Vulnerability Management Lead in Preston

Vulnerability Management Lead in Preston

Preston Full-Time 63000 - 77000 £ / year (est.) No working from home possible
Undisclosed

At a Glance

  • Tasks: Lead vulnerability management governance and ensure effective supplier processes.
  • Company: Join a dynamic team in a leading security environment.
  • Benefits: Competitive daily rate, professional growth, and a chance to make an impact.
  • Other info: Opportunity for career advancement in a complex, multi-supplier setting.
  • Why this job: Shape the future of cybersecurity while working with top-tier suppliers.
  • Qualifications: Experience in vulnerability management and strong stakeholder engagement skills.

The predicted salary is between 63000 - 77000 £ per year.

Role Title

Vulnerability Management Lead

Duration

contract to run until 31/03/2027

Location

Inverness or Preston. Fully onsite, 5 days per week

Rate

up to £644 p/d Umbrellainside IR35

Clearance required

Sole UK Nationality with Active SC Clearance.

The Senior Vulnerability Management Consultant operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of vulnerability management across a complex multi-supplier environment.

The role is responsible for ensuring suppliers manage vulnerabilities consistently, effectively, and in accordance with client policy, regulatory requirements, and risk appetite.

Working across security, service management, supplier, and client governance functions, the consultant provides a consolidated view of vulnerability risk and drives continuous improvement across the vulnerability management lifecycle.

This is a governance, assurance, and supplier management role and does not perform vulnerability scanning, penetration testing, exploit analysis, or technical remediation.

Key Responsibilities

  • Vulnerability Management Governance
  • Own and govern the vulnerability management framework across suppliers

• Define and maintain

  • Vulnerability classification standards
  • Risk-based prioritisation models
  • Remediation timelines
  • Ensure alignment to client security policies and control requirements
  • Act as the primary OI lead for vulnerability management
  • Challenge, validate, and assure supplier vulnerability processes
  • Drive consistency in reporting, remediation, and evidence standards
  • Manage escalations relating to high-risk or overdue vulnerabilities
  • Ensure suppliers apply risk-based prioritisation methodologies, including:
  • CVSS
  • EPSS
  • Business criticality considerations
  • Maintain visibility of enterprise vulnerability exposure
  • Oversee risk acceptance and exception management activities
  • Reporting & Executive Visibility
  • Produce consolidated vulnerability risk reporting across suppliers

Provide insight into

  • Risk posture
  • Compliance performance
  • Emerging threat exposure
  • Support governance boards and client security leadership
  • Assurance & Evidence Management
  • Define vulnerability management evidence requirements

Ensure end-to-end traceability of

  • Identification
  • Prioritisation
  • Remediation
  • Validation
  • Support audits, assurance reviews, and compliance activities
  • Identify trends, recurring weaknesses, and process improvement opportunities
  • Drive maturity improvements across supplier processes
  • Support optimisation of reporting, governance, and operating models
  • Contribute to security operating model evolution within the SIAM environment
  • Your skills and experience
  • Significant experience in Vulnerability Management, Cyber Governance, Security Operations Governance, or GRC roles

Strong understanding of

  • Vulnerability management lifecycle
  • Risk-based remediation approaches
  • Security governance frameworks
  • Experience operating within complex multi-supplier environments
  • Strong stakeholder management and supplier challenge capability
  • Experience presenting risk information to senior stakeholders

Knowledge of

  • NIST CSF
  • NCSC guidance
  • Secure by Design principles
  • Experience in Defence, Government, or highly regulated environments
  • Exposure to security assurance and audit activities
  • Vulnerability Management Framework
  • Consolidated supplier vulnerability reporting
  • Executive vulnerability risk dashboards
  • Vulnerability governance and assurance packs
  • Audit-ready evidence repository
  • Role Definition

The role governs and assures vulnerability management across suppliers, ensuring vulnerabilities are consistently prioritised, remediated, evidenced, and reported to the client through a risk-based and audit-ready approach, without performing technical remediation activities.

  • What This Role Does / Does Not Do
  • Does
  • Govern, assure, challenge and coordinate
  • Provide enterprise-wide vulnerability risk visibility
  • Does Not
  • Operate vulnerability scanners
  • Perform technical security testing
  • Deploy patches or fixes
  • Own remediation engineering activities

All profiles will be reviewed against the required skills and experience.

Due to the high number of applications we will only be able to respond to successful applicants in the first instance.

We thank you for your interest and the time taken to apply!

#J-18808-Ljbffr

Vulnerability Management Lead in Preston employer: Undisclosed

Experis is an exceptional employer, offering a dynamic work environment in London or Manchester where collaboration and innovation thrive. With a strong focus on employee growth, we provide comprehensive benefits including a contributory pension programme, medical and dental cover, and generous holiday allowances, ensuring our team members feel valued and supported in their professional journey.

Undisclosed

Contact Details:

Undisclosed Recruitment Team

We think you need these skills to ace Vulnerability Management Lead in Preston

Vulnerability Management
Cyber Governance
Security Operations Governance
GRC Roles
Risk-based Remediation Approaches
Security Governance Frameworks
Stakeholder Management