Cyber Security Vulnerability Manager

Laing O'Rourke

Dartford

On-site

GBP 90,000 - 120,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Disability Confident scheme
Reasonable adjustments during hiring

Job summary

Laing O'Rourke is seeking an experienced Cyber Security Vulnerability Manager to establish and lead an enterprise-wide vulnerability management programme across IT, cloud, OT and applications. You will identify, prioritise and remediate vulnerabilities and report to senior stakeholders to enable informed cyber risk decisions.

This role offers the chance to shape security across a leading engineering and construction business with a focus on robust governance, ISO 27001 alignment, and

Qualifications

  • Proven experience developing and implementing vulnerability management programmes in a large enterprise.
  • Experience using vulnerability scanning technologies across IT, cloud, and OT environments.
  • Knowledge of threat intelligence and risk-based prioritisation models.
  • Strong analytical and problem-solving skills with the ability to translate vulnerabilities into business actions.

Responsibilities

  • Design and lead an enterprise-wide vulnerability management programme across IT, cloud, OT and applications.
  • Prioritise vulnerabilities by business risk and ensure remediation within SLAs.
  • Coordinate and conduct vulnerability assessments across infrastructure, cloud services, apps, and manufacturing environments.
  • Collaborate with technology teams to agree proportionate remediations and controls.
  • Improve automation of vulnerability workflows and reporting to senior stakeholders.
  • Develop and maintain vulnerability management frameworks, policies and standards.
  • Support compliance with ISO 27001, Cyber Essentials Plus and other requirements.

Skills

Vulnerability management
Threat-based prioritisation
Vulnerability scanning
Stakeholder communication
ISO 27001 knowledge
Cyber risk

Tools

Qualys
Nessus

Job description

Help shape a resilient, risk-led cyber security environment at Laing O'Rourke.

We are looking for an experienced Cyber Security Vulnerability Manager to establish and lead an enterprise-wide vulnerability management programme. This is an opportunity to influence how vulnerabilities are identified, prioritised and resolved across a complex technology landscape, while helping colleagues make clear, informed decisions about cyber risk.

Laing O'Rourke's IT function has renewed its strategy to support the company's ambition to transform the construction industry, making it more sustainable, more productive, and fit for the future.

Technology has a critical role to play in achieving this ambition. Our focus is on applying digital capability in ways that genuinely matter, shaping how complex projects are delivered, how decisions are made, and how innovation improves outcomes for people, communities, and the environment.

Our mission is clear: to create a modern and resilient technology environment where trusted data informs every decision, AI enhances every process, and digital capability enables the organisation to operate with greater scale and productivity.

To deliver this, we are building a different kind of IT function, one that is trusted by the business, forward looking in its thinking, and deeply connected to operational outcomes. We are looking for individuals who are curious, thoughtful, and motivated by contributing to work that has real industry impact.

The Role

As Cyber Security Vulnerability Manager, you will develop, implement and continually improve Laing O'Rourke's vulnerability management capability across IT, cloud, operational technology and application environments.

You will provide clear oversight of security vulnerabilities and ensure they are prioritised according to business risk, addressed within agreed service levels and reported effectively to senior stakeholders. Through practical guidance and collaborative working, you will help strengthen security, support regulatory compliance and enable informed decision-making across the organisation.

Key Responsibilities
  • Design, implement and evolve an enterprise-wide vulnerability management strategy and programme covering discovery, assessment, risk prioritisation, remediation, validation and reporting.
  • Conduct and coordinate vulnerability assessments across IT infrastructure, cloud services, applications, software development and manufacturing environments.
  • Work collaboratively with technology colleagues to agree proportionate remediations, mitigations and compensating controls.
  • Improve the automation of vulnerability management workflows and support the continued development of the organisation's cyber security capability.
  • Establish clear measures and reporting that provide visibility of vulnerabilities, remediation progress and business risk.
  • Collaborate with Cyber Security Governance, Risk and Compliance colleagues to improve security across the supply chain and third-party providers.
  • Develop vulnerability management frameworks, policies and standards that support compliance with ISO 27001, Cyber Essentials Plus, Essential Eight and other relevant requirements.
  • Help improve mean time to detect and mean time to remediate while balancing cyber risk with operational availability.
  • Build trusted relationships with stakeholders, positioning cyber security as a practical enabler of the business.
Essential Requirements
  • Proven experience developing and implementing cyber security vulnerability management programmes within a large enterprise environment.
  • Practical experience using vulnerability scanning technologies across cloud, hybrid and complex technology environments.
  • Knowledge of threat intelligence and risk-based vulnerability prioritisation models.
  • Strong analytical and problem-solving skills, with the judgement to recommend practical and proportionate responses to risk.
  • The ability to translate technical vulnerabilities, security risks and compliance requirements into clear, business-relevant information.
  • Effective stakeholder management and communication skills, with experience working collaboratively across technical and non-technical teams.
  • The ability to work independently, remain accountable for outcomes and guide remediation activity through to completion.
Desirable Requirements
  • A relevant professional certification, such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP) or Certified Cloud Security Professional (CCSP).
  • Experience working across multidisciplinary teams within a complex organisational environment.
What Makes This Role Compelling?

You will have the opportunity to build and shape a vulnerability management programme with broad organisational reach. Your work will improve visibility of cyber risk, support faster and more effective remediation, and help protect technology environments that are central to the delivery of complex engineering and construction projects.

This role offers a balance of strategy, technical insight and stakeholder influence, providing the opportunity to make a visible contribution to Laing O'Rourke's future security and resilience.

About Laing O'Rourke

Laing O'Rourke is an international engineering and construction business known for pushing boundaries in digital engineering, modern methods of construction and sustainable delivery. With more than 150 years of heritage, we are committed to creating environments in which diverse teams can excel and thrive.

Accessibility & Inclusion

We are proud to be part of the Disability Confident scheme. If you meet the essential criteria and would like to be considered through our Offer an Interview scheme, please let us know. We're also happy to provide reasonable adjustments throughout the recruitment process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Vulnerability Manager
Cyber Security Vulnerability Manager

ENGINEERINGUK • Dartford

On-site
GBP 90,000 - 120,000
Cyber Security - Manufacturing Technology Engineer
Cyber Security - Manufacturing Technology Engineer

Laing O'Rourke • Dartford

On-site
GBP 65,000 - 90,000
Cyber Security Identity & Access Manager
Cyber Security Identity & Access Manager

ENGINEERINGUK • Dartford

On-site
GBP 90,000 - 120,000
Cyber Security Identity & Access Manager
Cyber Security Identity & Access Manager

Laing O'Rourke • Dartford

On-site
GBP 70,000 - 110,000
Cyber Security - Manufacturing Technology Engineer
Cyber Security - Manufacturing Technology Engineer

ENGINEERINGUK • Dartford

On-site
GBP 60,000 - 78,000
Enterprise Cyber Vulnerability Lead
Enterprise Cyber Vulnerability Lead

ENGINEERINGUK • Dartford

On-site
GBP 90,000 - 120,000
Enterprise Cyber Risk & Vulnerability Manager
Enterprise Cyber Risk & Vulnerability Manager

Laing O'Rourke • Dartford

Remote
GBP 90,000 - 120,000
Disability Confident scheme
Reasonable adjustments during hiring
Digital Manager - Data & Reporting
Digital Manager - Data & Reporting

Laing O'Rourke • Ipswich

Hybrid
GBP 70,000 - 90,000
Hybrid work arrangements
Travel & mobility support
Vulnerability Management Lead
Vulnerability Management Lead

RS UK & Ireland • Corby

On-site
GBP 60,000 - 90,000
Project Information Manager - Oxford
Project Information Manager - Oxford

Laing O'Rourke • Oxford

On-site
GBP 60,000 - 90,000