At a Glance
- Tasks: Lead the Threat & Vulnerability Management strategy and operations across cloud and on-prem environments.
- Company: Join PXC, the UK's largest wholesale connectivity provider with a focus on innovation.
- Benefits: Enjoy flexible working, competitive salary, private healthcare, and extra holiday leave.
- Why this job: Make a real impact in security while working with cutting-edge technology and a dynamic team.
- Qualifications: Experience in managing enterprise TVM programmes and understanding of security standards.
- Other info: Be part of a diverse culture that values inclusion and personal growth.
The predicted salary is between 48000 - 84000 £ per year.
We are PXC, the UK’s largest provider of wholesale connectivity. Our vision is to be the UK’s #1 wholesale platform, a one‑stop shop provider of connectivity, voice, cloud and security underpinned by the UK’s most robust, secure, resilient and reliable network. Born from the combination of Virtual1 and TalkTalk’s wholesale services and national network business, we operate across our three core sites (Salford, London and Skopje, North Macedonia). Our mission is clear: to be the UK’s best company to work for and best to work with. We believe this success is driven by the power of our employees. We empower our people to become true experts in their field who embody our values every day: we care; we challenge; we commit.
You will be part of an efficacious Security Risk Management team that exists in a strong and mature Security function within PXC’s Technology and Security Business Unit. Reporting directly into the Head of Security Risk Management, you will be responsible for vulnerability management of PXC and our partners’ application, on‑prem and cloud infrastructure.
You will lead the enterprise Threat & Vulnerability Management (TVM) function strategy, operations, and governance across on‑prem and cloud environments. You will own the end‑to‑end cycle (identify – assess – remediate – verify – report), drive timely risk reduction with technology teams, and ensure adherence to our security standards and regulatory obligations (ISO/IEC 27001:2022, PCI DSS, Cyber Essentials, TSA).
Key Responsibilities
- Define and evolve the TVM strategy, roadmap, and operating model covering infrastructure, applications, endpoints, and cloud services; embed policy/standard requirements into day‑to‑day engineering practice.
- Chair / contribute to the Vulnerability Management Steering Committee and related governance forums; drive decisions, unblock remediation and agree risk treatments or exceptions.
- Maintain and enforce the Vulnerability Management Security Standard and related procedures, ensuring clarity of roles (Asset Owners, TVM team, Security Risk Managers) and handoffs to Patch, Change, and Incident functions.
- Oversee asset‑appropriate discovery and scanning schedules (cloud, container, server, network, endpoint, web/app) and verify coverage and scan health.
- Lead triage and risk assessment using business context, exploitability and threat intelligence to prioritise remediation.
- Orchestrate remediation with platform and application owners.
- Drive Patch Management integration (assessment deployment validation), ensuring platform teams meet timelines per severity and service criticality.
- Ensure compliance with control objectives mapped in our standard (e.g., ISO/IEC 27001:2022, PCI DSS, TSA, Cyber Essentials).
- Prepare evidence for audits, customer assurance and regulatory inquiries; produce management reports for senior stakeholders demonstrating posture and risk trending.
- Own the TVM tooling estate and integrations (ITSM, CMDB, CI/CD, cloud security, dashboards); champion automation for noise reduction, dedupe and exception governance.
What Will Make You Successful In This Role
Essential
- Demonstrable leadership of an enterprise TVM programme across hybrid (on‑prem & cloud) estates, partnering cross‑functionally to land remediation at scale.
- Deep understanding of vulnerability lifecycle, risk assessment, exploitability, patch orchestration and asset lifecycle management.
- Strong grasp of relevant standards/regulations (ISO/IEC 27001:2022, PCI DSS, Cyber Essentials, TSA) and how to evidence compliance.
- Expertise in stakeholder management, influencing and conflict resolution at senior levels.
- Ability to design metrics and executive‑ready reporting; comfortable presenting at SteerCos and risk forums.
Desirable
- Experience integrating TVM into DevOps/CI‑CD and cloud‑native platforms.
- Familiarity with risk methodologies and governance tooling (e.g., ITSM, CMDB, GRC).
- Relevant certifications (e.g., CISSP, CISM, GIAC, AZ‑500, CSSLP).
How we look after our employees
Our brand new PXC Flex benefit launched in January 2025, which includes Flex30, an additional 30 hours of leave every year for you to use how you wish. Our hybrid working policy offers you flexibility to work from home as well as connect with your colleagues in one of our accessible and collaborative office spaces. A starting holiday allowance of 25 days holiday and up to 10 extra days leave via our holiday purchase scheme. Free private healthcare for all employees, competitive pension scheme and the opportunity to earn bonus. Free broadband for all employees plus gifts for major life events such as marriages and births. Flexible salary sacrifice scheme including dental, gym plus a huge range of shopping and leisure discounts so you can save even more cash. A range of inclusive employee networks to help integrate employees into life at PXC.
At PXC, we know that diversity means success and innovation. We want our workplace to reflect the communities and customers we serve. Being inclusive is part of our DNA; we are all 100% human, and we create a culture where you can truly be yourself. We’re also not your usual 9‑5. We are a dynamic workplace and we want to talk to you about how you like to work.
Threat and Vulnerability Manager in Salford employer: PXC
Contact Detail:
PXC Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Threat and Vulnerability Manager in Salford
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with PXC employees on LinkedIn. Building relationships can open doors that a CV just can't.
✨Tip Number 2
Prepare for interviews by diving deep into PXC's mission and values. Show us how you embody 'we care; we challenge; we commit' in your past experiences. Tailor your stories to resonate with our culture!
✨Tip Number 3
Practice makes perfect! Mock interviews with friends or mentors can help you articulate your thoughts clearly. Focus on your leadership experience in TVM and how you've tackled challenges in the past.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you're genuinely interested in being part of the PXC family.
We think you need these skills to ace Threat and Vulnerability Manager in Salford
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Threat and Vulnerability Manager role. Highlight your experience with vulnerability management, risk assessment, and any relevant certifications. We want to see how your skills align with our mission at PXC!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security and how you can contribute to our team. Don’t forget to mention your understanding of standards like ISO/IEC 27001:2022 and PCI DSS.
Showcase Your Leadership Skills: Since this role involves leading the TVM programme, be sure to highlight your leadership experience. Share examples of how you've successfully managed teams or projects in the past, especially in hybrid environments.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s the easiest way for us to keep track of your application and ensure it reaches the right people. We can’t wait to hear from you!
How to prepare for a job interview at PXC
✨Know Your Stuff
Make sure you have a solid understanding of the vulnerability lifecycle and risk assessment processes. Brush up on relevant standards like ISO/IEC 27001:2022 and PCI DSS, as these will likely come up in conversation. Being able to discuss how you've applied these in past roles will show you're the right fit.
✨Showcase Your Leadership Skills
Since this role involves leading the Threat & Vulnerability Management programme, be prepared to share examples of how you've successfully led similar initiatives. Talk about your experience in managing cross-functional teams and how you’ve driven remediation at scale.
✨Prepare for Stakeholder Engagement
This position requires strong stakeholder management skills. Think of instances where you've influenced senior stakeholders or resolved conflicts. Be ready to discuss your approach to building relationships and how you communicate complex security concepts to non-technical audiences.
✨Metrics Matter
Demonstrate your ability to design metrics and create executive-ready reports. Bring examples of how you've tracked and reported on security posture and risk trends in previous roles. This will show that you can provide valuable insights to senior management and contribute to strategic decision-making.