Vulnerability Management Service Lead

Adecco
Inverness, UK
5 days ago
Apply on www.adecco.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£70,000.0 - £75,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Executive Information Systems Software Vulnerability Management Cyber Threat Analysis Qualys

Job description

As the Vulnerability Management Service Lead, you will be responsible for owning and governing the end-to-end vulnerability management framework, ensuring effective risk management across complex technology estates., * Leading the enterprise vulnerability management service and governance framework

  • Driving vulnerability remediation activities through internal teams and third-party suppliers
  • Establishing and maintaining vulnerability reporting, metrics, KPIs and executive dashboards
  • Prioritising vulnerabilities using risk-based methodologies including CVSS, EPSS, Known Exploited Vulnerabilities (KEV), and business criticality
  • Managing exception processes, remediation timelines, and security risk governance
  • Providing assurance, oversight, and challenge across a multi-supplier service environment
  • Presenting vulnerability trends, risk exposure, and remediation performance to senior stakeholders
  • Ensuring audit readiness, evidence management, and compliance alignment
  • Identifying opportunities for process improvement, automation, and service maturity enhancement

Requirements

We’re seeking an experienced Vulnerability Management Service Lead to take ownership of a mature vulnerability management capability within a highly regulated enterprise environment.

This is an opportunity to play a critical role in protecting business-critical systems by driving governance, risk reduction, supplier accountability, and continuous improvement across a large-scale security operation. You’ll work closely with senior stakeholders, security teams, and delivery partners to ensure vulnerabilities are effectively identified, prioritised, remediated, and reported across the organisation.

If you’re passionate about cyber risk management, security governance, and influencing positive security outcomes at scale, we’d love to hear from you., * Significant experience in Vulnerability Management, Cyber Security Governance, GRC, or Security Operations Governance roles

  • Strong understanding of the end-to-end vulnerability management lifecycle
  • Experience implementing and governing risk-based remediation programmes
  • Proven ability to work across complex enterprise environments and multiple delivery partners
  • Strong stakeholder management skills with the ability to influence technical and non-technical audiences
  • Experience producing executive-level reporting and communicating cyber risk to senior leadership
  • Knowledge of recognised security frameworks and standards such as:
  • NIST Cyber Security Framework
  • ISO 27001
  • NCSC guidance
  • Secure by Design principles

Desirable Experience

  • Hands-on experience with vulnerability management platforms such as:
  • Tenable
  • Qualys
  • Brinqa
  • Experience working within defence, government, public sector, or other highly regulated environments
  • Relevant cyber security certifications, If you’re an experienced cyber security professional with a strong background in vulnerability management, governance, and risk reduction, we’d love to hear from you.

Benefits & conditions

  • The opportunity to lead a critical cyber security function within a large-scale enterprise environment
  • Exposure to complex and high-profile technology estates
  • Ongoing professional development and training opportunities
  • Access to experienced cyber security professionals across governance, operations, engineering, architecture, and compliance disciplines
  • Flexible and hybrid working arrangements
  • Comprehensive benefits package
  • Long-term career progression within a growing cyber security practice

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adecco.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:32 min

Mandatory vulnerability reporting and secure product design requirements

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:29 min

Forecasting organizational cybersecurity risks through public employee reviews

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:06 min

Implementing runtime threat event frameworks for attack telemetry

Tom Tovar · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:12 min

Preparing engineering organizations for rapid vulnerability response and remediation

Milin Desai Milin Desai +3 · World Congress 2026 Europe

Videos

See all

Related articles

See all