> Markdown version of [/jobs/ext/348373-information-security-vulnerability-management-analyst](https://www.wearedevelopers.com/jobs/ext/348373-information-security-vulnerability-management-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Vulnerability Management Analyst - **Company:** JCB - **Location:** Rocester, UK - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software as a Service, Cloud Computing, Cyber Security, System Configuration, Software Vulnerability Management, Patch Management, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=5bd748bbae8d3312 ## About the Role Do you have experience in NIST standards?, * You're passionate about cyber security and keeping up with the latest trends, threats and mitigations * You have proven experience in vulnerability management or previous role(s) as Security Analyst/Engineer * You have a strong understanding of vulnerability scanning tools and techniques * You're familiar with CVSS scoring and vulnerability prioritisation techniques. * You have knowledge of patch management processes and secure system configurations. * You are familiar with OT environments is a plus * You have an understanding of security frameworks such as NIST, and Cyber Essentials * You have an ability to work independently in a fast-paced, on-site environment * You have a strong analytical mindset and communication skills. * You have an understanding of IT Service Management principles ideally ITIL. ## Description The Information Security team is responsible for ensuring that JCB has the correct level of security integrity to protect our systems, information, personal data and people from cyber-attacks and unauthorised access. We are seeking a detail-oriented and proactive Vulnerability Management Analyst to join our on-site Information Security team. This critical role is essential in identifying, assessing, and mitigating vulnerabilities across our IT, OT, Cloud and SaaS environments. You will work closely with infrastructure, application, and operations teams to ensure timely remediation of security risks. What does this role involve day to day? * Manage the Vulnerability Management Process and Platform globally * Perform regular vulnerability scans and testing across IT, OT and SaaS systems using industry-standard tools * Arrange and Manage 3rd Parties for Security Penetration Tests on internal and external systems * Analyse scan results, prioritise vulnerabilities, and coordinate remediation efforts with relevant teams - see through to completion * Maintain and improve the vulnerability management lifecycle and reporting processes * Feed in to Risk Register and other teams for immediate and future improvements * Track and report on remediation progress and risk posture to senior stakeholders * Collaborate with IT and engineering teams to ensure secure configurations and patch management - find the root causes of issues and work to resolve * Support compliance alignment with NIST, and Cyber Essentials * Assist in threat modelling and risk assessments * Maintain documentation and procedures related to vulnerability management * Seek out and exploit opportunities for improvement to the group's overall security posture. ## Related Videos - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)