Vulnerability Management Analyst

Inspired Thinking Group

Birmingham

On-site

GBP 52,000 - 86,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Work from home
25 Days Holidays + Bank Holidays
Wellbeing program
Tech: Cutting-edge technology
Discounts

Job summary

Inspired Thinking Group is seeking a Vulnerability Management Analyst to join our information security and data protection team. The role focuses on identifying, prioritising, and remediating security vulnerabilities across our global product estate.

You will configure vulnerability tools, assess risk, and drive fixes in collaboration with developers and engineers. The role requires hands-on experience with SAST/DAST/IVS, and a proactive security mindset.

Qualifications

  • 2+ years in vulnerability management or related security role.
  • Experience with vulnerability scanning tools and remediation.
  • Familiarity with OWASP Top 10 and MITRE ATT&CK.
  • Ability to read code and scripts.

Responsibilities

  • Configure and tune vulnerability tools across scanning and CI/CD.
  • Risk-assess findings by severity and business impact.
  • Triage, validate, and coordinate remediation with developers.
  • Produce regular security reports and metrics.
  • Engage with external testing providers and manage engagements.

Skills

Vulnerability management
Security operations
Scripting basics
Threat intelligence
OWASP Top 10

Tools

SAST
DAST
SCA
CSPM
IVS

Job description

  • We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team
  • This is an ideal opportunity for someone with real-world experience in information security and data protection
  • It’s a great opportunity to get hands‑on with the tools and processes that keep all our products secure, and to make a genuinely visible difference to how we manage risk day to day
  • The Vulnerability Management Analyst will help us find, prioritise, and fix security vulnerabilities across our global business and all our products
  • You’ll configure and tune our vulnerability tools, risk assessing detections, and prioritising findings for fix
  • . You’ll cover code vulnerabilities (SAST, DAST, SCA, OSS licencing), Cloud Security Posture Management (CSPM), Internal Vulnerability Scanning (IVS), and penetration testing
  • You’ll also help design and report on our detection and remediation activities. This is a full-time position
  • Occasional after-hours work may be required for incident response or urgent security tasks. Successful candidates will be enrolled on a fully funded training pathway and will be provided with mentoring support to help them grow and learn
  • Help configure, tune, and maintain our vulnerability tooling across scanning tools, working with platform and engineering teams to keep coverage accurate
  • Support day-to-day scanning schedules and tooling integrations, including ticketing and CI/CD pipelines
  • Look for opportunities to automate reporting, validation, and other repetitive tasks across the whole vulnerability lifecycle
  • Triage findings from vulnerability sources, confirming genuine issues and filtering out false positives
  • Risk-assess confirmed findings against severity, exploitability, and business context, to prioritise fixes
  • Apply a consistent risk-scoring approach so findings are prioritised effectively, regardless of source
  • Stay on top of current threats and trends (e.g. threat actors, new vulnerabilities etc.) to inform vulnerability management activities
  • Develop and maintain secure configuration benchmarks and hardening guidelines for our software, infrastructure, and tooling
  • Align benchmarks and guidelines to recognised industry frameworks for business
  • Work with the right teams to help implement the secure configurations, providing practical advice, and facilitating deviations within our broader risk management framework
  • Act as a primary contact point for Developers and Engineers to help them understand and fix issues
  • Track remediation progress, chase owners on overdue items, escalat where necessary
  • Support teams with practical remediation guidance, drawing on the OWASP Top 10, the Mitre Att&ck Framework, and our secure coding standards
  • Organise our externally delivered IVS and Penetration Testing programmes, from scheduling and scoping, through to day-to-day contact with our testing partners
  • Help manage our relationships with testing providers, including engagement administration and reporting
  • Help design and report on remediation SLAs across vulnerability classes, severities, and products
  • Produce regular reporting (monthly, quarterly, and ad-hoc) on SLA performance, open findings, and trends
  • Feed data and insight into our wider security metrics and reporting processes
  • Suggest ways to improve how we manage vulnerabilities and the tools we use to do it
  • Support the rollout of new scanning tools or process changes across our global product estate
  • Help create and maintain our vulnerability management policies, standards, and procedures
Benefits
  • Work from home
  • 25 Days Holidays + Bank Holidays
  • Wellbeing at ITG: From employee Wellbeing Days to company-wide initiatives, your wellbeing is our top priority
  • Tech: Our cutting-edge technology empowers people to be their creative best
  • Discounts: Save money with some of the biggest brands around
  • Enhanced Sick Pay: For when you’re not quite feeling yourself
  • Health Insurance
  • Referral Programme
  • Welcome Packs

Comfortable working across a global, multi-product environmentRelevant certifications (e.g. CompTIA Security+, CompTIA CySA+, GIAC GFACT/GPEN, or CEH) are preferred but not essentialComfortable working within an agile enterprise environmentAbility to work autonomously, use good judgement, and know when to escapeOrganised enough to manage several scanning programmes, testing engagements, and remediation workstreams in parallelComfortable explaining technical findings to both Developers and non-technical stakeholdersComfortable coordinating third-party engagements, such as scheduling and scoping penetration testsAbility to read and understand common coding languages is essential, the ability to write scripts and/or code is preferredExperience triaging and risk-assessing security findings, helping teams to prioritise remediation based on severity and business impact2+ years’ experience in vulnerability management, security operations, development, or a related security/IT roleHands-on experience with vulnerability scanning and management tooling (e.g. SAST, DAST, SCA, CSPM, or IVS)Solid understanding of common vulnerability types and remediation approaches, including familiarity with the Mitre ATT&CK Framework and OWASP Top 10Strong analytical and problem-solving mindset, with real attention to detail

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Analyst
Vulnerability Analyst

Computacenter • England

On-site
GBP 45,000 - 60,000
Senior Analyst - Vulnerability Management (Contract)
Senior Analyst - Vulnerability Management (Contract)

GCS • Greater London

Hybrid
GBP 65,000 - 85,000
Information Security Analyst, Vulnerability Management
Information Security Analyst, Vulnerability Management

bet365 • Burslem

Hybrid
GBP 45,000 - 65,000
Senior IT Security Analyst
Senior IT Security Analyst

Cyber UK • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid working
Personal pension plan
Private medical & dental insurance
+1
Vulnerability Management Engineer
Vulnerability Management Engineer

Opus Recruitment Solutions • United Kingdom

Remote
GBP 50,000
Travel and food expenses fully reimbursed
Information Security Vulnerability Management Analyst
Information Security Vulnerability Management Analyst

JCB • Rocester

On-site
GBP 50,000 - 70,000
Company pension
On-site gym
In-house doctor
+6
Penetration Tester
Penetration Tester

Big Red Recruitment • Greater London

On-site
GBP 45,000 - 75,000
Vulnerability Manager
Vulnerability Manager

The Very Group • Liverpool

On-site
GBP 60,000 - 80,000
Flexible working model
30 days holiday + bank holidays
£1000 flexible benefits allowance
+2
Penetration Tester - Vulnerability Researcher
Penetration Tester - Vulnerability Researcher

Thales Group • Oxford

On-site
GBP 60,000 - 90,000
Performance-related bonus
Private healthcare
Pension scheme
+2
Penetration Tester - Vulnerability Researcher
Penetration Tester - Vulnerability Researcher

Thales Group • Templecombe

On-site
GBP 60,000 - 90,000
Performance-related bonus
Private healthcare
Pension scheme
+3