Location - London / Bristol or Manchester - you will only be required onsite once every 4 weeks (subject to adhoc meetings)
Duration - 12 months
Rate - 500 - 550 daily - inside IR35
As a Vulnerability Management Lead you will:
- Broaden the capability of the Domains Team. Currently the team has expertise around domains-related vulnerabilities. The Vulnerability Management Lead will develop this expertise such that the Team can support stakeholders deal with vulnerabilities found in the infrastructure, tools and services that Public Sector bodies commonly use in the development and delivery of their own digital services.
- Enable the Domains Operations Team to quickly classify and triage vulnerabilities at scale, according to priority
- Help Public Sector bodies understand, assess and act on the vulnerability information they receive
- Help Public Sector bodies plan and prioritise how vulnerabilities are addressed to meet organisational objectives, using a risk-based approach
- Help Public Sector bodies improve their vulnerability management life cycle
- Proactively identify and leverage threat intelligence sources to inform strategic vulnerability mitigation measures
- Help create a knowledgebase of written guidance to help stakeholders manage, prioritise and fix their vulnerabilities
- Develop and maintain good working relationships with stakeholders across the Public Sector to accelerate the reduction of risk through the fixing of vulnerabilities.
- Identify improvements to be made, specifically, and generally, identifying common problems and solutions across multiple organisations
- Work with the Domains Team to design and deliver effective services that meet user needs and are measurable through meaningful KPIs
Required skills:
- Expert knowledge of the security advantages and vulnerabilities of commodity products and technologies.
- Good working knowledge of current cyber security threats, risks.
- Experience in performing risk assessments, including business impact assessment, threat assessments and vulnerability (control gaps) assessments.
- Experience in developing security advice guidelines and specific mitigation advice, aligning these with business risk in a proportate way.
- Extensive experience in specifying and deploying security technical controls and developing design patterns based on solid understanding of security design principles.
- Good working knowledge of the marketplace of cyber security products and services
- Good working knowledge of cloud computing architecture and related technologies.
- Ability to interact with a broad cross-section of personnel to explain and encourage the implementation of security measures
Please submit a copy of your CV for more information on this vacancy.