Threat and Vulnerability Analyst

Royal London View All Jobs
Nether Alderley, UK
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Data Analysis Configuration Management Databases Cyber Security Python (Programming Language) Software Vulnerability Management Scripting Microsoft Power Automate Servicenow Vulnerability Analysis

Job description

Royal London is looking for a Senior Threat and Vulnerability Analyst to support the ongoing maturity and delivery of our enterprise patching and vulnerability management capability. Reporting to the Threat and Vulnerability Manager, you’ll help identify, prioritise, track and support the remediation of vulnerabilities across the Royal London estate, ensuring they are managed in line with business risk, regulatory expectations and agreed service levels. You will support the evolution of Royal London’s Continuous Threat Exposure Management (CTEM) capability, helping prioritise remediation activities based on exploitability, exposure and business risk. More about the role: As Senior Threat and Vulnerability Analyst, you will play a key role in supporting Royal London’s patching and vulnerability management processes, controls and reporting. You will help ensure vulnerabilities identified through cyber tools, assessments, audits and third parties are understood, prioritised and managed through to closure. You will:

  • Support the identification, triage, prioritisation, tracking and remediation of vulnerabilities across the Royal London estate.
  • Help mature and maintain the vulnerability management process, including the management of vulnerabilities identified through tooling, assessments, audits and third parties.
  • Ensure vulnerabilities are managed within documented SLAs, with compensating controls identified and implemented where required.
  • Produce metrics, management information and reporting with clear narrative, remediation updates and recommendations.
  • Support oversight of the patching and vulnerability management service delivered through our managed security service provider.
  • Work with operational teams, cyber security colleagues and third-party partners to support effective remediation activity.
  • Review and enhance processes, technologies and documentation used to support vulnerability management.
  • Contribute to governance, risk, compliance and reporting activity relating to vulnerability and patching risk.
  • Remain current on the threat landscape, vulnerability exploitation techniques and relevant cyber security practices.
  • Support the maintenance and improvement of asset inventory data used to underpin vulnerability management.

Requirements

  • Good knowledge and hands-on experience of vulnerability management tools, particularly Tenable One and similar enterprise vulnerability platforms.
  • Experience reviewing vulnerability scan data, producing reports and making clear remediation recommendations.
  • Good understanding of IT security, cyber security frameworks, security controls and vulnerability management practices.
  • Experience working with third-party providers, technology teams and business stakeholders.
  • Strong communication skills, with the ability to explain technical issues clearly and influence stakeholders.
  • An analytical and methodical approach to technical challenges, with strong attention to detail.
  • Understanding of exposure management, attack surface management or risk-based vulnerability prioritisation would be beneficial.
  • A collaborative, service-orientated mindset and the ability to work effectively across cyber security and wider technology teams.
  • Experience working in a regulated financial services environment would be beneficial.
  • Security qualifications such as CISSP, CISM, ISC2 or equivalent are desirable but not essential.

The following experience would be beneficial but is not essential:

  • Power BI dashboard and report development.
  • Power Automate or similar workflow automation platforms.
  • ServiceNow, including incident, request, change or CMDB processes.
  • Python or other scripting languages for automation, data analysis and security tool integration.

About the company

We’re the UK’s largest mutual life, pensions and investment company, offering protection, long-term savings and asset management products and services. Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve. We’ve always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance. Inclusion, diversity and belonging We’re an inclusive employer. We celebrate and value different backgrounds, perspectives and cultures across Royal London, and we’re committed to creating a workplace where everyone feels they belong and can do their best work.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · WWC 2023

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:55 min

Prioritizing system vulnerabilities and enhancing automated security posture

Raz Cohen · LIVE

1:36 min

Performing exploratory data analysis to uncover underlying patterns

Julian Joseph · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

Videos

See all

Related articles

See all