Cyber Threat and Vulnerability Manager

Reference: CTVM_1781529292

As a Cyber Threat & Vulnerability Manager, you will play a key role within the Security Operations function, leading the organisation's threat intelligence, vulnerability management, and intelligence-led testing capabilities across both IT and OT environments. Working closely with cybersecurity leadership, enterprise architects, programme delivery teams, and key business stakeholders, you will ensure that Threat and Vulnerability Management (TVM) services are effective, scalable, and continuously improved.

This role contributes to the cyber resilience by driving a risk-based approach to vulnerability management, embedding threat intelligence into operational and strategic decision-making, and enhancing security maturity across the organisation. You will lead a team of specialists, oversee governance and tooling, and ensure that TVM capabilities align with organisational objectives, regulatory requirements, and evolving threat landscapes.

You must be able to obtain Counter Terrorist Check (CTC) Clearance to be eligible for this position.

What you'll be doing as a Cyber Threat & Vulnerability Manager

  • Lead enterprise vulnerability management, ensuring frameworks for identifying, prioritising, and remediating vulnerabilities are defined, implemented, and continuously improved.
  • Manage the Cyber Threat Intelligence service, ensuring intelligence is collected, analysed, and operationalised to support risk reduction and security operations.
  • Collaborate with technical and business stakeholders to align TVM activities with organisational objectives and risk appetite.
  • Develop and maintain TVM documentation, including policies, standards, procedures, and governance controls.
  • Integrate and optimise vulnerability management, threat intelligence, and assessment tooling across enterprise systems and workflows.
  • Oversee intelligence-informed testing activities, including targeted assessments, exploit validation, and internal testing services.
  • Evaluate and recommend tools, technologies, and vendors to support and enhance TVM capabilities.
  • Investigate newly identified vulnerabilities and coordinate risk-based mitigation and remediation activities.
  • Work closely with technology teams to ensure effective patching, remediation tracking, and resolution of blockers.
  • Maintain and evolve the organisation's cyber threat assessment methodology aligned with industry standards and risk management processes.
  • Lead proactive threat hunting activities to identify emerging threats and suspicious activity across the technology estate.
  • Develop and maintain dashboards, reporting, and operational metrics that demonstrate risk reduction and control effectiveness.
  • Ensure compliance with relevant standards and regulations such as GDPR, NIS, and ISO 27001.
  • Monitor and improve the effectiveness of TVM processes, controls, and supporting technologies.
  • Provide leadership, coaching, and performance management to the TVM and testing team.
  • Build and maintain strong relationships with external intelligence providers, vendors, and delivery partners.
  • Stay current with emerging threats, technologies, and industry best practices to continuously enhance security operations.
  • Support major incident response activities where required as part of Security Operations.

What you should bring to the role

  • Experience leading or managing threat and vulnerability management processes and controls within a complex enterprise environment.
  • Strong experience in vulnerability remediation and patch management across diverse and evolving technology estates.
  • Experience managing cyber risks within dynamic digital and operational technology environments.
  • Ability to line manage and develop a team of security professionals towards shared objectives.
  • Strong analytical, problem-solving, and decision-making skills.
  • Experience managing third-party delivery partners, vendors, and service providers.
  • Excellent communication skills with the ability to explain complex security concepts to non-technical stakeholders.
  • Strong organisational, planning, and strategic thinking capabilities.
  • Innovative mindset with a focus on continuous improvement and measurable risk reduction.
  • Experience producing operational metrics and dashboards that demonstrate TVM effectiveness and cyber maturity improvements.

Technical experience and skills

  • Hands-on experience with vulnerability management and threat intelligence tools such as Tenable and Qualys.
  • Strong understanding of TVM concepts, including vulnerability assessment, threat modelling, OSINT, threat intelligence, and penetration testing.
  • Knowledge of patch management approaches across SaaS, IaaS, end-user computing, server, and enterprise technology environments.
  • Experience implementing risk-based approaches to vulnerability prioritisation and remediation.
  • Ability to develop dashboards and reporting that demonstrate control effectiveness, risk reduction, and technical debt management.
  • Experience aligning security practices with frameworks and regulations such as ISO 27001, NIS, and GDPR.

Desirable qualifications and experience

  • Experience working within utilities, critical infrastructure, or large complex enterprise environments.
  • Experience managing vulnerabilities and cyber risks within operational technology (OT) environments.
  • Familiarity with legacy systems and managing vulnerabilities within ageing technology estates.
  • Experience supporting cyber security transformation programmes and strategic cyber roadmaps.

Desirable technical skills and qualifications

  • Degree in Cyber Security, Computer Science, Information Technology, Engineering, or a related field.
  • Professional certifications such as CISSP, CISM, or CCSP.
  • TVM-specific certifications such as Certified Threat Intelligence Analyst (CTIA) or Certified Vulnerability Assessor (CVA).
  • Knowledge of penetration testing, ethical hacking, or related security assessment practices.

GCS is acting as an Employment Agency in relation to this vacancy.

£80,000.00 - £90,000.00
Per annum
GBP80000 - GBP90000 per annum

Berkshire

Permanent

Added 15/06/2026
Reference: CTVM_1781529292

Cyber Threat and Vulnerability Manager

Berkshire
Permanent

Other similar jobs

Cyber Threat and Controls Consultant - B2B

Added 12/05/2026

Role: Cyber Threat and Controls Consultant - B2BDuration: 6-month rolling contractWorking Pattern: Krakow, Hybrid (handful of days per month)GCS Cyber are partnered with a global financial services organisation undergoing multiple large-scale transformation programmes across their Cyber Security division.In this role you will perform threat and control assessments across the business, you'll partner with architects, developers and cloud specialists across the business to review designs, challenge assumptions, and ensure services are built with strong security foundations. You'll also contribute to improving the threat‑assessment process, sharing your expertise across a global community and helping uplift security practices across the organisation.Must have:Strong understanding...

Learn more

Cyber Threat and Controls Consultant - B2B

Added 06/04/2026

Role: Cyber Threat and Controls Consultant - B2BDuration: 6-month rolling contractWorking Pattern: Krakow, Hybrid (handful of days per month)GCS Cyber are partnered with a global financial services organisation undergoing multiple large-scale transformation programmes across their Cyber Security division.In this role you will perform threat and control assessments across the business, you'll partner with architects, developers and cloud specialists across the business to review designs, challenge assumptions, and ensure services are built with strong security foundations. You'll also contribute to improving the threat‑assessment process, sharing your expertise across a global community and helping uplift security practices across the organisation.Must have:Strong understanding...

Learn more

Cyber Threat Intelligence Lead

Added 12/05/2026

Cyber Threat Intelligence LeadContractIndustry: National Transport & Infrastructure Location: Hybrid (The Hague) Contract Length: 12 monthsAbout the RoleA major transport infrastructure organisation is expanding its national cyber defence capability and seeks a Cyber Threat Intelligence Lead to build its CTI function from the ground up. You will provide strategic and operational intelligence across both IT and OT environments.Key ResponsibilitiesEstablish and lead the organisation's threat intelligence programme.Monitor, analyse, and disseminate intelligence on campaigns targeting OT and transport systems.Collaborate with government partners and private sector information‑sharing groups.Feed intelligence into SOC, IR, and vulnerability management functions.Produce high‑quality threat reports for executive and operational...

Learn more

Cyber Threat Intelligence Lead

Added 07/04/2026

Cyber Threat Intelligence Lead ContractIndustry: National Transport & Infrastructure Location: Hybrid (The Hague) Contract Length: 12 monthsAbout the RoleA major transport infrastructure organisation is expanding its national cyber defence capability and seeks a Cyber Threat Intelligence Lead to build its CTI function from the ground up. You will provide strategic and operational intelligence across both IT and OT environments.Key ResponsibilitiesEstablish and lead the organisation's threat intelligence programme.Monitor, analyse, and disseminate intelligence on campaigns targeting OT and transport systems.Collaborate with government partners and private sector information‑sharing groups.Feed intelligence into SOC, IR, and vulnerability management functions.Produce high‑quality threat reports for executive and...

Learn more

Senior Consultant - AI Security & Threat Modelling

Added 21/04/2026

Senior Consultant - AI Security & Threat Modelling (GenAI / Agentic AI)We are supporting a large, regulated financial services organisation that is building a central GenAI threat‑modelling and consultancy capability. This role sits within a specialist threat‑modelling team, advising GenAI and Agentic AI projects early in design, before solutions reach production. This is not a coding role and not a general cyber role. Key ResponsibilitiesHands‑on threat modelling of GenAI and Agentic AI systemsAdvising application teams on AI‑specific risks, including:Prompt injectionAgent intent hijackingUnsafe autonomy and tool misuseMissing safety rails / kill switches (e.g. MCP‑style controls)Misalignment and behavioural driftActing as an internal...

Learn more

Head of Commercial - Retail, Transport and Mobile

Added 23/04/2026

Role: Head of Commercial - Retail, Transport and MobileReports to: Commercial Director - Technical Services Key Objective:To identify and maximise commercial opportunities and minimise commercial risks associated with the contracts within Retail, Transport and Mobile, whilst ensuring compliance with our obligations. Key Responsibilities: Providing appropriate commercial support to Account directors / account managers for accounts within Retail, Transport and Mobile throughout the account life cycle (including but not limited to preparing and maintaining e.g. contract obligations trackers, contract specific commercial processes, variations / changes, contract notices, etc);Ensure cyclical commercial activities (e.g. annual contract price increases for CiL and indexation) are...

Learn more

Change and Transformation Lead

Added 21/04/2026

Role OverviewWe are seeking an experienced Programme Lead - Change & Transformation to drive a large-scale operational integration programme across multiple business units within a fast-growing organisation.This role will be responsible for delivering a strategic transformation initiative focused on business integration, process standardisation, and synergy realisation, while supporting aggressive growth targets.You must have experience within Power & Grid or Facilities Management or Construction DomainKey ResponsibilitiesLead a complex business transformation programme involving multiple delivery-focused business unitsDrive operational integration across organisations with overlapping capabilitiesIdentify and implement synergies while maintaining individual business identities/brandsEstablish and build a PMO function from scratch, including governance, reporting,...

Learn more

Security Architect (AppSec and Network Security) - B2B

Added 06/04/2026

Role: Security Architect (AppSec and Network Security) - B2BDuration: 6-month rolling contractWorking Pattern: Krakow, Hybrid (handful of days per month)GCS Cyber are partnered with a global financial services organisation undergoing multiple large-scale transformation programmes across their Cyber Security division. They are now looking for a Security Architect who has extensive experience managing end-to-end solution designs within large-scale transformation programmes with a heavy focus on Network Security and Application Security Proven experience producing high-level solution designs in line with business requirements.Proven ability to conduct security assessments and threat modelling to inform design decisions.Strong background in cybersecurity, with deep expertise in network...

Learn more

IT Compliance and Audit

Added 17/03/2026

Tier 1 Bank - Regulatory Reporting TeamRole - IT Compliance and AuditDuration - 6 months with very likely extensionLocation - Hybrid / Canary Wharf - 3 days per week in a Canary Wharf officeRate - £415 per day (Inside IR35)Role IT Compliance Support Engineer to join a development team and act as the primary liaison with internal/external audit, compliance, and IT security counterparts. This role combines governance with technical capability-supporting audits, demonstrating IT controls, and troubleshooting or coordinating resolution of issues across Azure DevOps pipelines, ServiceNow change management, and Jira requirement workflows. You will help us evidence good practice, reduce...

Learn more

AI and Technology Director - Contract

Added 04/03/2026

Director of AI & Technology (Contract)Location: London (Hybrid, 2-3 days onsite) Contract Length: 6-12 months Start: ASAP IR35: TBCDirector of AI & Technology (Contract)We are seeking an experienced Director‑level AI Strategy & Technology leader to drive an organisation's external AI agenda and position them at the forefront of emerging technology across the accounting and professional services landscape.This is a high‑impact, outward‑facing contract focused on thought leadership, market influence, partnership development, and shaping how AI transforms the wider profession.The role does not involve internal AI engineering or delivery. Instead, you will provide vision, external influence, insights, and strategic direction to help...

Learn more

Business Analyst (Housing and Repair Domain)

Added 26/02/2026

This is an analyst-level Business Analyst role within the Information Systems & Change (IS&C) function. The position sits in the Change Delivery & Adoption team, meaning the focus is not just on gathering requirements, but ensuring changes are successfully implemented and adopted by the business.The main purpose of the role is to:Understand business needsDefine clear, structured requirementsImprove processes and servicesEnsure projects deliver measurable business valueSupport smooth implementation and adoption of new systems or improvementsBusiness Analysis & Process ImprovementInvestigate and document current business processesIdentify inefficiencies and areas for improvementEnsure solutions balance cost, quality, and outcomes (value for money focus)Requirements GatheringRun workshops...

Learn more

Cyber Security Manager

Added 11/06/2026

🔐 Cybersecurity Manager (Audit & Compliance) - Los Angeles, CA📍 Location: Los Angeles, CA 📄 Duration: 12+ Month Contract (C2H Possible) 🏢 Work Model: Hybrid🚀 About the RoleJoin as a Cybersecurity Manager leading large-scale security audit and compliance programs. You'll ensure audit readiness, drive remediation, and align enterprise systems with industry standards.🛠️ ResponsibilitiesLead enterprise audit and compliance initiativesOversee risk assessments and vulnerability remediationDrive adherence to ISO 27001, SOC2, NISTPartner with cross-functional teams and stakeholdersProvide executive-level reporting on audit progress✅ Requirements7-10+ years in cybersecurity or compliance rolesExperience with audit, risk, and governance programsStrong stakeholder communication skillsPreferred certifications: CISSP, CISM, CISA, PMP...

Learn more

Cyber Security Manager

Added 11/06/2026

🔐 Cybersecurity Manager (Audit & Compliance) - Irvine, CA📍 Location: Irvine, CA 📄 Duration: 12+ Month Contract (C2H Possible) 🏢 Work Model: Hybrid🚀 About the RoleWe are hiring a Cybersecurity Manager to lead enterprise audit and compliance initiatives, focusing on ISO 27001, SOC2, and NIST frameworks. You'll drive audit readiness, manage remediation efforts, and ensure security compliance across the organization.🛠️ ResponsibilitiesLead internal & external cybersecurity auditsManage audit findings, risk, and remediation effortsEnsure compliance with ISO, SOC2, NIST frameworksCollaborate with IT & Security teams to close gapsTrack and report audit status to leadership✅ Requirements7-10+ years in cybersecurity, audit, or complianceStrong knowledge...

Learn more

OT Cyber Security Delivery Manager

Added 01/06/2026

Role: OT Cyber Security Delivery ManagerDuration: 6 month rollingRate: Up to £650 Inside IR35Location: London (2 days onsite)I'm supporting an urgent requirement for an experienced OT Cyber Security Delivery Manager to drive the delivery of security improvements across a complex OT environment.This role is very much delivery-led, so we need someone who has hands-on experience implementing OT security controls, owning execution across initiatives like IT/OT segmentation, NIS2, and secure access.What we're looking for:Proven experience leading and delivering OT cyber programmes/projects end-to-end (IEC62443 / NIST aligned)Strong experience across ICS/SCADA and OT environmentsAbility to drive delivery across engineering, cyber, and operations teamsTo...

Learn more

OT Cyber Security Project Manager - Fully Remote

Added 06/05/2026

OT Cyber Security Project Manager - 6-month rolling - Inside IR35 - Fully RemoteI'm hiring for an experienced OT Cyber Security Project Manager to lead the delivery of Cyber Security improvements across an Operational Technology environment.Must have managed OT Cyber projects end-to-end, from conception to delivery!If interested, please drop me a message or an email to [email protected] is acting as an Employment Business in relation to this vacancy.

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.