At a Glance
- Tasks: Lead the Threat and Vulnerability Management function, ensuring security across EMEA Bank operations.
- Company: Join a leading global bank focused on innovation and security.
- Benefits: Competitive salary, career growth, and a dynamic work environment.
- Other info: Collaborative culture with opportunities for continuous learning and development.
- Why this job: Make a real impact in cybersecurity while developing your leadership skills.
- Qualifications: Proven experience in cybersecurity leadership and technical expertise.
The predicted salary is between 80000 - 100000 £ per year.
The role is part of the group which encompasses Infrastructure and Service Management across EMEA Bank, International Securities, and the 15+ countries in which these entities operate. The position is responsible for leading the Threat and Vulnerability Management function, including oversight of an outsourced offshore third-party service. This function integrates secure practices into the development lifecycle and aligns with service transition processes to ensure compliance with internal controls and regulatory standards. It plays a critical role in governance, audit readiness, and the continuous improvement of the organization’s security posture, while also serving as the central coordination point for all vulnerability-related activities across DES. The successful candidate must demonstrate proven experience in leading teams and fostering a culture of technical excellence. They will be expected to establish best practices for risk identification and remediation planning, while also influencing stakeholders and delivering competitive advantage for global organisations by protecting against external threats and potential security vulnerabilities.
Your responsibilities:
- Strategic Leadership & Vision
- Lead the design, development, operation and management of the department’s Threat and Vulnerability Management (TVM) strategy and roadmaps, ensuring alignment with business requirements, services, strategic goals, and IT risk appetite.
- Develop short, medium, and long-term strategic goals and objectives for DES TVM, including documenting the current environment and defining the future roadmap.
- Define measurable, repeatable processes and reporting metrics, subject to continuous improvement.
- Define the DES Threat and Vulnerability function’s Key Risk Indicators (KRIs) and govern accordingly.
- Produce regular KPI, MI, and risk management data for senior management.
- Responsible for identifying cost-saving and optimisation opportunities within MUS EMEA and the wider MUFG group.
- Operational Oversight & Technical Execution
- Lead a team of Threat and Vulnerability Engineers to deliver best practice operations and strategic development, shaping the department’s security posture while adhering to MUFG policies and procedures.
- Oversee the successful deployment of routine and out-of-band security patches across IT infrastructure.
- Automate patch deployments and associated post-deployment check-outs.
- Triage vulnerabilities into “Fix, Acknowledge, and Investigate” categories using industry-aligned risk rating methodologies.
- Use ServiceNow Application Vulnerability Response (AVR) and Vulnerability Response (VR) modules to manage and report on vulnerabilities and violations across the estate, integrating with dashboards and workflows for visibility and accountability.
- Risk Management & Remediation
- Work with other technology teams to provide in-depth analysis of vulnerabilities and impacts to key stakeholders.
- Collaborate with application teams to ensure secure coding practices and timely remediation of vulnerabilities, aligned with criticality-based policy enforcement.
- Prioritise weaknesses in IT infrastructure and applications using manual and automated methods, including results from Static Application Testing (SAST) and Software Composition Analysis (SCA) tooling (in conjunction with the Service Transition team).
- Influence stakeholders to prioritise and drive remediation of process and technology gaps.
- Work with Cyber Security, Application Teams, and IT Risk to ensure controls are met and vulnerabilities are addressed across infrastructure and applications.
- Engage and support Cyber Security for remediation of penetration test findings.
- Engage with Internal and External Auditors as the SME on all matters relating to VM.
- Stakeholder Engagement & Culture
- Act as the primary Service Matter Expert and point of contact for the Threat and Vulnerability Management function within DES.
- Work closely with industry partners, vendors, and the wider technology ecosystem to leverage external expertise and best practices.
- Conduct market research to identify emerging risk and vulnerability trends.
- Build strong relationships across Bank and Securities functions (e.g. IT Risk & Control, Cyber Security, Operational Risk), underpinned by trust and MUFG’s core values.
- Lead by example in building relationships across the Bank, strengthening peer networks and collaboration.
- Promote MUFG’s values-led culture, fostering inclusivity and diversity.
- Champion staff cyber education and awareness to embed a proactive cyber-focused culture.
- Promote a dynamic, delivery-driven culture that works alongside Technology and Business units to provide responsive resolutions and value-driven solutions.
Your Profile
- Skills and Experience
- Leadership & Team Development
- Proven experience of directly managing a team of Threat and Vulnerability Engineers, including mentoring, developing, and guiding security professionals in a collaborative, high-performing environment.
- Strong strategic thinking and visionary skills with the ability to co-develop and drive the function’s technical vision, strategy, and roadmap aligned with business goals and risk appetite.
- Technical Expertise & Security Operations
- Prior extensive experience working within infrastructure environments and cloud platforms (AWS, Azure, Oracle), with a high-level understanding of platforms, operating systems, and technologies.
- Proven capability in creating and executing comprehensive threat and vulnerability management programmes, including vulnerability scanning, penetration testing, and security awareness training.
- Proficiency in using vulnerability scanning tools (e.g. Tenable, Qualys, Rapid7, Veracode, JFrog Xray), threat intelligence platforms, and incident response tools.
- Prior experience implementing automated solutions for vulnerability scanning, threat detection, and incident response, with a focus on continuous process improvement.
- Risk Management & Threat Intelligence
- Strong familiarity with security frameworks and standards (e.g. NIST, ISO 27001), and deep understanding of security concepts including vulnerability management, threat intelligence, incident response, and offensive security techniques.
- Experience in gathering and analysing threat intelligence to understand emerging threats, attack vectors, and threat actors.
- Maintains up-to-date knowledge of the latest security threats, vulnerabilities, and best practices.
- Strong analytical and problem-solving skills to analyse data, identify patterns and develop effective solutions to mitigate risk.
- Communication & Stakeholder Engagement
- Proven ability to communicate effectively with senior management, providing governance and risk oversight.
- Excellent verbal and written communication skills to report findings and collaborate across cross-functional Technology and non-Technology teams.
- Ability to translate technical risks into business-relevant language for both technical and non-technical stakeholders, including executive leadership.
- Leadership & Team Development
- Education / Qualifications:
- Essential
- Recognised cybersecurity certification: CISSP and/or CISM
- Strong knowledge of: Ivanti LANDesk, Qualys, Splunk Windows Server/Desktop, RHEL/OEL Linux PowerShell and Python scripting
- Proven experience leading strategic security initiatives and process automation in large-scale environments
Threat Intelligence Lead in London employer: Webologix Ltd/ INC
As a leading employer in the financial services sector, we pride ourselves on fostering a culture of innovation and collaboration, particularly within our Threat Intelligence team. Our commitment to employee growth is evident through comprehensive training programmes and opportunities for advancement, all while working in a dynamic environment that values inclusivity and diversity. Located in the heart of EMEA, we offer competitive benefits and a chance to make a meaningful impact on global security practices, ensuring our employees are at the forefront of protecting against emerging threats.
StudySmarter Expert Advice🤫
We think this is how you could land Threat Intelligence Lead in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Webologix Ltd/ INC, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Webologix Ltd/ INC
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Webologix Ltd/ INC. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Threat Intelligence Lead in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Webologix Ltd/ INC insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Webologix Ltd/ INC that you’re committed to staying ahead in the game.
How to prepare for a job interview at Webologix Ltd/ INC
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Webologix Ltd/ INC to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Webologix Ltd/ INC.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.