Website Home Office
Job description
The role of Vulnerability Management is to triage vulnerabilities by relevance and criticality to the organisation. Vulnerability Management then identify mitigations for those vulnerabilities and advise on implementing them.
You’ll join an expert team of cyber professionals, committed to fighting cyber-attack across a complex network of systems. You’ll be aided by a supportive organisational culture, and a commitment to further your continuous development.
Person specification
Main Responsibilities
Your main day to day responsibilities will be:
Vulnerability Identification – Lead the process of identifying and classifying technical vulnerabilities in systems, applications and networks to identify security weaknesses and potential risks. Utilise vulnerability management tools/technologies to identify, assess and report on vulnerabilities.
Risk Assessment – Analyse and evaluate the results of vulnerability scans to determine the severity and potential impact of identified vulnerabilities, categorising them based on risk to assets and operations.
Remediation Planning – Collaborate with multiple departments, technical teams and senior stakeholders to recommend remediation plans and complex configuration changes in support of vulnerability remediation.
Reporting – Create and present detailed reports on vulnerability assessments, remediation efforts, and overall vulnerability management performance for stakeholders, management and technical teams.
Incident Management – Work closely with other security teams and technical resolver groups to ensure comprehensive approach to managing prioritised vulnerabilities.
Tool management – Knowledge and understanding of approaches and tooling used to perform vulnerability assessments against large and complex infrastructure. Implementing continuous monitoring processes to identify new vulnerabilities and assess the effectiveness of remediation efforts over time.
Vulnerability Management Service – Onboard assets into the appropriate vulnerability management tooling in line with the Threat and Vulnerability Management Service. Ensure that all vulnerability management activities align with service polices, standards and procedures.
Essential Skills
You’ll have a demonstrable passion for Vulnerability Management, with the following skills or strong experience in:
Driving improvements in vulnerability management processes and practices, working with security and technology teams to deliver technical and operational change.
Conducting vulnerability assessments using recognised frameworks, understanding severity and contextualising risk within an organisational environment to support effective prioritisation.
Implementing and operating technical vulnerability management tooling, ensuring effective deployment, maintenance and use of data to identify, analyse and communicate security risk.
Managing security risk, working collaboratively with stakeholders to drive remediation and achieving good security outcomes aligned to organisational prioritises and risk appetite.
Communicating complex technical vulnerability risk clearly and effectively, producing high quality written and verbal reports tailored to technical specialists and non-technical senior stakeholders.
Coordinating effective incident response activities in fast-paced environments, engaging with cross-functional teams to triage, contain and remediate security incidents.
To apply for this job please visit www.civilservicejobs.service.gov.uk.