Job Search and Career Advice Platform

Enable job alerts via email!

Director, Vulnerability Management (Manchester)

Fitch Group

Manchester

Hybrid

GBP 80,000 - 100,000

Full time

2 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading risk management firm based in Manchester is seeking a Director of Vulnerability Risk to lead the Vulnerability Management team. Responsibilities include overseeing the lifecycle for vulnerability management and collaborating effectively across teams. The ideal candidate will have 7-10 years of experience in Information Security, with strong leadership skills. This position offers a hybrid work environment, focusing on continuous learning and employee wellness programs.

Benefits

Hybrid Work Environment
Dedicated trainings and mentorship programs
Retirement planning and tuition reimbursement
Comprehensive healthcare offerings
Generous parental leave plan
Paid volunteer days

Qualifications

  • Proven ability to create executive-level dashboards and reports for vulnerability metrics.
  • Experience managing remediation lifecycles through enterprise ticketing systems for vulnerability tracking.
  • Experience leveraging AI-powered security tools to improve workflows.

Responsibilities

  • Lead the end-to-end vulnerability management lifecycle.
  • Define and execute the strategic roadmap for the Unified Vulnerability Management program.
  • Govern the intake, normalization, and triage of findings from tools.

Skills

Strong leadership
Risk management
Excellent communication
Collaboration

Education

7-10 years of experience in Information Security
2+ years in Vulnerability Management

Tools

SAST
DAST
SCA
CSPM
Job description

Fitch Group is currently seeking a Director of Vulnerability Risk based out of our Manchester office.

We are seeking a Director to lead our Vulnerability Management (VM) team. This role is ideal for an experienced security leader with a risk mindset who can oversee all aspects of vulnerability management, including identification, risk prioritization, and remediation of vulnerabilities discovered. The ideal candidate for this role will bring innovative ideas on how to consistently apply risk prioritization through automation, leveraging AI where appropriate. Success will look like:

  • Application of a risk mindset with consideration for the company’s set of standing security controls
  • Ideas on opportunities to strengthen protection of our critical assets
  • Strong collaboration across the vulnerability management teams and stakeholders
  • Delivering real-time metrics reports
  • Remediation tracking aligned with organizational risk priorities

This is a new role to oversee a recently established unified vulnerability management program, covering infrastructure and cloud scanning, application security testing, and penetration testing.

How You’ll Make an Impact:
  • Define and execute the strategic roadmap the Unified Vulnerability Management program, including resource planning, performance tracking, and establishing and reporting on metrics (key performance indicators; key risk indicators; and objectives and key results) for the program.
  • Lead the end-to-end vulnerability management lifecycle using a consistent, risk-based assessment methodology that evaluates likelihood, impact, control environment and Fitch specific business context, ensuring timely remediation and compliance with internal policies.
  • Govern the intake, normalization, and triage of findings originating from tools and assessments to ensure alignment with a unified lifecycle management process
  • Manage vulnerabilities identified from scanning tools covering open source, custom source code, dynamic application scanning, static application scanning, infrastructure scanning, and cloud security posture management solutions. (SCA, SAST, DAST, infrastructure, and CSPM)
  • Provide risk informed visibility to stakeholders through clear dashboards and other reporting mechanisms which indicate remediation expectations
  • Ensure proper reporting of vulnerabilities to stakeholders and drive remediation efforts from an Information Security perspective.
  • Develop strong partnerships with engineering, application development, and infrastructure teams to ensure aligned remediation workflows and streamlined ticketing processes for opening and closing vulnerabilities.
  • Maintain and track team workload, ensuring transparency and accountability.
  • Collaborate with subject matter experts across InfoSec and Technology to contextualize findings, validate assessments, resolve ambiguity and accelerate closure without compromising risk posture.
  • Own and operationalize Fitch’s cyber risk taxonomy, threat intelligence, compensating control analysis, and architectural context to ensure findings are prioritized appropriately.
  • Perform contextual analyses for vulnerability risk prioritization based on the following criteria: the business criticality of systems to Fitch, cloud architecture details such as network segmentation and access controls, understanding of system and application architecture, and data confidentiality.
  • Produce and maintain dashboards, metrics and trend analyses that facilitate consumption of risk information and enable responses to requests for executive reporting and audit requests.
  • Deliver VM team projects on time and on budget, ensuring alignment with department goals, organizational goals, and regulatory requirements.
You May be a Good Fit if:

The ideal candidate will have 7-10 years of progressive leadership experience in Information Security, with at least 2 years in a dedicated Vulnerability Management role.

They should demonstrate strong leadership skills, experience managing vulnerabilities across SAST, DAST, SCA, infrastructure, and CSPM solutions, and excellent communication and collaboration abilities for engaging technical teams and senior stakeholders.

What Would Make You Stand Out:
  • 7+ years of progressive security experience, with at least 3+ years assessing and managing vulnerability risks for multi-cloud enterprise systems.
  • Experience applying industry frameworks and compliance standards (NIST, DORA) to apply risk classifications during the vulnerability lifecycle management process.
  • Experience producing contextual analysis for vulnerability risk prioritization based on: the business criticality of systems, cloud architecture details such as network segmentation and access controls, understanding of system and application architecture, and data confidentiality.
  • Experience coordinating management of multiple vulnerability scanning tools and managing vulnerabilities identified from scanning tools covering open source, custom source code, dynamic application scanning, static application scanning, infrastructure scanning, and cloud security posture management solutions. (SCA, SAST, DAST, infrastructure, and CSPM)
  • Experience managing remediation lifecycles through enterprise ticketing systems for vulnerability tracking and workflow automation.
  • Proven ability to create executive-level dashboards and reports for vulnerability metrics.
  • Excellent communication and collaboration skills for engaging technical teams, and senior stakeholders.

senior stakeholders.

  • Leadership and team management skills, including resource planning, OKR setting, and performance reviews.
  • Strong problem-solving skills and ability to make risk-based decisions while managing multiple projects simultaneously.
  • Experience leveraging or guiding the work to use AI-powered security tools or platforms to improve vulnerability detection and remediation workflows.
Why Choose Fitch:
  • Hybrid Work Environment: 2 to 3 days a week in office required based on your line of business and location
  • A Culture of Learning & Mobility: Dedicated trainings, leadership development and mentorship programs designed to ensure that your time at Fitch will be a continuous learning opportunity
    • Investing in Your Future: Retirement planning, financial wellness and tuition reimbursement programs that empower you to achieve your short and long-term goals
    • Promoting Health & Wellness: Comprehensive healthcare offerings that prioritize a healthy body & mind
    • Supportive Parenting Policies: Family-first policies, including a generous global parental leave plan, designed to help you balance career and family life effectively
    • Dedication to Giving Back: Paid volunteer days and support for community engagement initiatives

Fitch is proud to be an Equal Opportunity and Affidavit Action Employer. We evaluate qualified applicants without regard to race, color, national origin, religion, sex, sexual orientation, gender identity, disability, protected veteran status, and other statuses protected by law.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.