> Markdown version of [/jobs/ext/2841433-cyber-security-vulnerability-manager](https://www.wearedevelopers.com/jobs/ext/2841433-cyber-security-vulnerability-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Vulnerability Manager - **Company:** Laing O'Rourke - **Location:** Dartford, UK - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Information Systems Security Architecture Professional, Cloud Services, Software Engineering, Software Vulnerability Management, Information Technology, Vulnerability Analysis - **Published:** September 11, 2026 - **Apply:** https://www.careerjet.co.uk/job/gba86e6498cc8758be010d959b06268e97/eaa ## About the Role * Proven experience developing and implementing cyber security vulnerability management programmes within a large enterprise environment. * Practical experience using vulnerability scanning technologies across cloud, hybrid and complex technology environments. * Knowledge of threat intelligence and risk-based vulnerability prioritisation models. * Strong analytical and problem-solving skills, with the judgement to recommend practical and proportionate responses to risk. * The ability to translate technical vulnerabilities, security risks and compliance requirements into clear, business-relevant information. * Effective stakeholder management and communication skills, with experience working collaboratively across technical and non-technical teams. * The ability to work independently, remain accountable for outcomes and guide remediation activity through to completion. Desirable Requirements * A relevant professional certification, such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP) or Certified Cloud Security Professional (CCSP). * Experience working across multidisciplinary teams within a complex organisational environment. ## Description We are looking for an experienced Cyber Security Vulnerability Manager to establish and lead an enterprise-wide vulnerability management programme. This is an opportunity to influence how vulnerabilities are identified, prioritised and resolved across a complex technology landscape, while helping colleagues make clear, informed decisions about cyber risk. Laing O'Rourke's IT function has renewed its strategy to support the company's ambition to transform the construction industry, making it more sustainable, more productive, and fit for the future. Technology has a critical role to play in achieving this ambition. Our focus is on applying digital capability in ways that genuinely matter, shaping how complex projects are delivered, how decisions are made, and how innovation improves outcomes for people, communities, and the environment. Our mission is clear: to create a modern and resilient technology environment where trusted data informs every decision, AI enhances every process, and digital capability enables the organisation to operate with greater scale and productivity. To deliver this, we are building a different kind of IT function, one that is trusted by the business, forward looking in its thinking, and deeply connected to operational outcomes. We are looking for individuals who are curious, thoughtful, and motivated by contributing to work that has real industry impact. The Role As Cyber Security Vulnerability Manager, you will develop, implement and continually improve Laing O'Rourke's vulnerability management capability across IT, cloud, operational technology and application environments. You will provide clear oversight of security vulnerabilities and ensure they are prioritised according to business risk, addressed within agreed service levels and reported effectively to senior stakeholders. Through practical guidance and collaborative working, you will help strengthen security, support regulatory compliance and enable informed decision-making across the organisation., * Design, implement and evolve an enterprise-wide vulnerability management strategy and programme covering discovery, assessment, risk prioritisation, remediation, validation and reporting. * Conduct and coordinate vulnerability assessments across IT infrastructure, cloud services, applications, software development and manufacturing environments. * Work collaboratively with technology colleagues to agree proportionate remediations, mitigations and compensating controls. * Improve the automation of vulnerability management workflows and support the continued development of the organisation's cyber security capability. * Establish clear measures and reporting that provide visibility of vulnerabilities, remediation progress and business risk. * Collaborate with Cyber Security Governance, Risk and Compliance colleagues to improve security across the supply chain and third-party providers. * Develop vulnerability management frameworks, policies and standards that support compliance with ISO 27001, Cyber Essentials Plus, Essential Eight and other relevant requirements. * Help improve mean time to detect and mean time to remediate while balancing cyber risk with operational availability. * Build trusted relationships with stakeholders, positioning cyber security as a practical enabler of the business. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)