At a Glance
- Tasks: Lead hands-on vulnerability assessments and drive remediation efforts across teams.
- Company: Join a leading firm committed to security excellence and innovation.
- Benefits: Competitive salary, bonus potential, and opportunities for professional growth.
- Other info: Dynamic work environment with a focus on collaboration and continuous improvement.
- Why this job: Make a real impact in cybersecurity while mentoring the next generation of security professionals.
- Qualifications: 7-10+ years in information security with strong vulnerability management experience.
The predicted salary is between 120000 - 140000 £ per year.
Responsibilities
- Vulnerability Management (Hands‑On Execution) – Conduct regular vulnerability assessments of all systems, applications, and infrastructure. Execute vulnerability scans using tools such as Nessus, Qualys, or Rapid7, perform or coordinate penetration testing and security assessments. Analyze vulnerability data and issue actionable remediation, mitigation, or risk‑acceptance recommendations calibrated to the firm’s risk profile. Drive remediation directly with engineering, infrastructure, and application teams, tracking findings from discovery through to validated closure. Validate all remediations to confirm findings are fully resolved. Develop and maintain meaningful vulnerability metrics and dashboards for senior leadership, incorporating risk‑based scoring, SLA adherence, and trend analysis. Work with cross‑functional teams to embed vulnerability management considerations into the design, development, and testing of new systems and applications. Coordinate with external vendors and partners to optimize detection quality, validate findings, and improve remediation workflows.
- Program Management & Governance – Develop and maintain security policies, procedures, and standards aligned to industry best practices (NIST, CIS, ISO) and PJT policy requirements. Support audit evidence collection and manage remediation timelines for compliance‑related findings. Communicate security risks and program status to management and stakeholders; provide clear, prioritized recommendations. Understand and effectively balance risk versus business operability in all remediation decisions. Provide leadership and mentorship to junior security team members; manage and direct external teams as needed.
- Engineering Support – Maintain the vulnerability management platform infrastructure, including scanner and agent configuration, and integration with downstream ticketing and reporting systems. In support of the overall PJT security program, assist with project work on security infrastructure, including SIEM, EDR, and related tooling – contributing engineering effort as priorities require.
- Incident Response – Serve as a critical incident response resource, providing coverage during hours when the primary SOC team may not be available. Triaging and responding to critical‑severity incidents, escalating appropriately, and ensuring continuity of response without gaps.
Qualifications
- Education & Experience: Bachelor’s degree in Computer Science, Information Security, or a related field. 7–10+ years of experience in information security with a strong focus on vulnerability management, secure design review, patch operations, and incident response. Demonstrated experience running a hands‑on vulnerability management program – not solely in an oversight or program management capacity. Experience providing incident response coverage, including participation in on‑call rotations or extended‑hours response.
- Technical Skills: Proficiency with vulnerability management platforms such as Nessus, Qualys, or Rapid7; ability to operate these tools directly. Knowledge of cloud security posture management (CSPM) platforms such as Wiz or Microsoft Defender for Cloud, and exposure management workflows. Strong technical skills in vulnerability scanning, patch management, and network security protocols. Working knowledge of operating systems (Windows, Linux) and web application security. Familiarity with SIEM tools for alert triage and incident investigation. Scripting and automation skills in PowerShell or Python; experience with workflow tools such as ServiceNow or JIRA. Working knowledge of security frameworks including NIST CSF, CIS Controls, and ISO 27001. Understanding of incident response frameworks (e.g., NIST SP 800‑61, PICERL) and how vulnerability management integrates into the IR lifecycle.
- Soft Skills & Availability: Excellent communication and interpersonal skills; able to convey complex security issues to both technical and non‑technical audiences. Strong leadership and mentorship abilities; demonstrated experience managing cross‑functional teams and external consultants. Ability to work independently, manage competing priorities, and adapt to rapidly shifting demands. Willingness and ability to provide extended‑hours incident response coverage as required by the role, including off‑hours and weekend on‑call responsibilities.
Compensation: Expected annualized base salary of $150,000 – $175,000, with a discretionary bonus component. Base salary is one component of the PJT Partners compensation structure.
Equal Opportunity Employer: PJT is an equal opportunity employer. We do not discriminate on the basis of race, color, religious creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expression, disability, medical condition, genetic information or predisposition, veteran or military status, status as a victim of domestic violence, a sex offense or stalking, or any other category protected by law. PJT Partners complies with all applicable laws with regard to providing reasonable accommodation of disabilities to applicants. Please contact Human Resources for more information or to request an accommodation.
Vulnerability Management and Security Engineering Vice President employer: PJT Partners Inc.
PJT Partners is an exceptional employer that fosters a dynamic work culture focused on innovation and collaboration, particularly in the field of vulnerability management and security engineering. Employees benefit from comprehensive professional development opportunities, competitive compensation packages, and a commitment to diversity and inclusion, all while working in a vibrant location that encourages both personal and professional growth.
StudySmarter Expert Advice🤫
We think this is how you could land Vulnerability Management and Security Engineering Vice President
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! If you've got experience with tools like Nessus or Qualys, make sure to highlight that in conversations. Consider doing a demo or sharing a project you've worked on to really impress potential employers.
✨Tip Number 3
Prepare for interviews by brushing up on your incident response knowledge. Be ready to discuss how you've handled critical incidents in the past and what strategies you used to mitigate risks. This will show you're not just book-smart but also hands-on.
✨Tip Number 4
Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining us at StudySmarter. Tailor your application to reflect our values and the specific role, and you'll stand out from the crowd.
We think you need these skills to ace Vulnerability Management and Security Engineering Vice President
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to highlight your experience in vulnerability management and security engineering. Use keywords from the job description to show we’re on the same page about what you bring to the table.
Showcase Your Skills:Don’t just list your skills; demonstrate them! Include specific examples of how you've used tools like Nessus or Qualys in your previous roles. We want to see your hands-on experience shine through.
Craft a Compelling Cover Letter:Your cover letter is your chance to tell us why you’re the perfect fit for this role. Share your passion for security, your approach to vulnerability management, and how you can contribute to our team’s success.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!
How to prepare for a job interview at PJT Partners Inc.
✨Know Your Tools Inside Out
Make sure you’re well-versed in the vulnerability management platforms mentioned in the job description, like Nessus, Qualys, or Rapid7. Be ready to discuss your hands-on experience with these tools and how you've used them to conduct assessments and drive remediation efforts.
✨Showcase Your Leadership Skills
As a Vice President, you'll need to demonstrate strong leadership and mentorship abilities. Prepare examples of how you've led teams, managed cross-functional projects, and communicated complex security issues to both technical and non-technical audiences.
✨Understand Risk Management
Be prepared to discuss how you balance risk versus business operability in your decision-making. Think of specific instances where you’ve had to make tough calls on remediation strategies and how you communicated those decisions to stakeholders.
✨Prepare for Incident Response Scenarios
Since the role involves incident response, brush up on your knowledge of incident response frameworks and be ready to talk about your experience in triaging critical incidents. Consider discussing any on-call experiences and how you ensured continuity of response during high-pressure situations.