Vulnerability Manager
The Very Group · Liverpool
Job description
About the role
You will act as the central coordination and risk authority for vulnerability activity, partnering closely with engineering and platform teams that own remediation delivery. The role requires a strong technical foundation and the ability to build, lead, and develop a high‑performing vulnerability management team.
Key responsibilities
- Own and continuously improve the end‑to‑end vulnerability management lifecycle across legacy, cloud, containerised, and third‑party environments.
- Operate and coordinate the Security Penetration Testing Framework, ensuring a consistent, risk‑led approach to scope, frequency, execution, retesting and closure.
- Triage, prioritise and track vulnerabilities and pen‑test findings, providing clear ownership, progress visibility and timely escalation of unmanaged risk.
- Govern risk acceptance, compensating controls and audit evidence.
- Produce reporting on risk posture, trends, coverage and performance for senior stakeholders and governance forums.
- Drive improvements in tooling, data quality, asset coverage and testing scope in collaboration with suppliers and internal teams.
- Establish and grow a sustainable vulnerability management team (hiring, onboarding, performance, coaching).
Required profile
- Strong experience coordinating vulnerability management and security penetration testing in complex enterprise environments.
- Demonstrable technical background in application, infrastructure and cloud security, as well as vulnerability assessment and remediation validation.
- Proven ability to hire, lead and develop a high‑performing vulnerability management team.
- Solid understanding of penetration testing methodologies and assurance expectations across applications, infrastructure, cloud and externally exposed services.
- Ability to apply risk‑based judgement beyond severity scoring, considering exploitability, exposure and business context.
- Experience governing penetration testing processes, including scope definition, prioritisation, retesting and remediation assurance.
- Confident stakeholder management with the skill to translate technical findings into clear business risk narratives.
- High standards for reporting, documentation and audit readiness.
Required skills
- Vulnerability management
- Penetration testing
- Application security
- Infrastructure security
- Cloud security
- Vulnerability assessment
- Remediation validation
- Risk‑based judgement
- Audit readiness
What we offer
- Flexible working arrangements
- Competitive perks and benefits
- Opportunities for continuous learning and career growth
Questions fréquentes
Why are you reporting this job?
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 hours ago
Expires 1 month from now
6 views · 0 applications
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
The Very Group
Liverpool
Related job offers
-
Senior HTML/CSS Developer for AI Training (Liverpool)
Prolific Liverpool -
Web Developer – WordPress & Elementor Specialist
The Regenda Group Liverpool -
Web Experience Developer – Hybrid (Marketing Agency)
Reed Liverpool -
Python Developer – Real‑time Risk & Trading Platform
Hunter Bond Londres et périphérie -
Data Analyst – Retail & Creative IP Business
POP MART Londres et périphérie