Description
The role owns the vulnerability-management lifecycle across on-premises and cloud estates, coordinating scanning, detection, triage, prioritisation, remediation, patching, SLA tracking, reporting, vendor coordination, audit and compliance, and automation. It requires experience in vulnerability or patch management and IT security operations, familiarity with tools such as Qualys, Rapid7, Ninja One, Ivanti, and Intune, knowledge of CVSS and NIST risk frameworks, ITIL-aligned service delivery experience, and strong stakeholder and reporting skills. The role reports to Service Delivery and Corporate Technology Leadership and supports the Information Security/CISO function, infrastructure, application, change, release, and third-party vendor teams.
