> Markdown version of [/jobs/ext/50670-vulnerability-management-analyst-leeds-national-security-west](https://www.wearedevelopers.com/jobs/ext/50670-vulnerability-management-analyst-leeds-national-security-west). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Management Analyst - Leeds - National Security West - **Company:** BAE Systems - **Location:** Leeds, UK (Remote available) - **Salary:** £60,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Access Network, Amazon Web Services, Microsoft Azure, Unix, Cloud Computing, Cyber Security, Linux, Open Source Technology, Software Vulnerability Management, Cyber Threat Analysis, Information Technology, Cybercrime, Tenable Nessus, Vulnerability Analysis - **Published:** May 15, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=9e0b57d3fc7e5241 ## About the Role Do you have experience in UNIX?, Do you have a Bachelor's degree?, Technical * 1+ years' experience in vulnerability management with an additional 1+ in related cyber roles. * Hands-on experience with vulnerability assessments, management, and remediation strategies. * Understanding of cloud concepts and environments (AWS, Azure) and their unique vulnerabilities. * Detailed understanding of Windows, Linux/Unix, and OS vulnerabilities. * Ability to perform risk analysis and prioritise. * A strong understanding of current and emerging threats. * Experience in technical incident response and management. Non-Technical * Project management skills to help deliver vulnerability programs. * Bachelor's Degree in Cybersecurity, Computer Science or equivalent experience in a SOC/ /Vulnerability Management field. * Excellent written and verbal communication skills with the ability to communicate the risk, potential impact and importance of detailed technical information to non-technical and senior stakeholders. * Team player and adept at working in a multi-disciplinary and diverse team. * Self-motivated and motivates others, keeping morale and performance high. ## Description We are looking for a talented and enthusiastic individual with a blend of technical and client-facing skills to join our dedicated client Security Operations Centre (SOC) as a vulnerability management analyst. This role will play an important part in supporting our client with identifying and assessing key vulnerabilities and working with stakeholders to complete remediation. This will also include assisting with the running of vulnerability remediation campaigns and reporting of the results. As the SME for vulnerabilities in the team, you will work closely with threat intelligence colleagues providing context and supporting other analysts in the SOC. The customer is committed for the SOC to be a benchmark of best practice and excellence. BAE Systems staff are based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location). This role requires a minimum of DV clearance. This role reports to the Cyber Threat Intelligence and Vulnerability Lead. The Role Core duties: * Monitor, investigate and report potential cyber threats and key vulnerabilities. * Analyse and interpret vulnerability report results, prioritise findings using risk-based prioritisation methodology and provide actionable recommendations for remediation. * Operate vulnerability scanning and configuration scanning tools, like AWS Inspector and Microsoft Defender. * Collaborate with a range of stakeholders and teams to address key vulnerabilities across the client's estate. * Ensure all relevant 0-Day, critical and high vulnerabilities sourced from internal tooling and open source feeds are tracked in a vulnerability register, and draft an alert and warning notice on an ADHOC basis when approved by the Cyber Threat Intelligence and Vulnerability Lead. * Assist in defining, creating and implementing various SOPs (Standard Operating Procedures) and SOMs (Service Operating Models). * Use asset risk information, vulnerability ratings, and threat information to communicate the risk and remediation. * Production of regular vulnerability reports to accurately articulate the landscape and progress. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)