> Markdown version of [/jobs/ext/725267-senior-cybersecurity-analyst-vulnerabilities-manager](https://www.wearedevelopers.com/jobs/ext/725267-senior-cybersecurity-analyst-vulnerabilities-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior CyberSecurity Analyst - Vulnerabilities Manager - **Company:** Welsh Revenue Authority - **Location:** Cardiff, UK - **Experience:** Expert - **Salary:** £47,675.0 - £56,445.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing, Cyber Security, Information Technology Operations, Network Architecture, Cloud Services, Software Vulnerability Management, EndPointSecurity, CIS Benchmarks, Service Stack, Vulnerability Analysis - **Published:** June 29, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=bcf95d336e226a66 ## About the Role Do you have experience in Presentation skills?, Relevant degree or equivalent experience. Security certifications (e.g. CISMP, Security+, Azure security certs, ISO 27001 quals) or equivalent experience. Languages We’ve undertaken an objective assessment of the Welsh language skills needed to undertake the duties of this role. For this role: Welsh language skills - Welsh skills are not essential. This means that you do not need Welsh language skills to undertake this role and these skills won’t be assessed during the recruitment process. However, we actively encourage all staff to learn, or improve their Welsh language skills and offer a range of opportunities to suit everyone., Use evidence and knowledge to support accurate, expert decisions and advice. Carefully consider alternative options, implications and risks of decisions., Communicating and Influencing Communicate purpose and direction with clarity, integrity and enthusiasm. Respect the needs, responses and opinions of others., You seek and analyse information to inform your decisions, based on the best available evidence. No Yes Problem Solver You take a positive approach to tackling problems and find ways to identify suitable solutions., Proven experience as a cyber security analyst (or equivalent role) in an enterprise environment., Practical experience in vulnerability management, including assessing, triaging and prioritising vulnerabilities across varied technology stacks., Hands-on experience with security tools such as Microsoft Defender for Cloud, Defender for Endpoint, Secure Score, Sentinel, or equivalent platforms., Relevant degree or equivalent experience., Security certifications (e.g. CISMP, Security+, Azure security certs, ISO 27001 quals) or equivalent experience., Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check . ## Description We encourage flexible and hybrid working. Some office attendance will be required based on business needs. This role is based in our Merthyr or Cardiff office., We’re responsible for Land Transaction Tax and Landfill Disposals Tax. Our work raises revenue to support public services, like the NHS and schools, in communities across Wales. But that’s not all, we're also involved with and support future tax design for Wales., The Cybersecurity Analyst – Vulnerabilities Manager is a key member of the WRA’s IT Operations & Security team, responsible for the operational security of our cloud-first digital estate. While this role covers a wide range of cyber responsibilities—including monitoring, incident support, secure configuration, governance input and SOC coordination—it includes lead responsibility for vulnerabilities management, reflecting the WRA’s identified security priority area. As we continue to grow our IT Security team we’re looking to streamline our vulnerabilities management and curate our threat intelligence sources. If you’re up for a challenge helping us improve our security posture and keep our systems secure then please do apply! "It’s a great time to join the WRA, and the Digital team in particular as we look to grow our portfolio of digital Services and produce an Easy, Fair and Sustainable tax system fit for the future.”, You will work closely with senior stakeholders, engineers developers, suppliers and the outsourced SOC to detect, assess and remediate threats, ensuring the organisation maintains a secure and resilient environment. 1. Vulnerability & Threat Management (Lead Area) * Lead the vulnerability management lifecycle across cloud workloads, endpoints and applications. * Coordinate and collate vulnerability scanning using relevant tools. * Work with our outsourced SOC provider to expand authenticated scanning, attack surface discovery and threat-led prioritisation. * Analyse scan results, interpret and triage vulnerabilities and threat data, and use these to produce clear remediation guidance tailored to technical and non-technical stakeholders. * Horizon-scan for emerging risks and work to ensure WRA is positioned to identify and mitigate those threats. * Maintain the WRA Vulnerability Management Policy and ensure it remains aligned with emerging risks, changes to compliance frameworks and regulatory changes. 2. Security Monitoring & Incident Response * Support security operations by reviewing alerts, triaging security events and escalating incidents as required. * Contribute to first-line and second-line incident investigation activities, coordinating with infrastructure engineers and suppliers. * Curate the collection of threat intelligence sources, adding and removing them as necessary to ensure a wide and deep coverage, and integrate insights into monitoring and detection. 3. Secure Configuration & Operational Security * Support secure configuration baselines for cloud services, endpoints and network infrastructure (e.g., CIS benchmarks). * Monitor patch compliance and system hardening across devices, cloud resources and identity platforms. * Work with IT Operations to ensure services remain secure, patched, resilient and compliant with organisational standards. 4. Governance, Risk & Compliance Support * Contribute to cyber risk assessments, working with senior colleagues to identify threats, vulnerabilities and control gaps. * Support audits and assessments aligned to Cyber Essentials Plus and IASME (and potentially other frameworks such as CAF and ISO 27001), including evidence preparation and remediation tracking. * Provide reporting and metrics that inform the organisation’s cyber risk posture and resilience planning. 5. Stakeholder Engagement & Advisory Duties * Work collaboratively with stakeholders to embed security considerations into day-to-day operations. * Communicate complex security issues in accessible, practical language to non-technical colleagues. * Promote security awareness and contribute to upskilling activities within IT and the wider organisation. 6. Continuous Improvement & Team Development * Contribute to improving cybersecurity processes, tooling and automation opportunities. * Participate in knowledge-sharing activities, retrospectives and capability development across the Digital team. * Help shape the evolving operating model for cybersecurity as the WRA expands its digital footprint., We’ll always be clear about how we assess your application, at each stage of the process. This will usually include: * Assessment of your Application Form and CV against the relevant Success Criteria * A panel interview (if you’re successful at the initial sift stage) Interviews will take place in person. * If any additional assessments are needed for this role, such as a test or presentation at interview, we’ll let you know in advance. * Should a large number of applications be received, an initial sift will be conducted using the lead behaviour, Making Effective Decisions We’re proud to be a Disability Confident Leader so we’ll ask you if you need any adjustments at each stage of the recruitment process. So that we can support you in a way that works for you, we’ll offer a pre-interview accessibility chat to anyone that declares a disability or needs any adjustments. This will take place with someone who is independent of the recruitment process and you won’t be placed at any disadvantage as a result of needing adjustments., * UK nationals * nationals of the Republic of Ireland * nationals of Commonwealth countries who have the right to work in the UK * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS) * individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020 * Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service, The law requires that selection for appointment to the Civil Service is on merit on the basis of fair and open competition. See the Civil Service Commission's recruitment principles where this is set out. If you feel your application has not been treated in line with the recruitment principles, and you wish to complain, you should contact the Head of HR. Email: hr@wra.gov.wales If you’re not satisfied with our response, you can contact the Civil Service Commission. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Introducing a Digital Service Catalog for speed and scale](https://www.wearedevelopers.com/videos/763-introducing-a-digital-service-catalog-for-speed-and-scale) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)