> Markdown version of [/jobs/ext/2857015-vulnerability-management-service-lead](https://www.wearedevelopers.com/jobs/ext/2857015-vulnerability-management-service-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Management Service Lead - **Company:** Adecco - **Location:** Preston, UK - **Experience:** Expert - **Salary:** £70,000.0 - £75,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Executive Information Systems, Software Vulnerability Management, Cyber Threat Analysis, Qualys - **Published:** September 12, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5879692307 ## About the Role We're seeking an experienced Vulnerability Management Service Lead to take ownership of a mature vulnerability management capability within a highly regulated enterprise environment. This is an opportunity to play a critical role in protecting business-critical systems by driving governance, risk reduction, supplier accountability, and continuous improvement across a large-scale security operation. You'll work closely with senior stakeholders, security teams, and delivery partners to ensure vulnerabilities are effectively identified, prioritised, remediated, and reported across the organisation. If you're passionate about cyber risk management, security governance, and influencing positive security outcomes at scale, we'd love to hear from you., * Significant experience in Vulnerability Management, Cyber Security Governance, GRC, or Security Operations Governance roles * Strong understanding of the end-to-end vulnerability management lifecycle * Experience implementing and governing risk-based remediation programmes * Proven ability to work across complex enterprise environments and multiple delivery partners * Strong stakeholder management skills with the ability to influence technical and non-technical audiences * Experience producing executive-level reporting and communicating cyber risk to senior leadership * Knowledge of recognised security frameworks and standards such as: + NIST Cyber Security Framework + ISO 27001 + NCSC guidance + Secure by Design principles Desirable Experience * Hands-on experience with vulnerability management platforms such as: + Tenable + Qualys + Brinqa * Experience working within defence, government, public sector, or other highly regulated environments * Relevant cyber security certifications, If you're an experienced cyber security professional with a strong background in vulnerability management, governance, and risk reduction, we'd love to hear from you. ## Description As the Vulnerability Management Service Lead, you will be responsible for owning and governing the end-to-end vulnerability management framework, ensuring effective risk management across complex technology estates., * Leading the enterprise vulnerability management service and governance framework * Driving vulnerability remediation activities through internal teams and third-party suppliers * Establishing and maintaining vulnerability reporting, metrics, KPIs and executive dashboards * Prioritising vulnerabilities using risk-based methodologies including CVSS, EPSS, Known Exploited Vulnerabilities (KEV), and business criticality * Managing exception processes, remediation timelines, and security risk governance * Providing assurance, oversight, and challenge across a multi-supplier service environment * Presenting vulnerability trends, risk exposure, and remediation performance to senior stakeholders * Ensuring audit readiness, evidence management, and compliance alignment * Identifying opportunities for process improvement, automation, and service maturity enhancement ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)