to work independently and unsupervised.
- Ability to own delegated tasks and see them through to completion.
- Ability to manage time and prioritize work to maximize productivity.
- Excellent reporting and presentation skills are essential for this role.
- Excellent communication skills (both written and verbal).
- Exceptional attention to detail and quality.
- Excellent problem-solving techniques and trouble analysis skills.
- Experience in design and publishing Security Standards & Policies.
- Experienced in leading Purple Teaming.
- Experienced in running global Bug Bounty/VDP programs.
- Experienced in leading Pen Testing, from scope, schedule, findings, remediation and risk registration and running the Pen Test program for Group Security as well as all other Verticals.
Knowledge Requirements
- Vulnerability Management concepts, controls, and best practices for all Operating systems & asset types, (e.g. workstations, endpoints, mobile, servers either Windows/Linux, cloud instances, etc.).
- Vulnerability Management tools (Tenable/Rapid7/Qualys).
- Cloud Security compliance (IaaS, PaaS, SaaS) and misconfigurations.
- Multi-platform endpoints, infrastructure and XaaS vulnerability management deployments.
- General IT networking concepts, protocols, standards and network security concepts, controls, and best practices.
- Forensic investigation techniques.
- Prior experience deploying, configuring, managing, and/or operating security technologies is preferred, such as endpoint security (e.g. AV/EPP/EDR), SIEM, DLP, SWG, CASB, UEBA, IDS, IPS, firewalls, IAM/PIM/PAM, Vulnerability Management, MDM, etc.
Excellent track record of Senior Leadership and Board level interaction, reporting and communications. Experience in InfoSec program management, project support and large-scale change. Proven knowledge of compliance, regulatory practices and experience managing audits.
ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business. ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.
Vulnerability Management Manager in City of Westminster employer: Openlink
Contact Detail:
Openlink Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Vulnerability Management Manager in City of Westminster
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cybersecurity field. Attend meetups, webinars, or even online forums. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or a personal website where you can showcase your projects, certifications, and any relevant experience. This is a great way to stand out and give potential employers a taste of what you can bring to the table.
✨Tip Number 3
Prepare for interviews by researching the company and its security practices. Be ready to discuss how your experience aligns with their needs, especially in vulnerability management. Tailor your answers to show you understand their challenges and how you can help.
✨Tip Number 4
Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you. Plus, it’s a great way to ensure your application gets seen by the right people. So, get clicking and let’s get you that job!
We think you need these skills to ace Vulnerability Management Manager in City of Westminster
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Vulnerability Management Manager role. Highlight your experience in vulnerability management, team leadership, and any relevant certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a perfect fit for our team. Don’t forget to mention specific achievements that demonstrate your expertise.
Showcase Your Communication Skills: Since excellent communication is key for this role, make sure your application reflects that. Use clear, concise language and structure your documents well. We want to see that you can convey complex information effectively!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!
How to prepare for a job interview at Openlink
✨Know Your Vulnerability Management Tools
Familiarise yourself with the specific vulnerability management tools mentioned in the job description, like Tenable, Rapid7, or Qualys. Be ready to discuss your experience with these tools and how you've used them to identify and mitigate vulnerabilities in past roles.
✨Showcase Your Leadership Skills
As this role involves personnel management and team development, prepare examples of how you've successfully led teams in the past. Highlight your experience in mentoring and upskilling team members, and be ready to discuss how you align team objectives with broader company goals.
✨Stay Current with Security Trends
Make sure you're up-to-date with the latest security news, threats, and vulnerabilities. Bring insights from recent incidents or trends to the interview, demonstrating your proactive approach to staying informed and your ability to apply this knowledge in a practical context.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills and technical expertise. Think through potential security incidents and how you would handle them, including isolation, containment, and remediation strategies. This will show your analytical thinking and readiness for real-world challenges.