×
Register Here to Apply for Jobs or Post Jobs. X

Lead Cyber Security Analyst Vulnerability Management

Job in Glasgow, Glasgow City Area, G1, Scotland, UK
Listing for: Scottish Government
Full Time position
Listed on 2026-09-06
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below

Description

We are seeking an experienced and motivated Cyber Security Lead Vulnerability Management to join the Digital Risk & Security branch within Digital Delivery & Change. This role is responsible for leading the delivery and continuous improvement of Vulnerability Management services helping to protect Social Security Scotlands digital services systems and sensitive information from emerging cyber threats.

As a technical lead within the Security Operations function you will lead a small team of specialist security professionals and provide leadership and expertise across the organisations vulnerability and exposure management capabilities. Working closely with infrastructure application cloud and security teams you will drive the identification assessment prioritisation and remediation of vulnerabilities ensuring that cyber risks are effectively managed and reduced across a complex cloud-first technology estate.

You will lead the operational delivery and development of key Vulnerability Management services including:

  • Vulnerability and Exposure Discovery
  • Vulnerability Triage Risk Assessment and Reporting
  • Risk-Based Vulnerability Prioritisation
  • Security Configuration and Hardening Assurance
  • Patch and Remediation Governance
  • Asset Discovery and Attack Surface Management
  • Cloud Security and Vulnerability Monitoring
  • Vulnerability Metrics Reporting and Continuous Improvement
  • Threat-Informed Risk Assessment and Remediation Planning

The role requires strong technical knowledge of vulnerability management practices threat and risk management and security technologies combined with the ability to engage effectively with technical and business stakeholders. You will provide expert advice support the development of team capability and drive improvements to processes and tooling to ensure vulnerabilities are identified and remediated in a timely and risk-based manner.

If you are passionate about reducing cyber risk improving security resilience and helping protect critical public services we would welcome your application.

The Vulnerability Management Lead is responsible for protecting the confidentiality integrity and availability of information and information systems used by government and Partners Across Government.

  • Performs security risk vulnerability assessments and business impact analysis for complex information systems or risk-based projects.
  • Investigates security breaches in accordance with established procedures and recommends required actions and supports / follows up to ensure these are implemented.
  • Specifies requirements for environment data resources and tools. Interprets executes and documents complex test scripts using agreed methods and standards.
  • Contributes to the development of cyber security policy standards and guidelines appropriate to business technology and legal requirements and in accordance with best professional and industry practice.
  • Understands voice of the customer and develops mechanisms to proactively sense adoption and usage patterns of consumer technologies by end users so that policy can align with need.
Responsibilities

Responsibilities

  • Leads the identification assessment and remediation of security vulnerabilities across infrastructure endpoints applications and cloud services using threat intelligence and risk-based prioritisation to reduce cyber risk.
  • Has oversight of security administration processes and checks that all requests for support are dealt with according to agreed procedures.
  • Contributes to the development of cyber security policy standards and guidelines appropriate to business technology and legal requirements and in accordance with best professional and industry practice.
  • Deliver specific pieces of work resulting from the Cyber Security Strategy related to cyber business risk and information control/protection requirements.
  • Champion incident management incident investigation and response policy and/or incident management and investigation processes procedures and systems.
  • Performs security risk vulnerability assessments and business impact analysis for complex information systems or risk-based projects.
  • Leads and directs Cyber Security Analysts to create test cases using in-depth technical analysis of risks and typical vulnerabilities and to produce test scripts materials and test packs to test new and existing software or services.
  • Specifies requirements for environment data resources and tools. Interprets executes and documents complex test scripts using agreed methods and standards.
  • Maintains current knowledge of malware attacks and other cyber security threats.
  • Maintains knowledge of specific specialisms provides detailed advice regarding their application and executes specialised tasks.
Qualifications

Success Profiles
We use an assessment framework called Success Profiles which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.

For this post the following Success Profile elements will be assessed:

Experience:

  • Experience of…
  • Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
    To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
     
     
     
    Search for further Jobs Here:
    (Try combinations for better Results! Or enter less keywords for broader Results)
    Location
    Increase/decrease your Search Radius (miles)
    0
    200
    Filters
    Education Level
    Experience Level (years)
    Posted in last:
    Salary