Vulnerability Management Analyst – Qualys VM

Vulnerability Management Analyst – Qualys VM

Full-Time 72000 - 88000 £ / year (est.) No working from home possible
P

At a Glance

  • Tasks: Lead vulnerability management operations and transformation activities using Qualys VM.
  • Company: Join a fast-growing recruitment consulting firm with a global presence.
  • Benefits: Competitive salary, career growth opportunities, and a dynamic work environment.
  • Other info: Ideal for those who thrive in execution-heavy roles and enjoy operational challenges.
  • Why this job: Make a real impact in cybersecurity by managing vulnerabilities in large enterprise environments.
  • Qualifications: 6-8 years of hands-on experience in vulnerability management and strong knowledge of Qualys VM.

The predicted salary is between 72000 - 88000 £ per year.

Experience: 6-8 years (pure hands-on Vulnerability Management experience mandatory)

Role Summary: We are looking for a hands-on Vulnerability Management professional with strong operational experience on Qualys VM / VMDR to support BAU vulnerability operations and lead transformation activities for large enterprise environments. The role is execution-heavy and requires day-to-day ownership of scanning, validation, remediation tracking, reporting, and stakeholder coordination, rather than advisory or governance only work.

Key Responsibilities

  • Transformation: Lead and strategise transformation activity end to end as lead. Hands-on experience on multiple VMS tools. Actively performed transformation activity in previous work role.
  • Qualys VM Operations: Perform authenticated and unauthenticated vulnerability scans using Qualys VM / VMDR across:
    • Servers (Windows & Linux)
    • Network devices
    • Endpoints
    • Cloud workloads (AWS / Azure)
  • Manage asset discovery, tagging, and grouping within Qualys.
  • Configure and maintain scan profiles, schedules, and exclusions based on environment and risk.
  • Troubleshoot scan failures, authentication issues, and agent-related problems.
  • Vulnerability Analysis & Validation: Analyze Qualys scan results and:
    • Validate true positives
    • Identify and eliminate false positives
  • Apply risk-based prioritisation using CVSS, exploitability, asset criticality, and threat context.
  • Track zero-day and high-severity vulnerabilities and support expedited remediation.
  • Remediation & Stakeholder Coordination: Create, track, and manage remediation tickets using ServiceNow / Jira or equivalent ITSM tools.
  • Work closely with:
    • Infrastructure teams
    • Application owners
    • Cloud and platform teams
  • Follow up on remediation SLAs and perform re-scans to confirm closure.
  • Reporting & BAU Governance: Prepare and publish:
    • Weekly / Monthly vulnerability reports
    • Executive summaries and dashboards
  • Support compliance and audit requirements (ISO 27001, CIS benchmarks, etc.).
  • Maintain SOPs, runbooks, and BAU documentation.
  • Tooling & Automation (Good to Have): Support Qualys API integrations with ServiceNow, SIEM, or reporting tools.
  • Basic scripting exposure (Python / PowerShell / Bash) for automation and data handling.

Mandatory Skills & Experience

  • Core Technical Skills: Strong hands-on experience with Qualys VM / Qualys VMDR (mandatory). Solid understanding of the vulnerability lifecycle (identify, assess, remediate, validate), CVE, CVSS, exploitability, patching concepts.
  • Experience with Windows & Linux OS, networking fundamentals (TCP/IP, ports, firewalls).
  • Exposure to cloud vulnerability scanning (AWS / Azure) is highly desirable.
  • Tools & Platforms: Qualys VM / VMDR, ITSM tools: ServiceNow / Jira, supporting tools: Nessus / Rapid7 (good to have, not mandatory), reporting tools: Excel / Power BI (basic to intermediate).
  • Soft Skills (Important for BAU Success): Strong operational ownership mindset, ability to manage multiple remediation streams in parallel, clear communication with technical and non-technical stakeholders, comfortable handling escalations and SLA-driven delivery, good documentation and reporting discipline.

Preferred / Nice to Have:

  • Experience in managed security services.
  • Exposure to policy compliance scanning, cloud posture/infrastructure security.
  • Certifications (preferred, not mandatory): Qualys certification, CEH / Security+ / ISO 27001 awareness.

Role Type: Hands-on BAU / Run Operations/Transformation. Not a consulting-only or GRC-only role. Ideal for candidates who enjoy day-to-day vulnerability operations and execution and lead transformation projects.

Vulnerability Management Analyst – Qualys VM employer: Pracyva ltd

Pracyva Ltd is an exceptional employer that fosters a culture of innovation and collaboration, making it an ideal place for a Lead Java Developer. With a focus on mentorship and professional growth, employees are encouraged to explore cutting-edge technologies like AI and cloud solutions, all while working in a supportive environment that values quality and efficiency. Located in a vibrant tech hub, the company offers unique opportunities to engage with industry leaders and contribute to impactful projects.

P

Contact Details:

Pracyva ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Vulnerability Management Analyst – Qualys VM

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Pracyva ltd, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Pracyva ltd

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Pracyva ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Vulnerability Management Analyst – Qualys VM

Vulnerability Management
Qualys VM
Qualys VMDR
Vulnerability Analysis
Remediation Tracking
ServiceNow
Jira

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Pracyva ltd insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Pracyva ltd that you’re committed to staying ahead in the game.

How to prepare for a job interview at Pracyva ltd

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Pracyva ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Pracyva ltd.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.