> Markdown version of [/jobs/ext/2820792-information-security-analyst-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/2820792-information-security-analyst-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - Vulnerability Management - **Company:** Starling - **Location:** Manchester, UK - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Bash Shell, Cloud Computing, Cloud Computing Security, Cyber Security, Python (Programming Language), PCI Data Security Standards, Systems Integration, Software Vulnerability Management, Scripting, Kubernetes, Teamcity, Terraform, Jenkins, Golang, Programming Languages - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2833355457-information-security-analyst-vulnerability-management ## About the Role * Demonstrated vulnerability management experience in a role such as vulnerability analyst, specialist, or engineer * Strong technical knowledge of cloud platforms (aws, gcp) and cloud-native security architecture * Experience with kubernetes and container security principles * Security knowledge in AWS/GCP * Basic scripting skill for automation purposes (Python, Go, Bash etc.) * Proven ability to develop integrations by interacting with APIs * Excellent analytical and problem-solving skills to identify vulnerabilities and assess potential impact * Strong written and verbal communication skills to foster collaboration across cross functional teams and stakeholders * Adaptability to learn new technologies and evolve alongside the security landscape Desirable * Knowledge of CI/CD pipelines management including TeamCity and Jenkins * Knowledge of external attack surface management * Proficiency in infrastructure as code, specifically terraform * Competence in at least one programming language (e.g. java, golang, python) for automation ## Description We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week., We are seeking a highly motivated and experienced Vulnerability Management Analyst to join our team. As a Vulnerability Management Analyst, your primary responsibility will be to enable remediation groups and engineers to address and resolve outstanding findings within agreed timeframes. You will achieve this by effectively triaging and prioritising vulnerabilities using a risk-based approach. Additionally, you will ensure that all assets within the scope of vulnerability management are scanned within agreed time frames., * Partner with engineering and product teams to bridge the gap between security discovery and resolution, turning complex findings into clear, actionable tasks * Utilise a risk-based approach to prioritise vulnerabilities based on their potential impact and exploitability * Coordinate with resolver groups to ensure timely and efficient remediation of identified vulnerabilities * Maintain and update a wide range of Vulnerability Management tools (Build Phase VM, CWPP, Endpoint VM, VM Intelligence) to ensure their effectiveness and reliability * Review and update Vulnerability Management related documentation to align with internal and external compliance requirements, industry best practices and emerging threats (e.g. ISO 27000, PCI-DSS, NIST) * Build and maintain our vulnerability ecosystem, from cloud-native stacks to endpoint security, using automation to reduce manual overhead for the wider team * Process vulnerability data to provide reports, insights and metrics, that aid in the risk-based approach to vulnerability management * Develop integrations for internal and external tools to capture data relevant to the vulnerability remediation process (e.g. by interacting with APIs) * Ensure compliance with relevant security standards, frameworks, and regulations * Stay up to date with the latest trends and developments in vulnerability management, security standards, and regulations, * Develop and maintain vulnerability management tooling, ensuring reliable coverage across cloud-native and on-premise environments * Lead the shift towards automated remediation by implementing integrations that reduce manual toil for engineering teams * Work with internal remediators to prioritise vulnerability management activities * Process vulnerability data to provide reports, insights and metrics, that aid in the risk-based approach to vulnerability management * Develop integrations for internal and external tools to capture data relevant to the vulnerability remediation process * Ensure compliance with relevant security standards, frameworks, and regulations * Stay up to date with the latest trends and developments in vulnerability management, security standards, and regulations * Act as a subject matter expert, staying ahead of emerging threats and evolving the team's defensive strategy alongside the wider security organisation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)