Job Search and Career Advice Platform

Enable job alerts via email!

CISO Vulnerability Manager

Barclays

Knutsford

On-site

GBP 70,000 - 90,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A major global financial institution is seeking a CISO Vulnerability Manager to drive the identification and remediation of cyber vulnerabilities across the organization. The role requires a strong understanding of risk management and cyber security threats, alongside excellent communication skills. The ideal candidate will have relevant qualifications and experience in information security. This position is based in Knutsford.

Qualifications

  • Experience in cyber security roles and threat detection and remediation.
  • Proven track record in risk management and controls.

Responsibilities

  • Identify and assess cyber vulnerabilities using a risk-based approach.
  • Develop policies and procedures for the vulnerability management program.
  • Communicate findings and recommendations to stakeholders.

Skills

Data evaluation and reporting
Risk Management
Understanding of cyber security threats
Excellent communication

Education

Qualification in Information Security (CISA, CISM, CISSP, ISO27001)

Tools

Microsoft Desktop / Server
UNIX/LINUX
Database
Networks
Middleware
Job description
Job Description
Purpose of the role

To keep our customers, clients, and colleagues safe by identifying cyber‑vulnerabilities across the Bank, using a risk‑based approach to prioritise them, and to drive effective remediation activity.

Accountabilities
  • Allocation of the correct risk rating and remediation prioritisation to a vulnerability based on industry standards for assessment, available threat intelligence concerning exploitation, the reachability of the host (or asset) and the value of the service(s) running on the impacted host.
  • Development of vulnerability management operating model, policies and procedures to ensure consistency in vulnerability identification, remediation and reporting. Element owner of the Vulnerability Management Standard including Issues Management and Regulatory alignment.
  • Communication of vulnerabilities to relevant parties including senior stakeholders, vendors, external security partners and affected business units using reports and dashboards and provide recommendations for improvement in vulnerability management practices.
  • Collaboration with Threat intelligence and Cyber Operations teams to assess and contextualise exposure to latest threat trends and exploits and set appropriate remediation timescales.
  • Definition of requirements and acceptance criteria for the implementation and maintenance of automation tools to streamline vulnerability management processes within operating systems and applications.
  • Reporting of remediation status of Security Assurance Specialist team findings against Key Risk Indicators.
Assistant Vice President Expectations
  • To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/ business divisions.
  • Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes.
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others.
  • OR for an individual contributor, they will lead collaborative assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will identify new directions for assignments and/ or projects, identifying a combination of cross‑functional methodologies or practices to meet required outcomes.
  • Consult on complex issues; providing advice to People Leaders to support the resolution of escalated issues.
  • Identify ways to mitigate risk and developing new policies/procedures in support of the control and governance agenda.
  • Take ownership for managing risk and strengthening controls in relation to the work done.
  • Perform work that is closely related to that of other areas, which requires understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub‑function.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategy.
  • Engage in complex analysis of data from multiple sources of information, internal and external sources such as procedures and practises (in other areas, teams, companies, etc.) to solve problems creatively and effectively.
  • Communicate complex information. ‘Complex’ information could include sensitive information or information that is difficult to communicate because of its content or its audience.
  • Influence or convince stakeholders to achieve outcomes.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.

Embark on a transformative journey as a CISO Vulnerability Manager at Barclays

Our vision is clear – To provide a primary liaison service between the business, technology, and security functions. To ensure the confidentiality, integrity and availability of information, and support the mitigation of security risk.

To be successful as a Vulnerability Manager, you should have experience with:
  • Data evaluation and reporting
  • Risk Management
  • Understanding of cyber security threats and the tools used to detect and remediate them
Some other highly valued skills may include:
  • Technical support experience of one or more of the following. Microsoft Desktop / Server, UNIX/LINUX, Database, Networks, Middleware.
  • Excellent communication
  • Qualification in an Information Security related discipline. CISA, CISM, CISSP, ISO27001 or equivalent.

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills.

The location of your role is Knutsford.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.