Vulnerability Management Analyst

  • Up to £47,000 + benefits
  • Preston (Hybrid – 2 days per week onsite)

Finding a vulnerability is only the beginning. The real challenge is making sure somebody fixes it.

We’re looking for a Vulnerability Management Analyst to join a growing cyber security team supporting a major client programme. You’ll take identified vulnerabilities and help drive them through prioritisation, remediation and closure — working with suppliers and technical teams to ensure nothing important is overlooked or left unresolved.

This isn’t a Penetration Tester role, and you won’t spend your days running vulnerability scans. It’s ideal for someone working as a Vulnerability Analyst, Vulnerability Remediation Analyst, Cyber Security Analyst, Security Governance Analyst or Vulnerability Management Coordinator who is comfortable combining cyber knowledge with reporting, organisation and plenty of stakeholder engagement.

What you’ll be doing

  • Tracking vulnerabilities from identification through to remediation and closure
  • Working with suppliers and technical owners to agree actions and timescales
  • Prioritising issues using severity, CVSS scores, risk ratings and remediation SLAs
  • Escalating high-risk, overdue or repeatedly unresolved vulnerabilities
  • Producing dashboards and reports covering vulnerability ageing, trends and SLA performance
  • Maintaining accurate records and audit-ready evidence
  • Supporting security governance, assurance and risk-exception processes
  • Helping improve the effectiveness of the wider vulnerability management service

What we’re looking for

  • Previous experience within vulnerability management, cyber security, information security or security governance
  • Experience coordinating or tracking vulnerability remediation
  • A good understanding of CVSS, vulnerability severity, risk ratings and remediation processes
  • Familiarity with tools such as Qualys, Tenable, Brinqa, Rapid7 InsightVM or similar
  • Strong reporting, data interpretation and documentation skills
  • Confidence engaging suppliers and technical stakeholders, and following actions through to completion
  • Experience working within a structured, regulated or multi-supplier environment would be particularly useful
  • Vulnerability management or security qualifications would be advantageous

Location and security requirements

You’ll work on a hybrid basis, attending the client site in Preston two to three days per week.

Due to the security requirements of the programme, applicants must:

  • Be a sole UK citizen (no dual nationals)
  • Be eligible to obtain Security Check clearance (SC)
  • Have lived continuously in the UK for the past five years

Salary and benefits

  • Up to £47,000
  • Excellent corporate benefits package
  • Permanent

There are several positions available, making this a great opportunity to join an expanding team and build your career within a large, established cyber security environment.

If you understand vulnerabilities but are equally good at working with people, keeping track of actions and making sure risks are properly resolved, we’d love to hear from you

Apply for this role:

    Advertised by:

    Alisa De Faria

    Principal Delivery Consultant

    Alisa De Faria

    With over 20 years of experience, I specialise in IT and business change recruitment, providing tailored solutions for clients and candidates primarily across the Information Technology and Financial Services sectors. My expertise spans client management, relationship building, search assignments, and effective communication, enabling me to deliver high-quality services for permanent and contract roles.

    Connect with Alisa De Faria