Vulnerability Management Lead
Ref: BBBH67807_1786375118Vulnerability Management Lead
Whitehall Resources are currently looking for a Vulnerability Management Lead in Lancashire/North Scotland for an initial 7-month contract.
***INSIDE IR35***
Role Description:
The Senior Vulnerability Management Consultant operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of vulnerability management across a complex multi-supplier environment.
The role is responsible for ensuring suppliers manage vulnerabilities consistently, effectively, and in accordance with client policy, regulatory requirements, and risk appetite. Working across security, service management, supplier, and client governance functions, the consultant provides a consolidated view of vulnerability risk and drives continuous improvement across the vulnerability management lifecycle.
Key Responsibilities:
Vulnerability Management Governance
Own and govern the vulnerability management framework across suppliers
Define and maintain:
- Vulnerability classification standards
- Risk-based prioritisation models
- Remediation timelines
- Exception management processes
- Ensure alignment to client security policies and control requirements
Supplier Governance & Performance Management
- Act as the primary OI lead for vulnerability management
- Challenge, validate, and assure supplier vulnerability processes
- Drive consistency in reporting, remediation, and evidence standards
- Manage escalations relating to high-risk or overdue vulnerabilities
Risk Management & Prioritisation
Ensure suppliers apply risk-based prioritisation methodologies, including:
- CVSS
- EPSS
- Known Exploited Vulnerabilities (KEV)
- Business criticality considerations
- Maintain visibility of enterprise vulnerability exposure
- Oversee risk acceptance and exception management activities
Reporting & Executive Visibility
Produce consolidated vulnerability risk reporting across suppliers
Provide insight into:
- Risk posture
- Remediation effectiveness
- Compliance performance
- Emerging threat exposure
- Support governance boards and client security leadership
Assurance & Evidence Management
- Define vulnerability management evidence requirements
- Ensure end-to-end traceability of:
- Identification
- Prioritisation
- Remediation
- Validation
- Support audits, assurance reviews, and compliance activities
Continuous Improvement
- Identify trends, recurring weaknesses, and process improvement opportunities
- Drive maturity improvements across supplier processes
- Support optimisation of reporting, governance, and operating models
- Contribute to security operating model evolution within the SIAM environment
Skills and experience
Essential
Significant experience in Vulnerability Management, Cyber Governance, Security Operations Governance, or GRC roles
Strong understanding of:
- Vulnerability management lifecycle
- Risk-based remediation approaches
- Security governance frameworks
- Experience operating within complex multi-supplier environments
- Strong stakeholder management and supplier challenge capability
- Experience presenting risk information to senior stakeholders
Desirable
Knowledge of:
- NIST CSF
- NCSC guidance
- ISO 27001
- Secure by Design principles
- Experience in Defence, Government, or highly regulated environments
- Exposure to security assurance and audit activities
All of our opportunities require that applicants are eligible to work in the specified country/location, unless otherwise stated in the job description.
Whitehall Resources are an equal opportunities employer who value a diverse and inclusive working environment. All qualified applicants will receive consideration for employment without regard to race, religion, gender identity or expression, sexual orientation, national origin, pregnancy, disability, age, veteran status, or other characteristics.
