Threat and Vulnerability Manager
Details
-----------
Reference number
462866
Salary
£47,766 \- £58,575
Maximum salary amount includes Recruitment Retention Allowance and Technical Allowances of up to £8,420\. Final salary package will be dependent on skills and experience.
A Civil Service Pension with an employer contribution of 28\.97%
GBP
Job grade
Senior Executive Officer
C1### Contract type
Permanent### Business area
IPO \- DDaT### Type of role
Digital
Information Technology
Security### Working pattern
Flexible working, Full\-time, Part\-time### Number of jobs available
1
Contents
------------
- Location
- About the job
- Benefits
- Things you need to know
- Apply and further information
------------
Newport, NP10 8QQAbout the job
-----------------
Job summary
Threat and Vulnerability Manager
This role is for an experienced professional in vulnerability management and threat intelligence to join our Cyber Operations team. You will work closely with colleagues across the organisation to further mature and continuously improve our cyber defence capabilities. Cyber Operations forms part of a wider, well established security function operating within a highly regulated environment.
In this role, you will lead and continuously enhance the management of vulnerability assessments across our hybrid IT estate. You will prioritise remediation activities using a risk based, threat informed approach, collaborating with stakeholders to strengthen the security posture of our systems and services.
You will also develop and mature our threat intelligence capability, identifying and maintaining relevant intelligence sources to inform tactical, operational, and strategic decision making. You will produce
and share high quality threat intelligence products with internal and external stakeholders and use this intelligence to support vulnerability management and threat hunting activities.
Additionally, you will contribute to incident response processes and provide support to colleagues responsible for the IPOs protection, detection, and response capabilities.
If you have strong relevant expertise, excellent communication skills and a collaborative working style we would love to hear from you.
Working Style
This role will be carried out in\-line with IPO Hybrid working arrangements where staff are currently expected to spend at least 20% of their time working onsite from one of our offices. This role is based in our Newport Office.
The requirement for attendance at an office location can vary by role so we would encourage candidates to discuss working arrangements with the recruiting manager to agree a reasonable balance between working from home and the office.
Job description
Main duties consist of but are not limited to:
Vulnerability Management (Primary Focus)
- Lead and enhance the organisations vulnerability management programme, including our Penetration Testing programme across a complex hybrid IT environment covering both infrastructure and applications. This will include scoping, scanning, prioritising work, engaging with stakeholders, and ensuring remediation activities happen in a timely fashion.
- Prioritise vulnerabilities using a risk‑based, threat‑informed approach to support organisational objectives, regulatory requirements, and audit needs.
- Oversee the full lifecycle of vulnerabilities, including triage, mitigation planning, remediation recommendations, and stakeholder coordination.
- Develop and maintain vulnerability management policies, procedures, standards, and best practice guidance.
- Produce high quality tactical, operational, and strategic intelligence assessments and briefings using analysis and interpretation of current threat intelligence. Utilising and liaising with internal stakeholders, commercial sources, open\-source intelligence and government partners to provide a rounded, comprehensive view of the current threat landscape.
- Lead initiatives to strengthen the organisations intelligence capability and participate in information sharing communities.
- Play an integral part in Cyber Security risk management, conducting risk and threat assessments aligned with regulations. Using your knowledge of standards and expertise to support our stakeholders by providing pragmatic and proportionate advice and best practice guidance.
- Develop and maintain actionable metrics that demonstrate the effectiveness of the organisations vulnerability management and threat intelligence capabilities.
- Contribute to and enhance our incident response processes, representing Cyber Security in operational incident calls, keeping stakeholders informed and liaising with government bodies to ensure timely and effective management of threat intelligence and threat hunting.
Person specification
Essential Technical
- Strong understanding and experience of vulnerability management, threat intelligence and security operations within a complex enterprise environment
- Experience of managing and developing penetration testing programs
- Knowledge of secure development practices and where security testing for vulnerabilities fits into the Software Development Lifecycle (SDLC)
- Broad technical knowledge, especially around hybrid and cloud architectures, identity management and application security.
- Highly organised and self\-motivated, able to manage and deliver on multiple concurrent tasks.
- Excellent communication and interpersonal skills. Ability to interact with stakeholders of all levels with the ability to explain complex security concepts to non\-technical audiences.
- A team player who is enthusiastic about contributing to the overall success of the team and collaborating with stakeholders of all levels.
- Sense of urgency and an ability to respond to tasks proactively and promptly.
- Continually stay abreast of emerging security technologies, threats and trends. Self\-motivated to drive their learning needs.
Click the 'Apply now' button and complete the application form by providing the following:
Your CV
- Upload an anonymised copy of your current CV. *Please remove all identifying markers such as name, title, education institution etc.*
- Make sure it clearly shows how you meet the essential criteria listed in the Person Specification.
- Use this to explain why you're suitable for the role.
- Structure your statement around the essential criteria in the Person Specification.
- Make sure to provide clear examples to show how you meet each requirement.
- Provide a 250\-word example that demonstrates your technical ability:
- Penetration testing (focussed on managing penetration testing programs rather than conducting the tests yourself) :
- Level \- Practitioner
- Make sure it aligns with the Technical criteria listed in the Person Specification.
For further information on the sift and interview stages of this recruitment campaign, please head to our 'Things you need to know' section below.
Please visit our Civil Service Careers page \- IPO Recruitment Support , Civil Service Careers (civil\-service\-careers.gov.uk)
If you require job\-specific information, please contact Dominic Read
E\-mail: Dominic.Read@ipo.gov.uk
Telephone: 01633 433189
Behaviours
We'll assess you against these behaviours during the selection process:
- Seeing the Big Picture
- Managing a Quality Service
- Changing and Improving
Technical skills
We'll assess you against these technical skills during the selection process:
- Penetration testing (focussed on managing penetration testing programs rather than conducting the tests themselves) : Level \- Practitioner Penetration testing \- UK Government Security \- Beta
------------
Alongside your salary of £47,766, Intellectual Property Office contributes £13,837 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides.* Unlimited Pluralsight video learning access
- Access to Microsofts ESI training suite
- Hybrid working with no core hours
- Substantial support for career progression
- 25 days annual leave moving to 30 days in annual increments
- You will also get 8 days public leave and 1 day privilege leave
*Please note that benefits may be subject to change.*
Things you need to know
---------------------------
Artificial intelligence
Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on appropriate and inappropriate use.### Selection process details
This vacancy is using Success Profiles , and will assess your Behaviours, Experience and Technical skills.Additional details on security and vetting
Successful candidates must pass a disclosure and barring security check and if successful you must also hold, or be willing to obtain, a higher Security Clearance.
For meaningful checks to be carried out individuals will need to have lived in the UK for a sufficient period of time, depending on the leve
This listing is from indeed. View original listing ↗