Enable job alerts via email!

Vulnerability Management Manager

ION

City Of London

On-site

GBP 80,000 - 100,000

Full time

Today
Be an early applicant

Job summary

A leading financial technology firm in London seeks a Vulnerability Management Manager to build and lead a Security team focused on vulnerability management. The role requires a strong cybersecurity background with a minimum of 10 years' experience, including senior leadership in large organizations. This position involves managing vulnerability management tools, driving improvements in security processes, and ensuring compliance with best practices.

Qualifications

  • Minimum 10 years in Vulnerability Management with at least 5 years in a senior role.
  • Strong technical expertise in vulnerability management frameworks.
  • Experience in leading global teams and building risk management frameworks.

Responsibilities

  • Lead a team of Security professionals specializing in Vulnerability Management.
  • Manage and operate vulnerability management tooling.
  • Drive improvements and changes to processes and procedures.

Skills

Team leadership
Excellent communication
Vulnerability assessments
Security policy design
Problem-solving skills

Education

Degree/diploma/certifications in technology-related field

Tools

Tenable
Rapid7
Qualys
Job description
Overview

The Role: The Vulnerability Management Manager is a global role within ION’s central services division and will support the Group Security strategy and operational excellence through the identification, mitigation and remediation of information security vulnerabilities, misconfigurations and risks to the business. This role reports to the Global Head of IT Security, who reports to the Group Chief Information Security Officer (CISO).

As a member of the ION Security team, you will build and lead a team of Security professionals specialising in Vulnerability Management along with managing the partners and technology vendor deliverables and building and owning the strategy to deliver a world class Vulnerability Management program. The candidate must understand their role in the broader vulnerability management program and your team will regularly perform discovery scanning, risk/exposure assessments, mitigation support activities, continuous validation assessments, and lessons learned workshops and improvement projects to continuously improve our process across Group Security and all other Verticals.

We are looking for a diligent, dedicated, creative and motivated individual. Excellent communication skills are a must, and the role holder will be expected to cultivate working relationships with other teams and colleagues of varying technical ability. The role would suit a technically strong candidate with an extensive cybersecurity background, at least 10+ years working in a security role, with focus on Vulnerability Management.

Key Responsibilities
  • Work out of hours in support of 24x7 globally coordinated operation.
  • Personnel Management
  • Ensure team members have clear objectives/development plans
  • Align Teams’ objectives to OKRs
  • Be the escalation point for security Tooling issues and critical security breaches
  • Responsible for team development, upskilling & mentoring
  • Protect and defend: Manage Vulnerability Management tooling to ensure coverage/availability/efficacy
  • Drive improvements and feature enhancement to ensure ROI
  • Operate and maintain: Configure, tune, maintain & operate key vulnerability management controls
  • Management reporting – real-time metrics and scheduled reports
  • Drive process/procedure changes accordingly
  • Ensure quality of ticketing & runbook maintenance
  • Cultivate and maintain strong vendor relationships
  • Have an attitude of continuous improvement
  • Participate in CAB, Tool review or Architecture Review Boards (ARBs)
  • As a member of the ION IT Security Team, execute ongoing, operational BAU tasks to meet KPIs and SLAs, and deliver security projects in line with priorities
  • Stay current with the latest security news, threats, intelligence, tactics, techniques, and vulnerabilities; analyze threats to determine exposure
  • Assist and/or lead efforts to isolate, contain, respond to, and recover from security incidents
  • Identify, review, prioritize, plan, coordinate, and follow-up on remediation of vulnerabilities
  • Define, document, and follow approved processes; create and maintain documentation for systems (design and operation)
  • Review vulnerability management systems, configurations, and processes for compliance with ION policy, client requirements, audit controls, regulations, and industry best practices; provide best practice security recommendations to IT and other teams
Experience, Skills and Qualifications
  • Degree/diploma/certifications in a technology-related field and/or relevant working experience; highly desired certifications include Security+, CCSP, CEH, GCIH, GMON, CASP, or CISSP
  • 10 years’ experience in Vulnerability Management within large organizations with at least 5 years in a senior leadership role
  • Excellent track record of building and leading a Vulnerability Management program on a global scale with knowledge on vulnerability assessments, remediation and mitigation activities
  • Technical Security/Engineering/Compliance background with a track record of building and running global teams
  • Previous track record of building risk management frameworks and applying them to an existing vulnerability management program
  • Strong technical expertise in implementing a prioritization formula to vulnerabilities and misconfigurations and translating these into risks
  • Excellent knowledge of Vulnerability Management frameworks such as NIST/SANS
General capabilities
  • A team player with the ability to work independently and unsupervised
  • Ability to own delegated tasks and see them through to completion
  • Ability to manage time and prioritize work to maximize productivity
  • Excellent reporting and presentation skills
  • Excellent communication skills (written and verbal)
  • Exceptional attention to detail and quality
  • Excellent problem-solving and trouble analysis skills
  • Experience in design and publishing Security Standards & Policies
  • Experience in leading Purple Teaming
  • Experience in running global Bug Bounty/VDP programs
  • Experience in leading Pen Testing, including scoping, scheduling, findings, remediation and risk registration; managing Pen Test program for Group Security and other Verticals
Knowledge areas
  • Vulnerability Management concepts, controls, and best practices for all operating systems and asset types (workstations, endpoints, mobile, servers Windows/Linux, cloud instances, etc.)
  • Vulnerability Management tools (Tenable/Rapid7/Qualys)
  • Cloud Security compliance (IaaS, PaaS, SaaS) and misconfigurations
  • Multi-platform endpoints, infrastructure and XaaS vulnerability management deployments
  • General IT networking concepts, protocols, standards and network security practices
  • Forensic investigation techniques
Additional experience
  • Experience deploying, configuring, managing, and/or operating security technologies (e.g., endpoint security, SIEM, DLP, SWG, CASB, UEBA, IDS/IPS, firewalls, IAM/PIM/PAM, Vulnerability Management, MDM)
  • Excellent track record of Senior Leadership and Board-level interaction, reporting and communications
  • Experience in InfoSec program management, project support and large-scale change
  • Proven knowledge of compliance, regulatory practices and experience managing audits
About us

We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world.

ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision.

ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor. ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.