> Markdown version of [/jobs/ext/3216157-information-security-vulnerability-management-analyst](https://www.wearedevelopers.com/jobs/ext/3216157-information-security-vulnerability-management-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Vulnerability Management Analyst - **Company:** Jcb - **Location:** Uttoxeter, UK - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software as a Service, Cloud Computing, Cyber Security, Software Vulnerability Management, Patch Management, Vulnerability Analysis - **Published:** September 2, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/information-security-vulnerability-management-analyst/46227326 ## About the Role Salary: Competitive Salary Working Pattern: Full Time Contract Type: Permanent Click here for our Careers & Life at JCB pages About the role:The Information Security team is responsible for ensuring that JCB has the correct level of security integrity to protect our systems, information, personal data and people from cyber-attacks and unauthorised access.We are seeking a detail-oriented and proactive Vulnerability Management Analyst to join our on-site Information Security team.This critical role is essential in identifying, assessing, and mitigating vulnerabilities across our IT, OT, Cloud and SaaS environments. You will work closely with infrastructure, application, and operations teams to ensure timely remediation of security risks.What does this role involve day to day?· Manage the Vulnerability Management Process and Platform globally· Perform regular vulnerability scans and testing across IT, OT and SaaS systems using industry-standard tools· Arrange and Manage 3rd Parties for Security Penetration Tests on internal and external systems· Analyse scan results, prioritise vulnerabilities, and coordinate remediation efforts with relevant teams - see through to completion· Maintain and improve the vulnerability management lifecycle and reporting processes· Feed in to Risk Register and other teams for immediate and future improvements· Track and report on remediation progress and risk posture to senior stakeholders· Collaborate with IT and engineering teams to ensure secure configurations and patch management - find the root causes of issues and work to resolve· Support compliance alignment with NIST, and Cyber Essentials· Assist in threat modelling and risk assessments· Maintain documentation and procedures related to vulnerability management· Seek out and exploit opportunities for improvement to the group's overall security posture.This would be suited to you if ...· You're passionate about cyber security and keeping up with the latest trends, threats and mitigations· You have proven experience in vulnerability management or previous role(s) as Security Analyst/Engineer· You have a strong understanding of vulnerability scanning tools and techniques· You're familiar with CVSS scoring and vulnerability prioritisation techniques.· You have knowledge of patch management processes and secure system configurations.· You are familiar with OT environments is a plus· You have an understanding of security frameworks such as NIST, and Cyber Essentials· You have an ability to work independently in a fast-paced, on-site environment· You have a strong analytical mindset and communication skills.· You have an understanding of IT Service Management principles ideally ITIL.What happens next?Ordinarily, our Resourcing Team reviews and shortlists CVs. If shortlisted, you'll speak to one of our Recruiters to discuss the role further. Our interview process usually consists of an initial teams interview followed by an in-person interview. We'll keep in touch