More jobs:
Threat and Vulnerability Manager
Remote / Online - Candidates ideally in
Newport, Newport County, NP10 8XG, Wales, UK
Listed on 2026-06-03
Newport, Newport County, NP10 8XG, Wales, UK
Listing for:
Intellectual Property Office
Full Time, Remote/Work from Home
position Listed on 2026-06-03
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Job Description & How to Apply Below
You will prioritise remediation activities using a risk based, threat informed approach, collaborating with stakeholders to strengthen the security posture of our systems and services. You will also develop and mature our threat intelligence capability, identifying and maintaining relevant intelligence sources to inform tactical, operational, and strategic decision making. You will produce and share high quality threat intelligence products with internal and external stakeholders and use this intelligence to support vulnerability management and threat hunting activities.
Additionally, you will contribute to incident response processes and provide support to colleagues responsible for the IPOs protection, detection, and response capabilities. If you have strong relevant expertise, excellent communication skills and a collaborative working style we would love to hear from you. Working Style This role will be carried out in-line with IPO Hybrid working arrangements where staff are currently expected to spend at least 20% of their time working onsite from one of our offices.
This role is based in our Newport Office . The requirement for attendance at an office location can vary by role so we would encourage candidates to discuss working arrangements with the recruiting manager to agree a reasonable balance between working from home and the office. Job description Main duties consist of but are not limited to:
Vulnerability Management (Primary Focus) Lead and enhance the organisations vulnerability management programme, including our Penetration Testing programme across a complex hybrid IT environment covering both infrastructure and applications. This will include scoping, scanning, prioritising work, engaging with stakeholders, and ensuring remediation activities happen in a timely fashion. Prioritise vulnerabilities using a risk-based, threat-informed approach to support organisational objectives, regulatory requirements, and audit needs.
Oversee the full lifecycle of vulnerabilities, including triage, mitigation planning, remediation recommendations, and stakeholder coordination. Develop and maintain vulnerability management policies, procedures, standards, and best practice guidance. Threat Intelligence Produce high quality tactical, operational, and strategic intelligence assessments and briefings using analysis and interpretation of current threat intelligence. Utilising and liaising with internal stakeholders, commercial sources, open-source intelligence and government partners to provide a rounded, comprehensive view of the current threat landscape.
Lead initiatives to strengthen the organisations intelligence capability and participate in information sharing communities. Cyber Risk Management Play an integral part in Cyber Security risk management, conducting risk and threat assessments aligned with regulations. Using your knowledge of standards and expertise to support our stakeholders by providing pragmatic and proportionate advice and best practice guidance. Metrics & Reporting Develop and maintain actionable metrics that demonstrate the effectiveness of the organisations vulnerability management and threat intelligence capabilities.
Incident Response Support Contribute to and enhance our incident response processes, representing Cyber Security in operational incident calls, keeping stakeholders informed and liaising with government bodies to ensure timely and effective management of threat intelligence and threat hunting. Person specification Essential Technical Strong understanding and experience of vulnerability management, threat intelligence and security operations within a complex enterprise environment
Experience of managing and developing penetration testing programs Knowledge of secure development practices and where security testing for vulnerabilities fits into the Software Development Lifecycle (SDLC) Broad technical knowledge, especially around hybrid and cloud architectures, identity management and application security. Essential Experience Highly organised and self-motivated, able to manage and deliver on multiple concurrent tasks. Excellent communication and interpersonal skills. Ability to interact with stakeholders of all levels with the ability to explain complex security concepts to non-technical audiences.
A team player who is enthusiastic about contributing to the overall success of the team and collaborating with stakeholders of all…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×