Vulnerability Manager in Liverpool

Vulnerability Manager in Liverpool

Liverpool Full-Time 60000 - 75000 € / year (est.) Home office (partial)
The Very Group

At a Glance

  • Tasks: Lead and improve vulnerability management across various environments while coordinating with engineering teams.
  • Company: Join the dynamic team at Very, a leading digital retailer focused on making life better for families.
  • Benefits: Enjoy flexible working, generous holiday, learning opportunities, and a £1000 benefits allowance.
  • Other info: Inclusive culture with excellent career growth and support for diverse backgrounds.
  • Why this job: Make a real impact in cybersecurity while developing your skills in a supportive environment.
  • Qualifications: Strong experience in vulnerability management and a technical background in security.

The predicted salary is between 60000 - 75000 € per year.

About us
We’re the team behind digital retailer Very. Our purpose, helping families get more out of life, powers everything we do. And we want our people to get more out of life too! If you’re high-performing, ambitious and make the most of every opportunity, we want to hear from you. In return, you’ll enjoy heaps of flexibility, great perks and benefits, and the freedom to be yourself, keep learning and take your career wherever you want it to go. If you love making a difference, you’ll love making it sparkle for millions of Very customers.

About the Role
You’ll act as the central coordination and risk authority for vulnerability activity—working closely with engineering and platform teams who remain accountable for remediation delivery. This role needs a strong technical foundation and the ability to build, lead and develop a vulnerability management team, setting clear ways of working, coaching capability and scaling our coverage and reporting as we grow.

What you will be doing:

  • Own and continuously improve the end-to-end vulnerability management lifecycle across legacy, cloud, containerised and third-party environments.
  • Operate and coordinate the Security Penetration Testing Framework, ensuring a consistent risk-led approach to scope, frequency, execution, retesting and closure.
  • Triage, prioritise and track vulnerabilities and pen test findings—ensuring clear ownership, progress visibility and timely escalation of unmanaged risk.
  • Govern risk acceptance/exceptions, compensating controls and evidence for audit and regulatory scrutiny.
  • Own reporting (risk posture, trends, coverage, performance) for senior stakeholders and governance forums.
  • Drive improvements in tooling, data quality, asset coverage and testing scope—working with suppliers and internal teams.
  • Establish a sustainable vulnerability management team (hiring, onboarding, performance, coaching).

Essential Skills and Experience:

  • Strong experience coordinating vulnerability management and security penetration testing in complex enterprise environments.
  • Demonstrable technical background (e.g., application/infrastructure security, cloud security, vulnerability assessment and remediation validation) with the capability to hire, lead and develop a high-performing vulnerability management team.
  • Solid understanding of penetration testing methodologies and assurance expectations across applications, infrastructure, cloud and externally exposed services.
  • Ability to apply risk-based judgement beyond severity scoring (exploitability, exposure and business context).
  • Experience governing penetration testing (scope definition, prioritisation, retesting and remediation assurance).
  • Proven track record working with engineering teams where remediation ownership sits outside of security.
  • Confident stakeholder management—able to translate technical findings into clear business risk narratives.
  • High standards for reporting, documentation and audit readiness.

Desirable Skills and Experience:

  • Experience aligning vulnerability governance to ISO 27001 and/or NIST.
  • Hands-on experience configuring and operating industry-standard vulnerability testing tooling.
  • Exposure to cloud-native and legacy environments.
  • Experience mentoring analysts or leading capability uplift.
  • Understanding of secure SDLC and modern engineering delivery models.

Some of our benefits:

  • Flexible, hybrid working model.
  • Inclusive culture and environment.
  • £1000 flexible benefits allowance to suit your needs.
  • 30 days holiday + bank holidays.
  • Udemy learning access.
  • Bonus potential (performance and business-related).
  • Up to 25% discount on Very.co.uk.
  • Matched pension up to 6%.
  • More benefits can be found on our career site.

How to apply:
Please note that the talent acquisition team are managing this vacancy directly, and if successful in securing this role, you will be required to undertake a credit, CIFAS, Right to Work checks and if a specific requirement of your role a DBS (criminal records) check. Should your application progress we require you to let the team know if there is anything you need to disclose in relation to any of these checks prior to them being undertaken, including any unspent criminal convictions.

What happens next?
Our talent acquisition team will be in touch if you’re successful so keep an eye on your emails! We’ll arrange a short call to learn more about you, as well as answer any questions you have. If it feels like we’re a good match, we’ll share your CV with the hiring manager to review. Our interview process is tailored to each role and can be in-person or held remotely. You can expect a two-stage interview process for this position: 1st Stage - Initial Teams call with Hiring Team. 2nd Stage - A one-hour formal interview where you can expect both competency and technical questions with a take home task to prepare for.

Please do let us know if you require any reasonable adjustments.

Diversity, inclusion and equal opportunities:
We’re building a culture of everyday inclusion, and welcome applications from anyone who believes they can do the job. We don’t discriminate based on age, disability, gender reassignment, marriage or civil partnership, pregnancy or maternity, race, religion or belief, sex, or sexual orientation.

We want our recruitment process to be accessible to everyone. If you need reasonable adjustments to apply, interview, or perform a role, let us know via talentacquisition@theverygroup.com. We’ll be happy to support you.

We’re proud to be a Disability Confident Committed Employer and have nine brilliant colleague networks - including DAWN (Disability Awareness at Very) and Think (Neurodiversity at Very) - that are helping us make Very an even more inclusive place to work.

Vulnerability Manager in Liverpool employer: The Very Group

At Very, we prioritise the well-being and growth of our employees, offering a flexible hybrid working model and a vibrant, inclusive culture that encourages personal and professional development. As a Vulnerability Manager, you'll not only lead a dynamic team but also enjoy a generous benefits package, including a £1000 flexible benefits allowance, 30 days holiday, and access to continuous learning through Udemy. Join us in making a meaningful impact for millions of customers while advancing your career in a supportive environment.

The Very Group

Contact Detail:

The Very Group Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Vulnerability Manager in Liverpool

Tip Number 1

Get to know the company inside out! Research Very's values, culture, and recent projects. This will help you tailor your conversations and show that you're genuinely interested in being part of the team.

Tip Number 2

Network like a pro! Connect with current employees on LinkedIn or attend industry events. Building relationships can give you insider info and might even lead to a referral—definitely a win!

Tip Number 3

Prepare for those interviews! Brush up on your technical skills and be ready to discuss your experience with vulnerability management. Practice answering common questions and think about how you can demonstrate your problem-solving abilities.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the Very team!

We think you need these skills to ace Vulnerability Manager in Liverpool

Vulnerability Management
Security Penetration Testing
Technical Background in Application Security
Cloud Security
Vulnerability Assessment
Remediation Validation
Penetration Testing Methodologies

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Vulnerability Manager role. Highlight your experience in vulnerability management and security penetration testing, and don’t forget to showcase your technical skills that align with what we’re looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to tell us why you’re passionate about vulnerability management and how your background makes you a perfect fit for our team. Keep it engaging and relevant to the role.

Showcase Your Achievements:When detailing your experience, focus on specific achievements rather than just responsibilities. Use metrics where possible to demonstrate your impact in previous roles—this helps us see the value you can bring to Very!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re genuinely interested in joining our team at Very!

How to prepare for a job interview at The Very Group

Know Your Vulnerability Management Inside Out

Make sure you brush up on the end-to-end vulnerability management lifecycle. Be ready to discuss your experience with legacy, cloud, and containerised environments, as well as how you've improved processes in the past.

Showcase Your Technical Skills

Prepare to demonstrate your technical background in application and infrastructure security. Be specific about the tools you've used for vulnerability assessment and how you've validated remediation efforts.

Communicate Clearly with Stakeholders

Practice translating complex technical findings into business risk narratives. You’ll need to show that you can effectively communicate with engineering teams and senior stakeholders, so think of examples where you've done this successfully.

Prepare for Competency and Technical Questions

Expect a mix of competency and technical questions in the second stage of the interview. Review common penetration testing methodologies and be ready to discuss how you’ve governed testing scopes and prioritised vulnerabilities in previous roles.