At a Glance
- Tasks: Lead vulnerability management and automate processes in a dynamic financial services environment.
- Company: Join a leading financial institution committed to innovation and security.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Collaborative culture with a focus on continuous learning and development.
- Why this job: Make a real impact by enhancing security measures and protecting vital network infrastructure.
- Qualifications: 6+ years in vulnerability management with expertise in Tenable and ServiceNow.
The predicted salary is between 60000 - 80000 £ per year.
The Senior Network Vulnerability Management Analyst will operate as a subject matter expert within a regulated financial services environment, owning the end to end lifecycle of network infrastructure vulnerabilities. This role focuses on Tenable driven discovery, risk based prioritisation, remediation coordination, ServiceNow Vulnerability Response workflow management, and automation to uplift the maturity and efficiency of the vulnerability management programme.
Responsibilities
- Act as the primary analyst for vulnerabilities identified through Tenable authenticated scans across routers, switches, firewalls, load balancers, wireless infrastructure, and other network devices.
- Validate vulnerability findings, remove false positives, and deduplicate results across scan cycles, asset groups, and overlapping detections.
- Perform risk based prioritisation using CVSS, EPSS, exploit intelligence, asset criticality, exposure, compensating controls, and regulatory considerations aligned to bank risk appetite.
- Maintain clear and defensible documentation for prioritisation decisions, exceptions, and risk acceptances.
- Coordinate remediation activities with network engineering, infrastructure, and platform teams to ensure vulnerabilities are resolved within agreed service level agreements.
- Translate technical findings into actionable remediation guidance including patching, configuration changes, upgrades, or mitigations appropriate to each platform.
- Lead remediation working sessions, track ageing vulnerabilities, escalate blockers through governance forums, and validate fixes through targeted rescans.
- Manage the vulnerability lifecycle within ServiceNow Vulnerability Response, ensuring accurate CMDB linkage, correct assignment routing, SLA tracking, and reporting.
- Tune Tenable and ServiceNow integrations including ingestion rules, asset matching, deduplication logic, severity overrides, exceptions, and reporting outputs.
- Build and maintain dashboards and key performance indicators for operational, management, and regulatory reporting.
- Identify and deliver automation across ingestion, enrichment, prioritisation, ticketing, notifications, evidence capture, rescanning, and reporting using ServiceNow Flow Designer, Integration Hub, Tenable APIs, scripting, and where appropriate SOAR platforms.
- Contribute to the strategic roadmap of the vulnerability management programme including process design, RACI definition, metrics, and integration with asset management, patch management, threat intelligence, and governance risk and compliance functions.
Qualifications
Required Experience
- Six or more years of vulnerability management experience with deep hands on expertise in Tenable Security Center, Tenable Vulnerability Management, Nessus, and authenticated scanning of network devices.
- Strong practical experience with ServiceNow Vulnerability Response including CMDB integration, assignment rules, exception workflows, and reporting.
- Solid knowledge of enterprise network platforms such as Cisco IOS, IOS XE, NX OS, Juniper, Palo Alto, Fortinet, F5, and Arista, and the vulnerability classes that commonly affect them.
- Demonstrated delivery of vulnerability management automation in production environments with clear measurable outcomes.
- Proficiency in at least one scripting language, preferably Python, and confidence working with REST APIs.
- Experience operating within regulated financial services environments with familiarity of frameworks such as FED, NIST Cybersecurity Framework, DORA, ISO 27001, and CIS Benchmarks.
- Strong stakeholder management skills with the ability to engage both technical engineering teams and senior security or risk stakeholders.
Preferred Experience
- Professional German language capability at B2 level or above.
- Experience with SOAR platforms such as Splunk SOAR, Cortex XSOAR, or ServiceNow SecOps.
- Exposure to additional vulnerability scanners such as Qualys or Rapid7 and threat intelligence or EPSS enrichment pipelines.
- Industry certifications including CISSP, OSCP, GIAC certifications, Tenable certifications, or ServiceNow CIS Vulnerability Response.
- Prior experience working within a Tier one bank or systemically important financial institution.
Tools and Technologies
- Tenable Security Center, Tenable Vulnerability Management, Nessus, ServiceNow Vulnerability Response, CMDB, ServiceNow Flow Designer, Integration Hub, Python, REST APIs, network infrastructure platforms, SOAR tooling.
Candidates will be required to go through background checks before commencing contract. Must be an EU Citizen. Some occasional travel may be required. Only successful candidates will be contacted.
EQUAL OPPORTUNITIES
World Wide Technology is committed to equal opportunities and actively seeks applications from all sectors of the community irrespective of sex, race, colour, nationality, ethnic or national origin, disability, marital status, sexual orientation, having responsibility for dependents, age, religion/beliefs, or any other reason which cannot be shown to be justified.
Senior Vulnerability Engineer employer: World Wide Technology
Contact Detail:
World Wide Technology Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Vulnerability Engineer
✨Tip Number 1
Network with industry professionals! Attend meetups, webinars, or conferences related to vulnerability management. This way, we can get insights into the latest trends and maybe even find out about job openings before they’re advertised.
✨Tip Number 2
Showcase your skills through projects! If you’ve worked on any relevant automation or vulnerability management projects, make sure to highlight them in conversations. We want to demonstrate our hands-on experience and problem-solving abilities.
✨Tip Number 3
Prepare for interviews by practising common questions! We should focus on technical scenarios related to Tenable and ServiceNow. Mock interviews with friends or using online platforms can help us feel more confident when it’s our turn to shine.
✨Tip Number 4
Apply directly through our website! It’s often the best way to ensure your application gets noticed. Plus, we can tailor our approach based on the specific roles we’re interested in, making it easier to stand out from the crowd.
We think you need these skills to ace Senior Vulnerability Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Vulnerability Engineer role. Highlight your experience with Tenable and ServiceNow, and don’t forget to mention any relevant certifications. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about vulnerability management and how your background makes you a perfect fit for our team. Keep it concise but impactful – we love a good story!
Showcase Your Achievements: When detailing your experience, focus on specific achievements rather than just listing duties. Did you automate a process that saved time? Or improve a system's security? We want to hear about it! Numbers and outcomes speak volumes.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our awesome team at StudySmarter!
How to prepare for a job interview at World Wide Technology
✨Know Your Tools Inside Out
Make sure you’re well-versed in Tenable Security Center, Nessus, and ServiceNow Vulnerability Response. Brush up on how these tools integrate with network devices and be ready to discuss your hands-on experience with them.
✨Speak the Language of Risk
Familiarise yourself with risk-based prioritisation methods like CVSS and EPSS. Be prepared to explain how you’ve used these frameworks in past roles to make informed decisions about vulnerability management.
✨Showcase Your Automation Skills
Highlight any experience you have with automating vulnerability management processes. Discuss specific examples where you’ve implemented automation using scripting languages like Python or tools like ServiceNow Flow Designer.
✨Engage with Stakeholders
Demonstrate your ability to communicate effectively with both technical teams and senior stakeholders. Prepare examples of how you’ve successfully coordinated remediation activities and managed expectations in previous roles.