We are currently supporting a global client in seeking a senior cybersecurity leader to drive its enterprise Vulnerability Management capability.
The role will evolve traditional vulnerability management towards a more proactive, threat-informed approach, covering infrastructure, applications, cloud and identity environments.
Key Responsibilities:
- Own the strategy and roadmap for enterprise vulnerability management.
- Drive continuous visibility and assessment of the organisation's attack surface across cloud, on-premises, applications and identity.
- Establish risk-based prioritisation using threat intelligence, exploitability, asset criticality and business impact.
- Oversee vulnerability scanning, penetration testing, attack-path analysis and breach/attack simulation.
- Partner with technology teams to drive remediation, address root causes and reduce recurring exposures.
- Establish vulnerability, remediation and patch-management standards and governance.
- Develop KRIs, KPIs and management reporting to track exposure and programme effectiveness.
- Leverage automation, analytics and AI to improve discovery, prioritisation and remediation.
- Partner with Technology Risk and Audit on assurance and control matters.
- Build and lead a high-performing team.
Requirements:
- Extensive cybersecurity experience with senior leadership responsibility across vulnerability management, or security assurance.
- Proven experience building or maturing an enterprise-scale vulnerability management programme.
- Strong expertise across vulnerability management, attack surface management, penetration testing and exposure validation.
- Good understanding of threat-informed prioritisation, attack paths and business-criticality-based risk assessment.
- Experience with threat intelligence, cloud security and security automation.
- Experience within financial services or another complex regulated environment preferred.
- Strong senior stakeholder management and communication skills.
- Relevant certifications such as CISSP, CISM, CRISC, SANS or OffSec would be advantageous.