Incident and Vulnerability Manager - Newport
13 hours ago
Chichester
About the job Job summary Incident and Vulnerability Manager This role is for an experienced professional in vulnerability management and threat intelligence to join our Cyber Operations team. You will work closely with colleagues across the organisation to further mature and continuously improve our cyber defence capabilities. Cyber Operations forms part of a wider, well established security function operating within a highly regulated environment. In this role, you will lead and continuously enhance the management of vulnerability assessments across our hybrid IT estate. You will prioritise remediation activities using a risk based, threat informed approach, collaborating with stakeholders to strengthen the security posture of our systems and services. You will also oversee our threat intelligence capability, identifying and maintaining relevant intelligence sources to inform tactical, operational, and strategic decision making. You will produce and share high quality threat intelligence products with internal and external stakeholders and use this intelligence to support vulnerability management and threat hunting activities. Additionally, you will contribute to incident response processes and provide support to colleagues responsible for the IPO's protection, detection, and response capabilities. if you have strong relevant expertise, excellent communication skills and a collaborative working style we would love to hear from you. Working Style This role will be carried out in-line with IPO Hybrid working arrangements where staff are currently expected to spend at least 20% of their time working onsite from one of our offices. This role is based in our Newport Office . The requirement for attendance at an office location can vary by role so we would encourage candidates to discuss working arrangements with the recruiting manager to agree a reasonable balance between working from home and the office. Job description Main duties consist of but are not limited to: Vulnerability Management (Primary Focus) • Lead and enhance the organisation's vulnerability management programme, including our Penetration Testing programme across a complex hybrid IT environment covering both infrastructure and applications. Scoping, prioritising work, engaging with stakeholders, and ensuring remediation activities happen in a timely fashion., • Prioritise vulnerabilities using a risk‑based, threat‑informed approach to support organisational objectives, regulatory requirements, and audit needs., • Oversee the full lifecycle of vulnerabilities, including triage, mitigation planning, remediation recommendations, and stakeholder coordination., • Produce high quality tactical, operational, and strategic intelligence assessments and briefings using analysis and interpretation of current threat intelligence. Utilising and liaising with internal stakeholders, commercial sources, open-source intelligence and government partners to provide a rounded, comprehensive view of the current threat landscape., • Strong understanding and experience of vulnerability management, threat intelligence and security operations, • Experience of managing penetration testing programs, • Broad technical knowledge, especially around cloud and hybrid technologies., • Highly organised and self-motivated, able to manage and deliver on multiple concurrent tasks., • Excellent communication and interpersonal skills. Ability to interact with stakeholders of all levels., • A team player who is enthusiastic about contributing to the overall success of the team and collaborating with stakeholders of all levels., • Sense of urgency and an ability to respond to tasks proactively and promptly., • Upload an anonymised copy of your current CV. Please remove all identifying markers such as name, title, education institution etc., • Use this to explain why you're suitable for the role ., • Structure your statement around the essential criteria in the Person Specification., • Seeing the Big Picture, • Managing a Quality Service, • Provide a 250-word example that demonstrates your technical ability. Penetration testing (focussed on managing penetration testing programs rather than conducting the tests themselves) :, • Unlimited Pluralsight video learning access, • Access to Microsoft's ESI training suite, • Hybrid working with no core hours, • Substantial support for career progression, • 25 days annual leave moving to 30 days in annual increments, • UK nationals, • nationals of the Republic of Ireland, • nationals of Commonwealth countries who have the right to work in the UK, • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) (opens in a new window), • nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS), • individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020