Enable job alerts via email!

Lead Secops Consultant - Vulnerability Management

Fruition Group

United Kingdom

Remote

GBP 60,000 - 80,000

Full time

Yesterday
Be an early applicant

Job summary

A leading financial services provider in the UK is seeking a Lead SecOps Consultant for Vulnerability Management Transformation. The role involves building a proactive vulnerability management strategy, ensuring compliance with regulations, and integrating security into engineering processes. Ideal candidates will have at least 7 years of experience in security engineering, a background in financial services, and hands-on knowledge of vulnerability scanning tools. This position offers remote work with occasional site travel and a competitive contract rate.

Qualifications

  • 7+ years in security engineering with 3 years leading vulnerability management programs.
  • Deep understanding of PCI-DSS requirements and financial services security standards.
  • Experience with vulnerability scanning tools and security automation.

Responsibilities

  • Conduct a comprehensive current state assessment for vulnerability management.
  • Evaluate and implement the optimal mix of vulnerability management tools.
  • Develop vulnerability scoring mechanisms incorporating business risk.
  • Integrate vulnerability management into CI/CD pipelines.

Skills

Security engineering
Vulnerability management
Technical communication
Strategic vision
DevOps
Compliance knowledge

Tools

Tenable
DAST tools
Job description
Overview

Role: Lead SecOps Consultant - Vulnerability Management Transformation

Location: UK remote with occasional site travel

Contract: Competitive market rate

Contract length: 6 months with strong chance of extension

Enablis are working with a leading financial services provider who are looking for a Lead SecOps Consultant to transform their vulnerability management capabilities. This is a critical role requiring both strategic vision and hands-on technical expertise to build a best-in-class vulnerability management programme.

The Opportunity:

You'll be joining an organisation that provides banking platform services to multiple companies, where vulnerability management has become fragmented across teams. They need someone who can move them from reactive incident-based responses to a proactive, engineering-led security approach that meets stringent financial services compliance requirements.

What you'll do
  • Assess & Transform: Conduct comprehensive current state assessment and design a unified vulnerability management strategy that brings consistency across platform, mobile, web, and Back End teams
  • Tool Selection & Implementation: Evaluate, select and implement the optimal blend of commercial and custom vulnerability management tools, including DAST capabilities to complement existing SAST
  • Build Context-Driven Processes: Develop sophisticated vulnerability scoring mechanisms that go beyond standard CVSS to incorporate internal threat context and business risk
  • Embed Engineering Excellence: Champion a \"security as engineering\" mindset, integrating vulnerability management into CI/CD pipelines and development workflows
  • Drive Compliance: Ensure all processes meet PCI-DSS, 3DS, SOC2, and ISO requirements with robust audit trails and evidence collection
  • Enable Teams: Create frameworks and playbooks that empower engineering teams to resolve vulnerabilities efficiently, particularly through dependency management
What you'll bring
  • Proven Track Record: 7+ years in security engineering with at least 3 years leading vulnerability management programmes in regulated environments
  • Financial Services Experience: Deep understanding of PCI-DSS requirements, authenticated scanning, and financial services security standards
  • Technical Depth: Hands-on experience with vulnerability scanning tools (Tenable preferred), SAST/DAST implementation, and security automation
  • Engineering Mindset: Background in software engineering or DevOps with ability to work closely with development teams and understand their workflows
  • Strategic Vision: Ability to design and implement enterprise-wide vulnerability management strategies while maintaining focus on practical delivery
  • Communication Excellence: Capability to influence stakeholders from engineers to executives, translating technical risks into business impact
Key deliverables
  • Comprehensive vulnerability management strategy and roadmap
  • Tool architecture design and implementation plan
  • Risk-based vulnerability scoring framework
  • Process documentation meeting audit requirements
  • Knowledge transfer and team enablement

This role offers the opportunity to make a significant impact on the security posture of a critical financial services provider while working with cutting-edge security technologies and talented engineering teams.

We're an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, marital status, or disability status.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.