Cloud Vulnerability Specialist
Role details
Job location
Tech stack
Job description
- Conduct cloud vulnerability scanning, analysis, and triage across AWS and GCP
- Lead vulnerability hunting, research, and risk-based prioritisation activities
- Own and optimise vulnerability management tooling, including Rapid7 CloudSec
- Drive remediation by working directly with Cloud, SOC, and Engineering teams
- Identify gaps across process, tooling, and results and actively close them
- Automate repetitive tasks using scripting to improve efficiency and accuracy
- Define and report actionable vulnerability metrics for senior stakeholders
- Track vulnerability trends and support predictive risk analysis
- Support security incidents with vulnerability-focused analysis and insight
Requirements
We are seeking an experienced Cloud Vulnerability Specialist to lead and mature end-to-end vulnerability management for a complex, cloud-first environment. This role is accountable for identifying, prioritising, and reducing material risk across AWS and GCP, with a strong focus on execution rather than reporting., 1. Strong hands-on experience in vulnerability management within cloud environments
- Proven knowledge of AWS and GCP security and vulnerability models
- Experience with Rapid7, Nessus, Qualys, or similar tooling
- Ability to prioritise vulnerabilities based on business impact and risk
- Scripting experience using Python and or PowerShell
- Experience collaborating with SOC, Cloud, and Engineering teams
- Working knowledge of ISO27001, NIST, and CIS frameworks
- Strong communication skills and stakeholder management capability
Nice to Have Experience in regulated or large-scale enterprise environments Exposure to vulnerability analytics or trend forecasting
This is not a passive scanning role. You will be expected to influence outcomes, challenge poor remediation practices, and materially reduce cloud risk.