Royal London est un groupe mutualiste qui propose des produits de retraite, de protection et de gestion d'actifs.
Senior Threat & Vulnerability Analyst (Edinburgh, GB)
Am I a fit — voir ma compatibilitéRoyal London recherche un Senior Threat and Vulnerability Analyst pour renforcer la gestion des vulnérabilités et du patching dans un environnement de cybersécurité. Le poste couvre l’identification, la priorisation, le suivi et la remédiation des vulnérabilités, ainsi que le reporting et l’évolution de la capacité CTEM.
Repères sur Royal London
- Domaine officiel
- royallondon.com
- Offres ouvertes
- 61
Détails de l’offre
La description complète publiée par Royal London.
Description de l’offre
Contract type: Permanent Location: Alderley Park, Glasgow Working style: Hybrid 50% home/office based Royal London is looking for a Senior Threat and Vulnerability Analyst to support the ongoing maturity and delivery of our enterprise patching and vulnerability management capability. Reporting to the Threat and Vulnerability Manager, you’ll help identify, prioritise, track and support the remediation of vulnerabilities across the Royal London estate, ensuring they are managed in line with business risk, regulatory expectations and agreed service levels.
You will support the evolution of Royal London's Continuous Threat Exposure Management (CTEM) capability, helping prioritise remediation activities based on exploitability, exposure and business risk. About the role As Senior Threat and Vulnerability Analyst, you will play a key role in supporting Royal London’s patching and vulnerability management processes, controls and reporting. You will help ensure vulnerabilities identified through cyber tools, assessments, audits and third parties are understood, prioritised and managed through to closure.
You will: Support the identification, triage, prioritisation, tracking and remediation of vulnerabilities across the Royal London estate. Help mature and maintain the vulnerability management process, including the management of vulnerabilities identified through tooling, assessments, audits and third parties.
- Ensure vulnerabilities are managed within documented SLAs, with compensating controls identified and implemented where required.
- Produce metrics, management information and reporting with clear narrative, remediation updates and recommendations.
- Support oversight of the patching and vulnerability management service delivered through our managed security service provider.
- Work with operational teams, cyber security colleagues and third-party partners to support effective remediation activity. Review and enhance processes, technologies and documentation used to support vulnerability management. Contribute to governance, risk, compliance and reporting activity relating to vulnerability and patching risk. Remain current on the threat landscape, vulnerability exploitation techniques and relevant cyber security practices.
- Support the maintenance and improvement of asset inventory data used to underpin vulnerability management.
About you
Good knowledge and hands-on experience of vulnerability management tools, particularly Tenable One and similar enterprise vulnerability platforms. Experience reviewing vulnerability scan data, producing reports and making clear remediation recommendations. Good understanding of IT security, cyber security frameworks, security controls and vulnerability management practices. Experience working with third-party providers, technology teams and business stakeholders. Strong communication skills, with the ability to explain technical issues clearly and influence stakeholders.
An analytical and methodical approach to technical challenges, with strong attention to detail. Understanding of exposure management, attack surface management or risk-based vulnerability prioritisation would be beneficial. A collaborative, service-orientated mindset and the ability to work effectively across cyber security and wider technology teams. Experience working in a regulated financial services environment would be beneficial. Security qualifications such as CISSP, CISM, ISC2 or equivalent are desirable but not essential.
The following experience would be beneficial but is not essential: Power BI dashboard and report development. Power Automate or similar workflow automation platforms. ServiceNow, including incident, request, change or CMDB processes. Python or other scripting languages for automation, data analysis and security tool integration. If you feel you’d be a great fit for Royal London but don’t meet every requirement, we’d still love to hear from you.
Research shows some candidates are less likely to apply unless they meet 100% of the criteria - if you meet most requirements and are keen to learn, we encourage you to apply! About Royal London We’re the UK’s largest mutual life, pensions and investment company, offering protection, long-term savings and asset management products and services. Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve.
We've always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance. Inclusion, diversity and belonging We’re an inclusive employer. We celebrate and value different backgrounds and cultures across Royal London. Our diverse people and perspectives give us a range of skills which are recognised and respected – whatever their background.
Prérequis
- CISSP
- CISM
- ISC2
Avantages mentionnés
- 28 days annual leave in addition to bank holidays
- up to 14% employer matching pension scheme
- private medical insurance