> Markdown version of [/jobs/ext/2143319-vulnerability-management-service-lead](https://www.wearedevelopers.com/jobs/ext/2143319-vulnerability-management-service-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Management Service Lead - **Company:** Capgemini - **Location:** Inverness, UK - **Experience:** Expert - **Salary:** £67,950.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Vulnerability Management, Cloud Platform System, Cybercrime, Qualys, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5847551745 ## About the Role Are you passionate about cybersecurity? Are you an excellent communicator with demonstrable experience of delivering security services within organisations? Would you relish putting these skills into practice by taking on a role within Capgemini to protect us and our clients from cyber threats?, * Significant experience in Vulnerability Management, Cyber Governance, Security Operations Governance, or GRC roles within complex enterprise environments. * Strong understanding of the vulnerability management lifecycle, risk-based remediation, and security governance frameworks. * Proven ability to operate effectively across multi-supplier environments, providing governance, assurance, and constructive supplier challenge. * Excellent stakeholder management and communication skills, with experience presenting security risk and performance information to senior leaders. * Knowledge of industry frameworks and standards such as NIST CSF, NCSC guidance, ISO 27001, and Secure by Design, ideally gained within defence, government, or other highly regulated sectors. Desirable: * Qualifications in Vulnerability Management Tooling (Qualys, Brinqa, Tenable) We are a Disability Confident Employer ## Description We are seeking a Vulnerability Manager with proven experience to join our cybersecurity team based out of Inverness or Preston. Working as part of our Security Operations team, you will be responsible for delivering a comprehensive vulnerability management service to our customer. As a Vulnerability Manager, you will play a crucial role in safeguarding our customer's information assets by identifying, assessing, and mitigating security vulnerabilities. Your expertise in Tenable will be essential in conducting thorough vulnerability assessments and ensuring the integrity and confidentiality of sensitive data. The Cyber Delivery Team sits within a wider Managed Services function, residing in the Cloud Infrastructure Services (CIS) UK business line. You will have the opportunity to interact with our global team of security experts, from Architects to Engineers, Analysts to Compliance Managers. Outreach in CIS doesn't just stop at security, as we actively encourage our staff to engage with other areas of the business and local communities. Hybrid working: The role will be hybrid and require working onsite at the customer site in either Inverness or Preston a minimum of 2 days a week, depending on business requirements. If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service). Your role: * Own and govern the end-to-end vulnerability management framework, ensuring alignment with security policies, risk standards, remediation timelines, and exception processes. * Lead supplier governance and performance management, driving consistent reporting, remediation practices, evidence standards, and escalation of high-risk issues. * Oversee vulnerability risk prioritisation using industry frameworks such as CVSS, EPSS, KEV, and business criticality to maintain visibility of enterprise risk exposure. * Deliver consolidated reporting and executive insights on vulnerability posture, remediation performance, compliance, and emerging threats to support governance decision-making. * Assure end-to-end traceability and audit readiness while driving continuous improvement, process maturity, and optimisation across the SIAM security operating model. You can bring your whole self to work. At Capgemini building an inclusive future is part of everyday life and will be part of your working reality. We have built a representative and welcoming environment, for everyone. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)