Senior Vulnerability Engineer

Senior Vulnerability Engineer

Full-Time 60000 - 80000 £ / year (est.) No home office possible
World Wide Technology

At a Glance

  • Tasks: Lead vulnerability management and automate processes in a dynamic financial services environment.
  • Company: Join a leading financial institution committed to innovation and security.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative culture with a focus on continuous learning and development.
  • Why this job: Make a real impact by enhancing security measures and protecting vital network infrastructure.
  • Qualifications: 6+ years in vulnerability management with expertise in Tenable and ServiceNow.

The predicted salary is between 60000 - 80000 £ per year.

The Senior Network Vulnerability Management Analyst will operate as a subject matter expert within a regulated financial services environment, owning the end to end lifecycle of network infrastructure vulnerabilities. This role focuses on Tenable driven discovery, risk based prioritisation, remediation coordination, ServiceNow Vulnerability Response workflow management, and automation to uplift the maturity and efficiency of the vulnerability management programme.

Responsibilities

  • Act as the primary analyst for vulnerabilities identified through Tenable authenticated scans across routers, switches, firewalls, load balancers, wireless infrastructure, and other network devices.
  • Validate vulnerability findings, remove false positives, and deduplicate results across scan cycles, asset groups, and overlapping detections.
  • Perform risk based prioritisation using CVSS, EPSS, exploit intelligence, asset criticality, exposure, compensating controls, and regulatory considerations aligned to bank risk appetite.
  • Maintain clear and defensible documentation for prioritisation decisions, exceptions, and risk acceptances.
  • Coordinate remediation activities with network engineering, infrastructure, and platform teams to ensure vulnerabilities are resolved within agreed service level agreements.
  • Translate technical findings into actionable remediation guidance including patching, configuration changes, upgrades, or mitigations appropriate to each platform.
  • Lead remediation working sessions, track ageing vulnerabilities, escalate blockers through governance forums, and validate fixes through targeted rescans.
  • Manage the vulnerability lifecycle within ServiceNow Vulnerability Response, ensuring accurate CMDB linkage, correct assignment routing, SLA tracking, and reporting.
  • Tune Tenable and ServiceNow integrations including ingestion rules, asset matching, deduplication logic, severity overrides, exceptions, and reporting outputs.
  • Build and maintain dashboards and key performance indicators for operational, management, and regulatory reporting.
  • Identify and deliver automation across ingestion, enrichment, prioritisation, ticketing, notifications, evidence capture, rescanning, and reporting using ServiceNow Flow Designer, Integration Hub, Tenable APIs, scripting, and where appropriate SOAR platforms.
  • Contribute to the strategic roadmap of the vulnerability management programme including process design, RACI definition, metrics, and integration with asset management, patch management, threat intelligence, and governance risk and compliance functions.

Qualifications

Required Experience

  • Six or more years of vulnerability management experience with deep hands on expertise in Tenable Security Center, Tenable Vulnerability Management, Nessus, and authenticated scanning of network devices.
  • Strong practical experience with ServiceNow Vulnerability Response including CMDB integration, assignment rules, exception workflows, and reporting.
  • Solid knowledge of enterprise network platforms such as Cisco IOS, IOS XE, NX OS, Juniper, Palo Alto, Fortinet, F5, and Arista, and the vulnerability classes that commonly affect them.
  • Demonstrated delivery of vulnerability management automation in production environments with clear measurable outcomes.
  • Proficiency in at least one scripting language, preferably Python, and confidence working with REST APIs.
  • Experience operating within regulated financial services environments with familiarity of frameworks such as FED, NIST Cybersecurity Framework, DORA, ISO 27001, and CIS Benchmarks.
  • Strong stakeholder management skills with the ability to engage both technical engineering teams and senior security or risk stakeholders.

Preferred Experience

  • Professional German language capability at B2 level or above.
  • Experience with SOAR platforms such as Splunk SOAR, Cortex XSOAR, or ServiceNow SecOps.
  • Exposure to additional vulnerability scanners such as Qualys or Rapid7 and threat intelligence or EPSS enrichment pipelines.
  • Industry certifications including CISSP, OSCP, GIAC certifications, Tenable certifications, or ServiceNow CIS Vulnerability Response.
  • Prior experience working within a Tier one bank or systemically important financial institution.

Tools and Technologies

  • Tenable Security Center, Tenable Vulnerability Management, Nessus, ServiceNow Vulnerability Response, CMDB, ServiceNow Flow Designer, Integration Hub, Python, REST APIs, network infrastructure platforms, SOAR tooling.

Candidates will be required to go through background checks before commencing contract. Must be an EU Citizen. Some occasional travel may be required. Only successful candidates will be contacted.

EQUAL OPPORTUNITIES

World Wide Technology is committed to equal opportunities and actively seeks applications from all sectors of the community irrespective of sex, race, colour, nationality, ethnic or national origin, disability, marital status, sexual orientation, having responsibility for dependents, age, religion/beliefs, or any other reason which cannot be shown to be justified.

Senior Vulnerability Engineer employer: World Wide Technology

At World Wide Technology, we pride ourselves on being an exceptional employer, particularly for the Senior Vulnerability Engineer role within the dynamic financial services sector. Our commitment to employee growth is evident through continuous training opportunities and a collaborative work culture that values innovation and teamwork. Located in a vibrant environment, we offer competitive benefits and a focus on diversity and inclusion, ensuring that every team member feels valued and empowered to contribute meaningfully to our mission.
World Wide Technology

Contact Detail:

World Wide Technology Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Vulnerability Engineer

✨Tip Number 1

Network with industry professionals! Attend meetups, webinars, or conferences related to vulnerability management. This way, we can get insights into the latest trends and maybe even find out about job openings before they’re advertised.

✨Tip Number 2

Showcase your skills through projects! If you’ve worked on any relevant automation or vulnerability management projects, make sure to highlight them in conversations. We want to demonstrate our hands-on experience and problem-solving abilities.

✨Tip Number 3

Prepare for interviews by practising common questions! We should focus on technical scenarios related to Tenable and ServiceNow. Mock interviews with friends or using online platforms can help us feel more confident when it’s our turn to shine.

✨Tip Number 4

Apply directly through our website! It’s often the best way to ensure your application gets noticed. Plus, we can tailor our approach based on the specific roles we’re interested in, making it easier to stand out from the crowd.

We think you need these skills to ace Senior Vulnerability Engineer

Tenable Security Center
Tenable Vulnerability Management
Nessus
ServiceNow Vulnerability Response
CMDB Integration
Python
REST APIs
Network Infrastructure Knowledge
Vulnerability Management Automation
Risk Based Prioritisation
Stakeholder Management
Regulated Financial Services Experience
Scripting Skills
SOAR Platforms

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Senior Vulnerability Engineer role. Highlight your experience with Tenable and ServiceNow, and don’t forget to mention any relevant certifications. We want to see how your skills match what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about vulnerability management and how your background makes you a perfect fit for our team. Keep it concise but impactful – we love a good story!

Showcase Your Achievements: When detailing your experience, focus on specific achievements rather than just listing duties. Did you automate a process that saved time? Or improve a system's security? We want to hear about it! Numbers and outcomes speak volumes.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our awesome team at StudySmarter!

How to prepare for a job interview at World Wide Technology

✨Know Your Tools Inside Out

Make sure you’re well-versed in Tenable Security Center, Nessus, and ServiceNow Vulnerability Response. Brush up on how these tools integrate with network devices and be ready to discuss your hands-on experience with them.

✨Speak the Language of Risk

Familiarise yourself with risk-based prioritisation methods like CVSS and EPSS. Be prepared to explain how you’ve used these frameworks in past roles to make informed decisions about vulnerability management.

✨Showcase Your Automation Skills

Highlight any experience you have with automating vulnerability management processes. Discuss specific examples where you’ve implemented automation using scripting languages like Python or tools like ServiceNow Flow Designer.

✨Engage with Stakeholders

Demonstrate your ability to communicate effectively with both technical teams and senior stakeholders. Prepare examples of how you’ve successfully coordinated remediation activities and managed expectations in previous roles.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>