Cyber Threat and Vulnerability Manager

Reference: CTVM_1781529292

As a Cyber Threat & Vulnerability Manager, you will play a key role within the Security Operations function, leading the organisation's threat intelligence, vulnerability management, and intelligence-led testing capabilities across both IT and OT environments. Working closely with cybersecurity leadership, enterprise architects, programme delivery teams, and key business stakeholders, you will ensure that Threat and Vulnerability Management (TVM) services are effective, scalable, and continuously improved.

This role contributes to the cyber resilience by driving a risk-based approach to vulnerability management, embedding threat intelligence into operational and strategic decision-making, and enhancing security maturity across the organisation. You will lead a team of specialists, oversee governance and tooling, and ensure that TVM capabilities align with organisational objectives, regulatory requirements, and evolving threat landscapes.

You must be able to obtain Counter Terrorist Check (CTC) Clearance to be eligible for this position.

What you'll be doing as a Cyber Threat & Vulnerability Manager

  • Lead enterprise vulnerability management, ensuring frameworks for identifying, prioritising, and remediating vulnerabilities are defined, implemented, and continuously improved.
  • Manage the Cyber Threat Intelligence service, ensuring intelligence is collected, analysed, and operationalised to support risk reduction and security operations.
  • Collaborate with technical and business stakeholders to align TVM activities with organisational objectives and risk appetite.
  • Develop and maintain TVM documentation, including policies, standards, procedures, and governance controls.
  • Integrate and optimise vulnerability management, threat intelligence, and assessment tooling across enterprise systems and workflows.
  • Oversee intelligence-informed testing activities, including targeted assessments, exploit validation, and internal testing services.
  • Evaluate and recommend tools, technologies, and vendors to support and enhance TVM capabilities.
  • Investigate newly identified vulnerabilities and coordinate risk-based mitigation and remediation activities.
  • Work closely with technology teams to ensure effective patching, remediation tracking, and resolution of blockers.
  • Maintain and evolve the organisation's cyber threat assessment methodology aligned with industry standards and risk management processes.
  • Lead proactive threat hunting activities to identify emerging threats and suspicious activity across the technology estate.
  • Develop and maintain dashboards, reporting, and operational metrics that demonstrate risk reduction and control effectiveness.
  • Ensure compliance with relevant standards and regulations such as GDPR, NIS, and ISO 27001.
  • Monitor and improve the effectiveness of TVM processes, controls, and supporting technologies.
  • Provide leadership, coaching, and performance management to the TVM and testing team.
  • Build and maintain strong relationships with external intelligence providers, vendors, and delivery partners.
  • Stay current with emerging threats, technologies, and industry best practices to continuously enhance security operations.
  • Support major incident response activities where required as part of Security Operations.

What you should bring to the role

  • Experience leading or managing threat and vulnerability management processes and controls within a complex enterprise environment.
  • Strong experience in vulnerability remediation and patch management across diverse and evolving technology estates.
  • Experience managing cyber risks within dynamic digital and operational technology environments.
  • Ability to line manage and develop a team of security professionals towards shared objectives.
  • Strong analytical, problem-solving, and decision-making skills.
  • Experience managing third-party delivery partners, vendors, and service providers.
  • Excellent communication skills with the ability to explain complex security concepts to non-technical stakeholders.
  • Strong organisational, planning, and strategic thinking capabilities.
  • Innovative mindset with a focus on continuous improvement and measurable risk reduction.
  • Experience producing operational metrics and dashboards that demonstrate TVM effectiveness and cyber maturity improvements.

Technical experience and skills

  • Hands-on experience with vulnerability management and threat intelligence tools such as Tenable and Qualys.
  • Strong understanding of TVM concepts, including vulnerability assessment, threat modelling, OSINT, threat intelligence, and penetration testing.
  • Knowledge of patch management approaches across SaaS, IaaS, end-user computing, server, and enterprise technology environments.
  • Experience implementing risk-based approaches to vulnerability prioritisation and remediation.
  • Ability to develop dashboards and reporting that demonstrate control effectiveness, risk reduction, and technical debt management.
  • Experience aligning security practices with frameworks and regulations such as ISO 27001, NIS, and GDPR.

Desirable qualifications and experience

  • Experience working within utilities, critical infrastructure, or large complex enterprise environments.
  • Experience managing vulnerabilities and cyber risks within operational technology (OT) environments.
  • Familiarity with legacy systems and managing vulnerabilities within ageing technology estates.
  • Experience supporting cyber security transformation programmes and strategic cyber roadmaps.

Desirable technical skills and qualifications

  • Degree in Cyber Security, Computer Science, Information Technology, Engineering, or a related field.
  • Professional certifications such as CISSP, CISM, or CCSP.
  • TVM-specific certifications such as Certified Threat Intelligence Analyst (CTIA) or Certified Vulnerability Assessor (CVA).
  • Knowledge of penetration testing, ethical hacking, or related security assessment practices.

GCS is acting as an Employment Agency in relation to this vacancy.

£80,000.00 - £90,000.00
Per annum
GBP80000 - GBP90000 per annum
Added 15/06/2026
Reference: CTVM_1781529292

Cyber Threat and Vulnerability Manager

Berkshire, United Kingdom Permanent Threat vulnerability

Other similar jobs

Threat Intelligence and Vulnerability Manager

Added 02/09/2026

Threat Intelligence and Vulnerability Manager6-Month Contract | Inside IR35 | London 1-2 Days Per WeekWe're looking for an experienced security leader to take ownership of Threat Intelligence, Vulnerability Management, Threat Modelling, Security Testing and External Threat Hunting capabilities within a complex, high-profile environment.This is a hands-on leadership role where you'll help identify emerging threats, uncover vulnerabilities, drive assurance activities, and provide the intelligence needed to strengthen enterprise security across IT, OT, physical and people security domains.Key Experience✅ Threat Intelligence & Threat Hunting ✅ Vulnerability Management & Risk Prioritisation ✅ Threat Modelling & Security Assurance ✅ Penetration Testing & Control Validation...

Learn more

Senior Analyst - Vulnerability Management (Contract)

Added 25/06/2026

Senior Analyst - Vulnerability Management (Contract)Location: London (hybrid)Duration: 6 monthsEngagement: Inside IR35OverviewA Senior Vulnerability Management Analyst is required to drive vulnerability identification, prioritisation, and remediation across enterprise IT and cloud environments. This role will improve the organisation's ability to manage exposure to cyber threats through robust vulnerability processes.Key Responsibilities* Operate and enhance the vulnerability management lifecycle (scan, assess, prioritise, remediate, report)* Perform and coordinate regular vulnerability scans across infrastructure, applications, and cloud environments* Analyse vulnerabilities and provide risk-based prioritisation aligned to business impact* Work with IT and engineering teams to track and drive remediation efforts* Provide detailed reporting on risk...

Learn more

Packaging and Virtual Desktop Migration Project Manager

Added 30/07/2026

Project Manager - Application Packaging & Virtual Desktop Migration Initial 12 month contract role - Inside ir35Hybrid in the Preston/Manchester Area Key ResponsibilitiesLead the planning and delivery of application packaging and virtual desktop migration projects.Manage project plans, milestones, dependencies, RAID logs, and governance reporting.Coordinate packaging, testing, deployment, migration waves, and operational transition activities.Build strong relationships with business stakeholders, technical teams, and third-party suppliers.Manage project risks, issues, and dependencies, ensuring timely resolution and escalation where required.Ensure delivery meets agreed quality standards, governance requirements, and business expectations.Produce regular status reports and present progress to senior stakeholders and project boards.Support business readiness and...

Learn more

BI Platform Engineer - Looker and Tableau

Added 17/09/2026

Role: Senior Looker Platform EngineerLocation: Wayne, PAJob SummaryWe are seeking an experienced Looker Administrator to support platform engineering, cloud migration initiatives, data platform modernization, and operational excellence within a large-scale analytics environment. The ideal candidate will have strong expertise in Looker administration, LookML development, BI platform support, cloud technologies, identity management, and performance optimization.Key ResponsibilitiesPlatform Engineering & OperationsProvide L3/L4 production support for Looker environments across development and production platforms.Lead platform upgrades, releases, patch management, and validation activities.Support GitHub and LookML development workflows, including Dev/Prod deployments and coordination.Troubleshoot and resolve complex performance, scalability, and data modeling issues.Monitor platform health, reliability, and...

Learn more

People and Culture Advisor

Added 17/07/2026

About the OpportunityAn exciting opportunity has arisen for an experienced People & Culture Advisor to join a dynamic and fast-paced organisation on a 12-month fixed-term contract.Working as part of a collaborative People team, you will provide high-quality HR advisory support across a broad range of people matters, partnering with managers and stakeholders to deliver practical, commercially focused solutions while ensuring compliance with employment legislation and HR best practice.This role offers a mix of employee relations, people operations, organisational change support, and HR project work within a complex, matrixed environment.Key ResponsibilitiesAct as a trusted first point of contact for managers on...

Learn more

IT Business Analyst (Public Sector Exp and Active SC Required)

Added 01/07/2026

ROLE PURPOSEBusiness Analysts are responsible for eliciting, analysing, and documenting business requirements for the PMP programme, ensuring solutions address operational needs and deliver measurable improvements. PRINCIPAL ACCOUNTABILITIESEngage with operational and enabling stakeholders to gather, analyse and clarify business requirements.Translate business needs into clear, structured artefacts including process maps, user stories and functional specifications.Ensure requirements are documented accurately, clearly and to agreed PMP standards.Support testing and acceptance activities by validating delivered solutions against approved business requirements.Assist with User Acceptance Testing (UAT), clarifying acceptance criteria and supporting issue resolution.Maintain traceability between requirements, delivered solutions and expected benefits.Support assurance and governance activity by...

Learn more

Cyber Programme Manager

Added 10/07/2026

Cyber Security Programme ManagerDuration: 12 month rolling day rate contract 600-700 per day Location: Dublin Onsite Requirement: 3 to 4 days onsite per weekSummary of RoleWe're looking for an experienced Information Security Programme Manager to lead and deliver a broad range of cyber security initiatives within a growing organisation.This is a hands-on leadership role where you'll drive security improvements, strengthen governance, manage security risks, and support major technology change programmes.You'll work closely with IT teams, business stakeholders, and external partners to ensure security remains a core part of the organisation's strategy and operations.Key ResponsibilitiesLead information security projects and programmes from...

Learn more

Cyber Programme Manager (TVM)

Added 10/07/2026

Cyber Programme Manager (Threat and Vulnerability management)Duration: 6 month rolling day rate contract Type: Day rate contract 600-700 per day Location: Dublin Onsite Requirement: Hybrid working model (3 days per week onsite)Summary of RoleIn this role, you will:Lead and enhance a large-scale Threat & Vulnerability Management (TVM) function within a complex enterprise environment.Drive the organisation's approach to vulnerability identification, risk prioritisation, remediation governance, and continuous security improvement.Serve as the senior owner of the vulnerability management operating model, ensuring security risks are managed effectively across infrastructure, cloud, and application estates.Act as the principal point of contact between cyber security, technology teams,...

Learn more

Cyber Security Manager

Added 11/06/2026

🔐 Cybersecurity Manager (Audit & Compliance) - Los Angeles, CA📍 Location: Los Angeles, CA 📄 Duration: 12+ Month Contract (C2H Possible) 🏢 Work Model: Hybrid🚀 About the RoleJoin as a Cybersecurity Manager leading large-scale security audit and compliance programs. You'll ensure audit readiness, drive remediation, and align enterprise systems with industry standards.🛠️ ResponsibilitiesLead enterprise audit and compliance initiativesOversee risk assessments and vulnerability remediationDrive adherence to ISO 27001, SOC2, NISTPartner with cross-functional teams and stakeholdersProvide executive-level reporting on audit progress✅ Requirements7-10+ years in cybersecurity or compliance rolesExperience with audit, risk, and governance programsStrong stakeholder communication skillsPreferred certifications: CISSP, CISM, CISA, PMP...

Learn more

Cyber Security Manager

Added 11/06/2026

🔐 Cybersecurity Manager (Audit & Compliance) - Irvine, CA📍 Location: Irvine, CA 📄 Duration: 12+ Month Contract (C2H Possible) 🏢 Work Model: Hybrid🚀 About the RoleWe are hiring a Cybersecurity Manager to lead enterprise audit and compliance initiatives, focusing on ISO 27001, SOC2, and NIST frameworks. You'll drive audit readiness, manage remediation efforts, and ensure security compliance across the organization.🛠️ ResponsibilitiesLead internal & external cybersecurity auditsManage audit findings, risk, and remediation effortsEnsure compliance with ISO, SOC2, NIST frameworksCollaborate with IT & Security teams to close gapsTrack and report audit status to leadership✅ Requirements7-10+ years in cybersecurity, audit, or complianceStrong knowledge...

Learn more

Head of Cyber Security

Added 16/09/2026

Head of Cybersecurity The OpportunityWe are seeking an experienced Head of Cybersecurity to join a senior leadership team within a large, complex organisation operating in a highly regulated and rapidly evolving digital environment. The successful candidate will work closely with senior stakeholders across a broad range of organisations and industries, helping shape strategic approaches to emerging cybersecurity, technology and resilience requirements.The RoleThe Head of Cybersecurity will lead and develop a multidisciplinary team of experienced engagement and policy professionals. The role will involve significant engagement with senior stakeholders across industry, technology, public and private sector organisations, professional networks and other key...

Learn more

Cyber Security Automation Engineer

Added 15/09/2026

Role- Senior Security Automation EngineerType- ContractDuration- 12+ monthsLocation- Mt. Laurel, NJOverviewSeeking a Senior Security Automation Engineer to build AI-driven security automation solutions within a Cyber Security Operations Center (CSOC). This is a hands-on engineering role focused on developing intelligent agents and automated workflows that improve threat detection, investigations, and incident response.Key ResponsibilitiesDesign, develop, deploy, and maintain production-grade security automation and AI-powered workflows.Build AI agents capable of accessing security data, using tools, maintaining context, and executing multi-step tasks.Automate processes across:Threat IntelligenceThreat HuntingDetection EngineeringSecurity InvestigationsIncident ResponseSecurity Data AnalysisApply advanced AI techniques including:Tool CallingRetrieval-Augmented Generation (RAG)Structured GenerationPlanning & ReflectionVerificationModel RoutingMulti-Agent CoordinationDesign memory, context...

Learn more

Cyber Security Engineer

Added 02/09/2026

Cyber Security Engineer Secure by Design & Security Platforms6-Month Contract | Inside IR35 | London 1-2 Days Per WeekWe're seeking a hands-on Cyber Security Engineer to embed Secure by Design principles across technology programmes while helping improve and optimise a suite of enterprise security platforms.This is an excellent opportunity for a security professional who enjoys working across architecture, engineering and delivery teams, influencing projects from inception through to deployment while providing practical, pragmatic security guidance.Key Experience✅ Secure by Design & Security Assurance ✅ Security Architecture & Design Reviews ✅ Threat Modelling & Risk Identification ✅ Microsoft Security Stack (Identity, Endpoint,...

Learn more

Cyber Security Architect - OutsideIR35

Added 31/07/2026

Security Architect - Consultant Advisory12-Month Contract | Outside IR35 | Hybrid (2 days per week on-site)Location: West London / Greater LondonWe are supporting a major UK transport infrastructure organisation undergoing a significant programme of cyber security improvement and technology transformation.We are seeking an experienced Security Architect Consultant to provide advisory support across a complex digital estate, reviewing security architectures, assessing risks, and supporting the delivery of security improvements across critical technology platforms.This role will involve working with technical teams, architects, and senior stakeholders to review existing security controls, improve security design practices, and support the implementation of secure technology solutions...

Learn more

Cyber Security Engineer (OUTSIDE IR35)

Added 14/07/2026

Cyber Security Engineer - Microsoft 365 & Azure6-Month Contract | Outside IR35 | £350-400 per day | Remote (UK) | 1-2 Days per Month On-Site (South West London)A leading public sector organisation is looking for a Cyber Security Engineer to support a major cyber security improvement programme.Working alongside the Cyber Security, Infrastructure and Platform teams, you'll help deliver a range of security enhancements across Microsoft 365, Azure and AWS, strengthening the organisation's overall security posture while improving identity, endpoint, cloud and data protection capabilities.This is a fantastic opportunity for someone who enjoys hands-on engineering and wants to be involved in...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.