×
Register Here to Apply for Jobs or Post Jobs. X

SC Vulnerability Management Lead CGEMJP00351666

Job in Preston, Lancashire, SN15, England, UK
Listing for: Experis - ManpowerGroup
Full Time position
Listed on 2026-08-13
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 644 GBP Daily GBP 644.00 DAY
Job Description & How to Apply Below

Role

Title:

Vulnerability Management Lead

Duration: contract to run until 31/03/2027

Location: Inverness or Preston. Hybrid

Rate: up to £644 p/d Umbrella inside IR35

Clearance required: Sole UK Nationality with Active SC Clearance.

Role purpose / summary

he Senior Vulnerability Management Consultant operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of vulnerability management across a complex multi-supplier environment.

The role is responsible for ensuring suppliers manage vulnerabilities consistently, effectively, and in accordance with client policy, regulatory requirements, and risk appetite. Working across security, service management, supplier, and client governance functions, the consultant provides a consolidated view of vulnerability risk and drives continuous improvement across the vulnerability management lifecycle.

This is a governance, assurance, and supplier management role and does not perform vulnerability scanning, penetration testing, exploit analysis, or technical remediation.

Key Responsibilities:

Vulnerability Management Governance
  • Own and govern the vulnerability management framework across suppliers
  • Define and maintain:
  • Vulnerability classification standards
  • Risk-based prioritisation models
  • Remediation timelines
  • Exception management processes
  • Ensure alignment to client security policies and control requirements
  • Supplier Governance & Performance Management
  • Act as the primary OI lead for vulnerability management
  • Challenge, validate, and assure supplier vulnerability processes
  • Drive consistency in reporting, remediation, and evidence standards
  • Manage escalations relating to high-risk or overdue vulnerabilities
  • Risk Management & Prioritisation
Ensure suppliers apply risk-based prioritisation methodologies, including:
  • CVSS
  • EPSS
  • Known Exploited Vulnerabilities (KEV)
  • Business criticality considerations
  • Maintain visibility of enterprise vulnerability exposure
  • Oversee risk acceptance and exception management activities
  • Reporting & Executive Visibility
  • Produce consolidated vulnerability risk reporting across suppliers
Provide insight into:
  • Risk posture
  • Remediation effectiveness
  • Compliance performance
  • Emerging threat exposure
  • Support governance boards and client security leadership
  • Assurance & Evidence Management
  • Define vulnerability management evidence requirements
Ensure end-to-end traceability of:
  • Identification
  • Prioritisation
  • Remediation
  • Validation
  • Support audits, assurance reviews, and compliance activities
  • Continuous Improvement
  • Identify trends, recurring weaknesses, and process improvement opportunities
  • Drive maturity improvements across supplier processes
  • Support optimisation of reporting, governance, and operating models
  • Contribute to security operating model evolution within the SIAM environment
Your skills and experience Essential
  • Significant experience in Vulnerability Management, Cyber Governance, Security Operations Governance, or GRC roles
Strong understanding of:
  • Vulnerability management lifecycle
  • Risk-based remediation approaches
  • Security governance frameworks
  • Experience operating within complex multi-supplier environments
  • Strong stakeholder management and supplier challenge capability
  • Experience presenting risk information to senior stakeholders
Desirable Knowledge of:
  • NIST CSF
  • NCSC guidance
  • ISO 27001
  • Secure by Design principles
  • Experience in Defence, Government, or highly regulated environments
  • Exposure to security assurance and audit activities
Key Deliverables
  • Vulnerability Management Framework
  • Consolidated supplier vulnerability reporting
  • Executive vulnerability risk dashboards
  • Vulnerability governance and assurance packs
  • Continuous improvement roadmap
  • Audit-ready evidence repository
Role Definition

The role governs and assures vulnerability management across suppliers, ensuring vulnerabilities are consistently prioritised, remediated, evidenced, and reported to the client through a risk-based and audit-ready approach, without performing technical remediation activities.

What This Role Does / Does Not Do Does
  • Govern, assure, challenge and coordinate
  • Provide enterprise-wide vulnerability risk visibility
  • Drive supplier accountability
  • Support risk-informed decision making
Does Not
  • Operate vulnerability scanners
  • Perform technical security testing
  • Deploy patches or fixes
  • Own remediation engineering activities
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary