> Markdown version of [/jobs/ext/103380-threat-and-vulnerability-manager](https://www.wearedevelopers.com/jobs/ext/103380-threat-and-vulnerability-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat and Vulnerability Manager - **Company:** Royal London - **Location:** Glasgow, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Vulnerability Management, Vulnerability Analysis - **Published:** May 28, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=77456d7237eaf671 ## About the Role * Strong experience leading vulnerability and patch management in a complex enterprise environment. * Deep understanding of exposure management, attack surface concepts and risk-based vulnerability prioritisation. * Hands-on experience with vulnerability management tools such as Tenable One. * Good understanding of operating systems, infrastructure, applications and how vulnerabilities manifest across different asset types. * Experience defining control frameworks, SLAs and executive reporting. * Experience working in regulated environments; financial services desirable. * Comfortable engaging with and influencing senior stakeholders, translating technical findings into clear business risk insights. * Experience managing third-party or outsourced service providers. * Knowledge of cyber security frameworks, standards and good practice, with a continuous improvement mentality. Relevant security qualifications (CISSP, CISM or equivalent) beneficial but not essential. ## Description Reporting to the Head of Attack Surface Management, the Threat and Vulnerability Manager is accountable for defining, owning and operating Royal London's enterprise patching and vulnerability management capability. The role ensures vulnerabilities are identified, prioritised, governed and reported in line with business risk, regulatory expectations and industry best practice, supporting cyber resilience across the Group. You will lead Royal London's patching and vulnerability management capability, working closely with operational technology teams and our partner resources. Through strong collaboration, clear prioritisation and effective reporting, you will help ensure that vulnerabilities are managed transparently and treated in a timely, risk informed way, strengthening our overall cyber resilience. More About the role: * Own the enterprise patching and vulnerability management framework, standards, policies, processes, controls and operating model. * Own the end-to-end vulnerability lifecycle including identification, triage, risk-based prioritisation, remediation tracking and closure. * Define and manage vulnerability SLAs, KPIs and KRIs aligned to asset criticality, exposure and business impact. * Provide executive-level reporting on vulnerability exposure, trends, insights and remediation performance. * Oversee patching and vulnerability-related operational controls, ensuring they are documented, tested, evidenced and continuously improved. * Work closely with technology and service teams to ensure remediation activities are delivered in line with defined SLAs. * Oversee third-party providers delivering vulnerability scanning and patching services. * Support assurance activity, control testing and risk event management related to vulnerability and patching risk. * Continuously improve processes, controls and tooling supporting Attack Surface Management. ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What is the real price of one successful line of code?](https://www.wearedevelopers.com/videos/1921-what-is-the-real-price-of-one-successful-line-of-code) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)