Cyber Security Analyst - Vulnerability Management

Morson Group
London, UK
6 days ago
Apply on www.morson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£156,000.0 - £169,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Cloud Computing Configuration Management Cyber Security Linux Network Architecture Security Information and Event Management Software Vulnerability Management Web Applications Software Security
+6 more
Cyber Threat Analysis SC Clearance Kubernetes Devsecops Qualys Vulnerability Analysis

Job description

My client is looking for an experienced Senior Vulnerability Analyst to join their Cyber Security team, taking a lead role in identifying, assessing and managing vulnerabilities across a complex enterprise technology environment.

This is a senior position requiring someone who can go beyond simply identifying vulnerabilities. You’ll be expected to understand the underlying risk, prioritise remediation and work closely with infrastructure, cloud, application and security teams to drive vulnerabilities through to resolution.

Security Clearance -

Eligibility for UK Security Check (SC) clearance is a mandatory requirement for this role. Candidates who already hold active SC clearance will be prioritised.

Key Responsibilities -

  • Lead the identification, assessment and prioritisation of vulnerabilities across infrastructure, applications, endpoints and cloud environments.
  • Analyse vulnerability scan results, distinguishing genuine risks from false positives and low-impact findings.
  • Assess vulnerabilities using CVSS, exploitability, asset criticality, exposure and business impact.
  • Monitor emerging vulnerabilities, zero-days and relevant threat intelligence.
  • Work closely with infrastructure, cloud, application, DevOps and IT operations teams to coordinate remediation.
  • Track vulnerabilities through to resolution, ensuring remediation is completed within agreed risk-based timescales.
  • Provide technical guidance and challenge remediation plans, risk acceptances and proposed compensating controls where appropriate.
  • Produce vulnerability reporting, dashboards and management information for technical and senior stakeholders.
  • Identify trends, recurring vulnerabilities and systemic weaknesses across the environment.
  • Help improve vulnerability management processes, tooling, automation and reporting.

Requirements

  • Significant experience in vulnerability management, vulnerability assessment or cyber security operations.
  • Strong understanding of vulnerability assessment methodologies and risk-based prioritisation.
  • Hands-on experience with enterprise vulnerability management platforms such as Tenable, Qualys, Rapid7 or similar.
  • Strong understanding of CVSS, CVE, CWE and common vulnerability types.
  • Experience analysing vulnerabilities across Windows, Linux, network infrastructure, cloud and/or applications.
  • Good understanding of patching, configuration management and security controls.
  • Proven experience working with technical teams to drive vulnerability remediation.
  • Strong analytical and problem-solving skills, with the ability to communicate technical risk clearly to both technical and non-technical stakeholders.
  • Eligible for UK SC security clearance.

Desirable Experience -

  • Active UK SC security clearance.
  • Experience working within Defence, Nuclear, Critical National Infrastructure (CNI) or other highly regulated and security-conscious organisations.
  • Experience with Azure and/or AWS vulnerability management.
  • Experience with container, Kubernetes or DevSecOps security.
  • Knowledge of application security and common web application vulnerabilities.
  • Experience using SIEM, EDR and threat intelligence alongside vulnerability data.
  • Knowledge of NIST, CIS, ISO 27001 or Cyber Essentials.
  • Relevant security certifications such as CISSP, CISM, GIAC, OSCP or similar., My client is looking for someone who combines strong technical vulnerability analysis skills with the ability to operate confidently at a senior level. You’ll be comfortable getting into the technical detail, while also being able to explain what the vulnerability means, how serious it is, what needs to be done and why. This is an excellent opportunity for a senior vulnerability professional to join a complex organisation where cyber security, risk management and continuous improvement are key priorities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.morson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all