Vulnerability Management Governance Analyst
18 days ago
London
Vulnerability Management Oversight and Governance Analyst Banking Hybrid: 3 days onsite in London per week 6 months £487 per day In short: Due to a recent audit, we require a Vulnerability Management Analyst to assess our current processes and strategy and re-align, where necessary, to meet regulatory requirements. Job purpose: • Support the oversight, governance, and enhancement of vulnerability management activities within The Bank., • Lead smaller-scale projects independently, analysing and developing frameworks and procedures, ensuring alignment with regulatory requirements and industry best practices., • Analysing reporting on vulnerability management from third parties, identifying areas of risk for escalation and ensuring their posture remains within our risk appetite., • Refining metrics and reporting on vulnerability management, ensuring effective reporting and understanding of resilience risks., • Security and Operations exist to ensure that the Bank's security risks are managed and aligned with business objectives, enabling sustained growth and preventing harm, damage, or loss to its people, information, or assets., • Oversight of services provided by third parties, and vulnerability management activities within the Bank., • Provide insights into vulnerability management performance, maintain records, track key metrics, and escalate issues as needed., • Engage with stakeholders across London, the region, and globally, contributing to governance forums and remediation efforts., • Review and enhance frameworks and procedures to strengthen our approach and ensure ongoing regulatory compliance., • No direct reports., • Lead oversight of vulnerability scanning and vulnerability management activity, ensuring regulatory compliance and resilience assurance., • Lead gap analysis and enhancement of frameworks and procedures on vulnerability management to enhance effectiveness., • Drive engagement with key third party service providers on vulnerability management, supporting effective reporting and SLA adherence., • Assist in designing and implementing policies, procedures, and frameworks related to testing and vulnerability management., • Refining and reporting on key metrics and contribute to governance forums, ensuring visibility of risks and progress., • Solid understanding of frameworks such as NIST, ISO27001, OWASP, CVSS., • Formal security certifications desirable: CompTIA Security+, CISM / CISSP / CRISC beneficial., • Working knowledge of regulatory requirements including DORA, CBEST, and BoE Operational Resilience., • Degree in computer science or similar, or equivalent work experience., • Approximately 3 years' experience in a relevant cyber security field within a regulated environment, ideally Financial Services., • Strong stakeholder engagement and communication skills, with ability to convey technical issues to non-technical audiences., • Analytical and problem-solving skills with attention to detail., • Experience in vulnerability management programmes and remediation delivery,, • including working knowledge of scan tools. We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.