Vulnerability Management Specialist - Quilter in Southampton

Vulnerability Management Specialist - Quilter in Southampton

Southampton Full-Time 50000 - 60000 £ / year (est.) No working from home possible
Quilter

At a Glance

  • Tasks: Drive a risk-based vulnerability management programme and enhance cloud security posture.
  • Company: Join Quilter, a leading UK wealth management provider with a commitment to innovation.
  • Benefits: Enjoy competitive salary, flexible benefits, and a supportive work environment.
  • Other info: Be part of a diverse team that values inclusivity and continuous improvement.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: Experience with vulnerability management tools and strong communication skills required.

The predicted salary is between 50000 - 60000 £ per year.

Fixed Term Contract Duration - 12 Months

About the Business

Quilter plc is a leading provider of financial advice, investments and wealth management, committed to being the UK's best wealth manager for clients and their advisers. Quilter oversees £141.9 billion in customer investments (as of 31 March 2026). It has an adviser and customer offering spanning financial advice, investment platforms, multi-asset investment solutions, and discretionary fund management. The business is comprised of two segments: Affluent and High Net Worth.

At Quilter we never stand still. Our foundations are rooted in our extraordinary expertise, which is trusted by hundreds of thousands of customers, but we have great ambitions to stay one step ahead and make an even greater difference to the people and communities we serve. Our business is transforming, continually modernising, and becoming even more customer centric. So, if you want to be bold in the pursuit of your ambitions, bring new ideas, and challenge and evolve what we do, it's the perfect time to join us!

About the Role

Level: 4

Department: Security Operations (Information Security)

Reports to: Head of Security Operations

Location: Southampton / London / England - Home Worker

Contract Type: Fixed Term contract - 12 months

At Quilter, we're strengthening our exposure management capability across on-prem, cloud and externally facing estate. This role is central to driving a risk-based vulnerability management programme - combining high-quality scanning and asset insight with cloud posture and attack surface intelligence - so that remediation is prioritised where it matters most and delivered with pace and measurable outcomes.

The Vulnerability Management Specialist is responsible for the end-to-end vulnerability management lifecycle, including detection, triage, prioritisation, tracking and assurance of remediation across infrastructure, endpoints, applications and cloud platforms. The role also supports Cloud Security Posture Management (CSPM) activities, including monitoring of cloud security benchmark compliance and CSPM attack paths, and integrates Attack Surface Management findings to reduce exposure from unknown or unmanaged internet-facing assets.

The successful candidate will be hands-on with enterprise vulnerability tooling and will partner closely with infrastructure, cloud engineering, application teams and third parties to ensure remediation is delivered within defined service levels and supported by clear reporting and governance.

Key Responsibilities

  • Vulnerability Detection, Triage & Prioritisation: Operate and continuously improve vulnerability scanning and prioritisation using Qualys VMDR and associated capabilities. Perform daily/weekly triage of new and emerging vulnerabilities, validating detections and ensuring severity and urgency reflect exploitability, asset criticality, business impact, patch availability and compensating controls.
  • Cloud Security Posture Management (Azure focus): Own day-to-day CSPM triage and oversight, ensuring cloud posture findings are actionable, risk-rated and routed to the correct engineering owners for remediation.
  • Attack Surface Management & Exposure Reduction: Ingest and operationalise Attack Surface Management findings to identify and reduce risk from internet-facing assets, unknown services, misconfigurations and unmanaged exposure.
  • Remediation Oversight, Governance & Assurance: Drive remediation outcomes through structured engagement with platform, infrastructure, application, endpoint and cloud teams.
  • Reporting, Metrics & Stakeholder Communication: Produce clear, accurate reporting for operational teams and leadership, including trends, SLA performance, backlog health, and risk-based prioritisation views.
  • Process & Continuous Improvement: Follow and continuously improve established vulnerability and CSPM processes, ensuring the operating cadence remains effective and measurable.

Key Stakeholders: Security Operations / Detection Engineering, Cyber Threat, Infrastructure & Platform and Cloud Engineering, Application Owners, End User Computing, Risk & Governance partners, and relevant third-party suppliers/MSSPs.

About You

Essential:

  • Significant hands-on experience operating enterprise vulnerability management tooling, with deep expertise in Qualys (VMDR) across complex environments.
  • Strong experience with Azure CSPM operations: triage, prioritisation, remediation routing, and assurance.
  • Practical experience with Attack Surface Management concepts and workflows.
  • Deep understanding of how code-based and software component vulnerabilities are discovered, exploited, and weaponised.
  • Proven ability to run a risk-based vulnerability programme.
  • Confident communicator who can explain technical vulnerabilities, exploitation likelihood, and remediation options to varied audiences.

Desirable:

  • Experience integrating vulnerability management with broader security tooling and control frameworks.
  • Experience in regulated environments, with evidence-led reporting and governance expectations.

Qualifications / Certifications (optional but beneficial): Relevant security certification(s) (e.g., CISSP/CCSP, Azure Security, vulnerability management or cloud security certifications).

Inclusion & Diversity: We value diversity and strive to promote inclusivity in all aspects of our culture. We believe in equal opportunities for all, ensuring that no applicant encounters less favourable treatment based on anything but their skills, qualifications, experience, and potential.

Values: Do the right thing, Always curious, Embrace challenge, Stronger together.

Core Benefits: Holiday: 182 hours (26 days), Quilter Incentive Scheme, Pension Scheme, Healthcare Cash Plan, Benefit Allowance.

Vulnerability Management Specialist - Quilter in Southampton employer: Quilter

Quilter plc is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration. With a strong commitment to employee growth, we provide extensive training opportunities and a supportive culture that values diversity and inclusivity. Located in vibrant Southampton or London, our employees enjoy competitive benefits, including a generous holiday allowance and a non-contributory pension scheme, making Quilter the ideal place for those seeking meaningful and rewarding careers in financial services.

Quilter

Contact Details:

Quilter Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Vulnerability Management Specialist - Quilter in Southampton

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching Quilter and understanding their values and goals. Tailor your responses to show how your skills align with their mission. Remember, it’s all about demonstrating how you can contribute to their success!

Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms to refine your answers. Focus on articulating your experience with vulnerability management and cloud security clearly and confidently.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in joining the Quilter team. Let’s get you that job!

We think you need these skills to ace Vulnerability Management Specialist - Quilter in Southampton

Vulnerability Management
Qualys VMDR
Cloud Security Posture Management (CSPM)
Azure
Attack Surface Management
Risk Assessment
Stakeholder Management

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Vulnerability Management Specialist role. Highlight your hands-on experience with enterprise vulnerability management tooling, especially Qualys, and any relevant Azure CSPM operations you've been involved in.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for Quilter. Share specific examples of how you've driven remediation outcomes or improved vulnerability management processes in your previous roles.

Showcase Your Communication Skills:As a Vulnerability Management Specialist, you'll need to communicate technical details to various stakeholders. Use your application to demonstrate your ability to explain complex concepts clearly and concisely.

Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensure it gets the attention it deserves!

How to prepare for a job interview at Quilter

Know Your Tools Inside Out

Make sure you’re well-versed in the enterprise vulnerability management tools, especially Qualys VMDR. Be ready to discuss your hands-on experience and how you've used these tools to drive a risk-based vulnerability programme.

Stay Updated on Threats

Familiarise yourself with the latest trends in cybersecurity threats, particularly those related to cloud security and attack surface management. Being able to discuss recent vulnerabilities or exploits will show that you’re proactive and knowledgeable.

Communicate Clearly

Practice explaining complex technical concepts in simple terms. You’ll need to communicate effectively with various stakeholders, from engineering teams to senior leadership, so being able to translate technical jargon into business impact is key.

Demonstrate Your Problem-Solving Skills

Prepare examples of how you've triaged and prioritised vulnerabilities in past roles. Highlight your approach to remediation and how you’ve worked with different teams to ensure timely fixes, showcasing your collaborative spirit.