
Vulnerability Manager
- Daresbury, Cheshire
- Permanent
- Full-time
- Microsoft: Top 3 Service Providers, Azure Expert Status, Fastrack & Inner Circle Partner
- HPE: Platinum Partner - FY23 UK&I Solution Provider of the Year
- Fortinet: Elite VIP Program - one of only 2 in the UK
- Palo Alto & Crowdstrike: part of our NextDefense Cyber Security Portfolio
- Tenable Platform Management:
- Administer, configure, and optimize the Tenable vulnerability management platform across multiple client environments.
- Develop, schedule, and execute regular vulnerability scans (internal, external, web application, cloud, container) using Tenable products.
- Manage Tenable agents, scanners, and integrations to ensure comprehensive asset coverage and accurate data collection.
- Troubleshoot and resolve any issues related to scan execution, data ingestion, or platform performance.
- Stay abreast of new Tenable features and updates, and implement them to enhance service delivery.
- Vulnerability Identification & Analysis:
- Analyze scan results from Tenable to identify and assess security vulnerabilities across diverse client infrastructures (on-premise, cloud, endpoints, applications, networks).
- Prioritize vulnerabilities based on risk, leveraging industry-standard frameworks (CVSS), threat intelligence, asset criticality, and client-specific context.
- Conduct in-depth research on identified Common Vulnerabilities and Exposures (CVEs) and their potential impact.
- Reporting & Communication:
- Generate clear, concise, and actionable vulnerability reports and dashboards for various client stakeholders (technical, management, executive).
- Present vulnerability findings, risk assessments, and remediation recommendations to clients, clearly articulating the business impact of security weaknesses.
- Track and report on remediation progress, compliance metrics, and overall vulnerability management program effectiveness for each client.
- Remediation & Advisory:
- Work closely with client IT, operations, and development teams to provide guidance and support for vulnerability remediation efforts.
- Recommend appropriate mitigation strategies, including patching, configuration changes, architectural improvements, and compensating controls.
- Facilitate the communication and coordination between clients and internal security teams (e.g., Incident Response, Security Architecture).
- Process Improvement & Compliance:
- Develop, maintain, and continuously improve vulnerability management policies, procedures, and runbooks within the MSSP framework.
- Ensure vulnerability management processes align with industry best practices (e.g., NIST, ISO 27001, CIS Controls) and regulatory requirements (e.g., GDPR, PCI DSS).
- Contribute to internal and external audits by providing documentation and evidence related to vulnerability management.
- Threat Intelligence & Research:
- Stay current with the latest cybersecurity threats, attack techniques, and vulnerability disclosures.
- Integrate threat intelligence into vulnerability assessments to enhance prioritization and proactive defense.
- Proven Experience: Minimum of 5 years of experience in cybersecurity, with at least 3 years specifically in vulnerability management within an MSSP or large enterprise environment.
- Tenable Expertise: Deep hands-on experience with Tenable products, including Tenable.io, Tenable.sc, Nessus Professional, and Nessus Agents. Experience with Tenable One is highly desirable.
- Technical Acumen: Strong understanding of network protocols, operating systems (Windows, Linux), cloud platforms (AWS, Azure, GCP), databases, and web applications.
- Vulnerability Assessment: Proficient in interpreting vulnerability scan results, performing risk assessments, and applying vulnerability scoring systems (e.g., CVSS).
- Cybersecurity Frameworks: Familiarity with common security frameworks and standards (e.g., NIST CSF, ISO 27001, CIS Controls, OWASP Top 10).
- Analytical & Problem-Solving: Excellent analytical skills with the ability to identify trends, root causes, and develop effective solutions.
- Communication: Exceptional written and verbal communication skills, with the ability to translate complex technical information into clear, actionable insights for both technical and non-technical audiences.
- Collaboration: Proven ability to work effectively in a fast-paced, client-facing environment, collaborating with internal teams and external stakeholders.
- Certifications (Highly Desirable):
- Tenable Certifications (e.g., Tenable Certified Nessus User, Tenable Certified SC User, Tenable.io Certified Professional)
- Industry certifications such as CISSP, CISM, CompTIA Security+, CEH.
- Clearance: Ability to pass SC
- Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
- Opportunity to work with a leading global MSSP and manage cutting-edge security technologies.
- Exposure to a diverse range of client environments and industries.
- Continuous professional development and training opportunities.
- A collaborative and innovative work environment.
- Competitive salary and benefits package.