Senior Vulnerability Management Engineer

HCLTech

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Vacation per year
Term life insurance
Business travel insurance

Job summary

HCLTech is seeking a Senior Vulnerability Management Engineer in London with 3–6 years of VM/information security experience. You will own the end-to-end VM programme across endpoints, servers, network devices, and apps, tuning scanners, prioritising risks, integrating with patch management and SOC functions, and driving automation across the stack.

Responsibilities include defining VM SLA, leading risk acceptance, and delivering monthly dashboards for CISO leadership.

Qualifications

  • 3–6 years in vulnerability management / information security.
  • Experience with enterprise vulnerability management tools and security operations.
  • Ability to translate vulnerabilities into remediation actions for multiple teams.

Responsibilities

  • Own and operate the enterprise vulnerability management programme across all domains.
  • Design and maintain scan policies and schedules in VM tools.
  • Perform risk-based vulnerability prioritisation with CVSS, asset criticality and threat intel.
  • Translate findings into remediation tasks for patch management teams.
  • Define and enforce VM SLA policies and incident communication.
  • Lead risk acceptance processes with compensating controls and sign-off.
  • Integrate VM tooling with SIEM, ITSM, and CMDB for automation.
  • Automate reporting and remediation tracking via Python and REST APIs.
  • Monitor threat intel feeds and coordinate emergency patching for zero-days.
  • Oversee web app VM management and cloud vulnerability posture.
  • Produce monthly VM dashboards for leadership review.

Skills

Risk communication
Programme management
Analytical mindset
Collaborative
Threat intelligence awareness
Documentation

Tools

Qualys VMDR
Tenable Security Centre/InsightVM
Rapid7 InsightVM
Burp Suite Pro
OWASP ZAP
HCL AppScan
Burp/ZAAP Web App Scanning
AWS Inspector
Microsoft Defender for Cloud
Prisma Cloud
Snyk
Trivy
ServiceNow VR module
Splunk
Microsoft Sentinel
ServiceNow CMDB
Python scripting

Job description

We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products.

HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here. We’ve always approached our work with an idea-first attitude because every one of our accomplishments —no matter how big or small —can be traced back to an idea’s single spark.

It’s that spark —that inner drive —that sets our people apart from our competitors. It enables us not just to pull off game-changing feat after game-changing feat but to better our world in the process. We want you to find your spark. Because that’s what drives you to be better, be more and ultimately, be more fulfilled.

To learn more about how we can supercharge progress for you, visit www.hcltech.com

Job Title: Senior Vulnerability Management Engineer

Location: London, UK (Hybrid mode at client location)

Experience: 3 – 6 years in vulnerability management / information security

ROLE SUMMARY

The L2 Senior Vulnerability Management Engineer owns the organisation's end-to-end vulnerability management programme, spanning EUC, Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement of the VM programme.

KEY RESPONSIBILITIES
  • Own and operate the enterprise vulnerability management programme across all technology domains (endpoints, servers, network devices, web applications, cloud).
  • Design and maintain scan policies, asset groups, and scanning schedules in Qualys VMDR / Tenable Security Centre / Rapid7 InsightVM to ensure full coverage.
  • Perform risk-based vulnerability prioritisation: correlate CVSS scores with asset criticality, exposure, threat intelligence (EPSS, CISA KEV), and business context.
  • Translate vulnerability findings into actionable remediation tasks for patch management teams across EUC, Data Center, Networks, and Application Infra; define acceptance criteria for closure.
  • Define, publish, and enforce the VM SLA policy; elevate breaches to asset owners and management.
  • Lead the vulnerability exception and risk acceptance process: assess compensating controls, document residual risk, and obtain formal sign-off.
  • Integrate VM tooling with SIEM (Splunk, Microsoft Sentinel), ITSM (ServiceNow VR module), and CMDB for automated ticket creation and asset correlation.
  • Automate vulnerability reporting and remediation tracking using Python, REST APIs (Qualys/Tenable API), or ServiceNow workflows.
  • Conduct threat-informed vulnerability analysis: monitor NVD, CISA KEV, vendor security advisories, and threat intelligence feeds to identify exploitable CVEs requiring emergency response.
  • Lead response to zero-day vulnerabilities: assess impact across the estate, co-ordinate emergency patching or compensating controls, and communicate status to security leadership.
  • Own web application vulnerability management: integrate DAST/SAST findings (Burp Suite, Checkmarx, Veracode) into the unified VM programme.
  • Manage cloud vulnerability posture: AWS Inspector, Microsoft Defender for Cloud, or Prisma Cloud for hybrid cloud environments.
  • Produce monthly VM programme dashboards, KPIs, and trend analysis for CISO and management review.
  • Act as L2 escalation for L1 analysts; mentor team members and review scan configurations and reports.
  • Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence.
TECHNICAL SKILLS & KNOWLEDGE
  • Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre / Tenable.io, or Rapid7 InsightVM.
  • Strong understanding of CVE/CVSS v3.1 scoring, EPSS (Exploit Prediction Scoring), and CISA Known Exploited Vulnerabilities (KEV) catalogue.
  • Experience with web application scanning: Burp Suite Pro, OWASP ZAP, Tenable Web App Scanning, or HCL AppScan.
  • Cloud security posture: AWS Inspector, Microsoft Defender for Cloud, Prisma Cloud, or Wiz.
  • Container and image vulnerability scanning: Trivy, Snyk, Anchore, or Aqua Security.
  • Automation and API integration: Python scripting, REST API calls to Qualys/Tenable/Rapid7; ServiceNow VR module configuration.
  • SIEM integration: Splunk, Microsoft Sentinel – correlating vulnerability data with threat events.
  • CMDB-driven asset correlation: ServiceNow CMDB, ensuring VM data reflects accurate asset inventory.
  • Network and infrastructure knowledge sufficient to assess vulnerability exploitability (firewall rules, segmentation, exposure).
  • Patch management workflow knowledge across Windows (SCCM/Intune), Linux (Satellite/Ansible), and network devices – to drive effective remediation co-ordination.
  • Threat intelligence: experience consuming TI feeds (MISP, OpenCTI, commercial TI platforms) to contextualise vulnerabilities.
  • Familiarity with compliance frameworks: ISO 27001, NIST CSF, CIS Controls, PCI DSS, SOC 2 – as they relate to vulnerability management.
SOFT SKILLS & COMPETENCIES
  • Strong risk communication skills – translates technical vulnerability data into business risk language for senior stakeholders.
  • Excellent programme management skills to co-ordinate remediation across multiple infrastructure teams.
  • Analytical and data-driven – builds metrics and trends to demonstrate programme maturity.
  • Collaborative – works effectively with patch teams, SOC analysts, application owners, and compliance.
  • Proactive threat awareness – stays current with the evolving CVE landscape and emerging exploits.
  • Clear and structured documentation – programme policies, exception records, and executive reports.
PREFERRED CERTIFICATIONS
  • Qualys Certified Specialist – VMDR / TruRisk
  • Tenable Certified Security Engineer (TCSE)
  • Certified Information Systems Security Professional (CISSP) – or working towards
  • Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP)
  • CompTIA CySA+ or PenTest+
  • GIAC Vulnerability Assessor (GEVA)
  • Microsoft Certified: Security Operations Analyst (SC-200) – advantageous for Azure environments
  • ITIL 4 Foundation or Managing Professional
Benefits
  • A supportive, diverse, and global team with a brilliant culture.
  • Competitive compensation and benefits that includes vacation per year, various insurances like Term life and Business Travel insurance. These are apart from the statutory benefits applicable in the country. Employee benefits are regulated by an internal policy that contains full details regarding the entitlement and conditions for the benefits as per the law of the land.
  • Great opportunities to make the role your own, upskill yourself and get involved with exciting projects.
  • Total Wellbeing is our focus. Alongside your professional excellence, you join the likeminded colleagues to create a larger impact within the company and society at large in your chosen area of passion - CSR Council, Diversity Council, Women Connect, Sparks – Engagement Champion to name a few.
  • To know more about us visit – www.hcltech.com
  • For more information on how we process your personal data, please refer to HCLTech’s Candidate Data Privacy Notice.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

HCLTech • Birmingham

Hybrid
GBP 60,000 - 90,000
Competitive compensation
Insurance packages
Professional growth
+2
Security Analyst
Security Analyst

HCLTech • Nechells

Hybrid
GBP 75,000 - 110,000
Competitive compensation
Insurance benefits
CSR initiatives
End User Technology Compliance & Security Lead
End User Technology Compliance & Security Lead

HCLTech • Birmingham

On-site
GBP 60,000 - 90,000
Vacation 20 days
Term life insurance
Business travel insurance
+1
Senior Patch Management Engineer
Senior Patch Management Engineer

HCLTech • Slough

Hybrid
GBP 70,000 - 110,000
Vacation benefit
Insurance coverage
Global team
Senior Patch Management Engineer
Senior Patch Management Engineer

HCLTech • Greater London

Hybrid
GBP 70,000 - 110,000
Vacation allowance
Insurance (Term life, business travel)
Mobile Security Engineer
Mobile Security Engineer

HCLTech • Slough

Hybrid
GBP 65,000 - 90,000
Cybersecurity Delivery Manager
Cybersecurity Delivery Manager

HCLTech • Slough

Hybrid
GBP 90,000 - 130,000
Vacation benefits
Insurance: Term life and Travel
Global team culture
+1
Cybersecurity Delivery Manager
Cybersecurity Delivery Manager

HCLTech • City Of London

Hybrid
GBP 120,000 - 180,000
Competitive compensation
Vacation per year
Term life insurance
+5
Vulnerability Analyst
Vulnerability Analyst

Computacenter • England

On-site
GBP 45,000 - 60,000
Vulnerability Management Lead
Vulnerability Management Lead

RS UK & Ireland • Corby

On-site
GBP 60,000 - 90,000