Vulnerability Management Service Lead

Capgemini

Inverness

On-site

GBP 65,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Learning for life
Wellbeing programs

Job summary

Capgemini is seeking a Vulnerability Manager to join our Cyber Delivery Team in the UK, based in Inverness or Preston. You will own end-to-end vulnerability management, coordinating across security governance and multi-supplier environments to protect client information assets.

This hybrid role requires hands-on expertise with vulnerability tools (Tenable and related tooling), strong stakeholder communication, and the ability to deliver executive reporting on risk posture and remediation

Qualifications

  • Significant experience in Vulnerability Management, Cyber Governance, Security Operations Governance, or GRC roles within complex enterprise environments.
  • Strong understanding of the vulnerability management lifecycle, risk-based remediation, and security governance frameworks.
  • Proven ability to operate across multi-supplier environments, providing governance, assurance, and supplier challenge.
  • Excellent stakeholder management and communication skills, with experience presenting security risk to senior leaders.
  • Knowledge of frameworks such as NIST CSF, NCSC guidance, ISO 27001 and Secure by Design in regulated sectors.

Responsibilities

  • Own and govern the end-to-end vulnerability management framework, ensuring alignment with security policies and remediation timelines.
  • Lead supplier governance and performance management with consistent reporting and escalation of high-risk issues.
  • Oversee vulnerability risk prioritisation using CVSS, EPSS, KEV and business criticality.
  • Deliver consolidated reporting and executive insights on vulnerability posture and remediation progress.
  • Ensure end-to-end traceability and audit readiness while driving continuous improvement.

Skills

Vulnerability Management
Security Governance
GRC
Stakeholder Management
NIST CSF
ISO 27001
CVSS/EPSS

Tools

Tenable
Qualys
Brinqa

Job description

About the job you're considering

Are you passionate about cybersecurity? Are you an excellent communicator with demonstrable experience of delivering security services within organisations? Would you relish putting these skills into practice by taking on a role within Capgemini to protect us and our clients from cyber threats?

We are seeking a Vulnerability Manager with proven experience to join our cybersecurity team based out of Inverness or Preston.

Working as part of our Security Operations team, you will be responsible for delivering a comprehensive vulnerability management service to our customer.

As a Vulnerability Manager, you will play a crucial role in safeguarding our customer's information assets by identifying, assessing, and mitigating security vulnerabilities. Your expertise in Tenable will be essential in conducting thorough vulnerability assessments and ensuring the integrity and confidentiality of sensitive data.

The Cyber Delivery Team sits within a wider Managed Services function, residing in the Cloud Infrastructure Services (CIS) UK business line. You will have the opportunity to interact with our global team of security experts, from Architects to Engineers, Analysts to Compliance Managers. Outreach in CIS doesn't just stop at security, as we actively encourage our staff to engage with other areas of the business and local communities.

Hybrid working

The role will be hybrid and require working onsite at the customer site in either Inverness or Preston a minimum of 2 days a week, depending on business requirements.

If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service).

Your role:
  • Own and govern the end-to-end vulnerability management framework, ensuring alignment with security policies, risk standards, remediation timelines, and exception processes.
  • Lead supplier governance and performance management, driving consistent reporting, remediation practices, evidence standards, and escalation of high-risk issues.
  • Oversee vulnerability risk prioritisation using industry frameworks such as CVSS, EPSS, KEV, and business criticality to maintain visibility of enterprise risk exposure.
  • Deliver consolidated reporting and executive insights on vulnerability posture, remediation performance, compliance, and emerging threats to support governance decision-making.
  • Assure end-to-end traceability and audit readiness while driving continuous improvement, process maturity, and optimisation across the SIAM security operating model.

You can bring your whole self to work. At Capgemini building an inclusive future is part of everyday life and will be part of your working reality. We have built a representative and welcoming environment, for everyone.

Your skills and experience
  • Significant experience in Vulnerability Management, Cyber Governance, Security Operations Governance, or GRC roles within complex enterprise environments.
  • Strong understanding of the vulnerability management lifecycle, risk-based remediation, and security governance frameworks.
  • Proven ability to operate effectively across multi-supplier environments, providing governance, assurance, and constructive supplier challenge.
  • Excellent stakeholder management and communication skills, with experience presenting security risk and performance information to senior leaders.
  • Knowledge of industry frameworks and standards such as NIST CSF, NCSC guidance, ISO 27001, and Secure by Design, ideally gained within defence, government, or other highly regulated sectors.
Desirable:
  • Qualifications in Vulnerability Management Tooling (Qualys, Brinqa, Tenable)
We are a Disability Confident Employer

Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:

  • Declare they have a disability, and
  • Meet the minimum essential criteria for the role.

Please opt in during the application process.

Your security clearance and pre-employment checks

If you are successfully offered this position, you will go through a series of pre-employment checks, including: identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service)

Some roles will also require an additional level of security clearance:

Security Check (SC) Clearance:

To be successfully appointed to this role, it is a requirement to obtain Security Check (SC) clearance.

To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements.

Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality.

Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process.

Make it real - what does it mean for you?
Flexibility to work your way

You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements.

Your wellbeing

You'd be joining an accredited Great Place to work for Wellbeing in 2024. Employee wellbeing is vitally important to us as an organisation. We see a healthy and happy workforce a critical component for us to achieve our organisational ambitions.

To help support wellbeing we have trained 'Mental Health Champions' across each of our business areas, and we have invested in wellbeing apps such as Thrive and Peppy.

Shape your path

You will be empowered to explore, innovate, and progress. You will benefit from Capgemini's 'learning for life' mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.

Shared energy

You'll be bringing your unique skills and perspectives to the team, inspiring and taking inspiration from your teammates as you unlock value in everything you do. You'll be joining a professional community of experts, who have got your back and will support you, every step of the way.

Why should you consider Capgemini?

Growing clients' businesses while building a more sustainable, more inclusive future is a tough ask. When you join Capgemini, you'll join a thriving company and become part of a collective of free-thinkers, entrepreneurs and industry experts. We find new ways technology can help us reimagine what's possible. It's why, together, we seek out opportunities that will transform the world's leading businesses, and it's how you'll gain the experiences and connections you need to shape your future. By learning from each other every day, sharing knowledge, and always pushing yourself to do better, you'll build the skills you want. You'll use your skills to help our clients leverage technology to innovate and grow their business. So, it might not always be easy, but making the world a better place rarely is.

About Capgemini

Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organisations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion. Make it real | www.capgemini.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Analyst
Vulnerability Management Analyst

Capgemini • Inverness

On-site
GBP 42,000 - 56,000
GRC Analyst
GRC Analyst

Capgemini • Inverness

On-site
GBP 48,000 - 70,000
Senior Security Incident Management Consultant
Senior Security Incident Management Consultant

Capgemini • Inverness

On-site
GBP 80,000 - 110,000
GRC Lead
GRC Lead

Capgemini • Inverness

Hybrid
GBP 45,000 - 65,000
Hybrid working
Wellbeing programmes
Learning & development
+1
Security Command Centre - Onsite and On Shift (Security Incident Management Analyst)
Security Command Centre - Onsite and On Shift (Security Incident Management Analyst)

Capgemini • Inverness

Hybrid
GBP 40,000 - 60,000
Flexible working
Wellbeing programs
Cloud Security Consultant
Cloud Security Consultant

Capgemini • Birmingham

On-site
GBP 70,000 - 90,000
Principal DevSecOps Engineer
Principal DevSecOps Engineer

Capgemini • West of England

On-site
GBP 90,000 - 130,000
Disability Confident Employer
Applaud peer recognition portal
Learning for life program
Principal DevSecOps Engineer
Principal DevSecOps Engineer

Capgemini • Bristol

On-site
GBP 90,000 - 130,000
Total rewards package
Applaud portal
Learning for life
Lead DevSecOps Engineer
Lead DevSecOps Engineer

Capgemini • Bristol

On-site
GBP 70,000 - 100,000
Disability Confident Employer (Level 2
Applaud peer recognition portal
Learning for life training & 250,000+
Onsite Desktop Engineer
Onsite Desktop Engineer

Capgemini • Manchester

On-site
GBP 23,000 - 32,000