Description
Vulnerability Management Service Lead
Location: Preston OR Inverness (Hybrid Working)
Salary: £75,000 + Bonus + Benefits
Security Clearance: Eligible for SC Clearance Required (SOLE BRITISH NATIONAL)
Lead Enterprise Vulnerability Management in a Complex, Security-Critical Environment
We're seeking an experienced Vulnerability Management Service Lead to take ownership of a mature vulnerability management capability within a highly regulated enterprise environment.
This is an opportunity to play a critical role in protecting business-critical systems by driving governance, risk reduction, supplier accountability, and continuous improvement across a large-scale security operation. You'll work closely with senior stakeholders, security teams, and delivery partners to ensure vulnerabilities are effectively identified, prioritised, remediated, and reported across the organisation.
If you're passionate about cyber risk management, security governance, and influencing positive security outcomes at scale, we'd love to hear from you.
The Role
As the Vulnerability Management Service Lead, you will be responsible for owning and governing the end-to-end vulnerability management framework, ensuring effective risk management across complex technology estates.
Key responsibilities include:
Leading the enterprise vulnerability management service and governance framework
Driving vulnerability remediation activities through internal teams and third-party suppliers
Establishing and maintaining vulnerability reporting, metrics, KPIs and executive dashboards
Prioritising vulnerabilities using risk-based methodologies including CVSS, EPSS, Known Exploited Vulnerabilities (KEV), and business criticality
Managing exception processes, remediation timelines, and security risk governance
Providing assurance, oversight, and challenge across a multi-supplier service environment
Presenting vulnerability trends, risk exposure, and remediation performance to senior stakeholders
Ensuring audit readiness, evidence management, and compliance alignment
Identifying opportunities for process improvement, automation, and service maturity enhancement
What We're Looking For
Essential Experience
Significant experience in Vulnerability Management, Cyber Security Governance, GRC, or Security Operations Governance roles
Strong understanding of the end-to-end vulnerability management lifecycle
Experience implementing and governing risk-based remediation programmes
Proven ability to work across complex enterprise environments and multiple delivery partners
Strong stakeholder management skills with the ability to influence technical and non-technical audiences
Experience producing executive-level reporting and communicating cyber risk to senior leadership
Knowledge of recognised security frameworks and standards such as:
NIST Cyber Security Framework
ISO 27001
NCSC guidance
Secure by Design principles
Desirable Experience
Hands-on experience with vulnerability management platforms such as:
Tenable
Qualys
Brinqa
Experience working within defence, government, public sector, or other highly regulated environments
Relevant cyber security certifications
Working Arrangement
This is a hybrid position requiring onsite attendance in either Preston or Inverness approximately two days per week, with flexibility depending on business requirements.
What's on Offer
The opportunity to lead a critical cyber security function within a large-scale enterprise environment
Exposure to complex and high-profile technology estates
Ongoing professional development and training opportunities
Access to experienced cyber security professionals across governance, operations, engineering, architecture, and compliance disciplines
Flexible and hybrid working arrangements
Comprehensive benefits package
Long-term career progression within a growing cyber security practice
Security Requirements
Due to the nature of the work, successful applicants will be required to undergo pre-employment screening and must be eligible to obtain Security Check (SC) Clearance. Applicants will typically need to have resided continuously in the UK for the previous five years.
Apply Now
If you're an experienced cyber security professional with a strong background in vulnerability management, governance, and risk reduction, we'd love to hear from you.
Join a team where you'll have genuine influence over cyber security strategy, risk management, and the protection of critical services
Job Details
| Location |
Preston, Lancashire |
| Job Type |
Permanent |
| Language |
English |
| Salary |
£70000 - £75000/annum + perm benefits+bonus |