Cyber Security Engineer – Vulnerability Management
Job description
Salary: $160,000 to $180,000 base + super
This is a permanent opportunity for a well-rounded Cyber Security Engineer who has strong Vulnerability Management experience but does not want to be confined to a purely VM-focused role.
Vulnerability Management will be the core responsibility, but you will join a small, multidisciplinary Information Security team where you will also contribute across cloud security, security tooling, penetration testing, remediation activity and broader cyber security initiatives as priorities shift.
The opportunity
You will take ownership of Vulnerability Management end to end — understanding findings, assessing genuine risk, prioritising what matters, identifying the right technical owners and driving remediation through to closure.
The emphasis is not on simply producing scanner reports or passing findings to other teams. You will need enough technical depth to understand the likely impact of a vulnerability, possible remediation or workaround options, and which team needs to act.
The environment is 100% cloud, with Qualys as the primary Vulnerability Management platform alongside several other security tools.
This is also a role where you will not be siloed. The security team is small, so when priorities change you will have the opportunity to contribute to broader Information Security work and projects.
Why this role stands out
- Brand-new permanent headcount with genuine ownership
- Small Information Security team with broad exposure across cyber
- 100% cloud environment
- Qualys plus multiple security platforms
- Exposure to penetration testing and remediation of findings
- Opportunity to work beyond pure VM governance and reporting
- Scope to contribute to wider security projects and capability uplift
What you’ll be doing
- Own the Vulnerability Management lifecycle from identification through to remediation and closure
- Analyse and prioritise vulnerabilities based on exploitability, exposure, asset criticality and business impact
- Work closely with Infrastructure, Cloud, Application and Security teams to drive remediation
- Manage and optimise Qualys and other security tooling
- Coordinate penetration testing activity and remediation of findings
- Maintain vulnerability SLAs, exceptions, risk acceptance and escalation processes
- Improve reporting, workflow automation and remediation visibility
- Contribute to cloud security, security tooling and broader cyber initiatives
- Support wider Information Security activity where team priorities require it
What you’ll bring
You do not need to have spent your entire career in Vulnerability Management. In fact, this role will particularly suit someone with a broader Cyber Security Engineering or Security Operations background who has meaningful VM experience within that broader remit.
You will ideally bring:
- 5+ years across Cyber Security / Information Security
- Strong hands-on Vulnerability Management experience
- Experience with Qualys, Tenable, Rapid7, Wiz or similar platforms
- Good technical understanding across cloud, infrastructure and applications
- Experience driving remediation with technical teams
- Strong risk-based prioritisation and vulnerability analysis skills
- Exposure to penetration testing and remediation tracking
- Broader experience across areas such as cloud security, security operations, endpoint security, SIEM/EDR, DevSecOps, application security or security engineering
- Strong stakeholder communication skills
- Ability to work effectively in a small team where responsibilities extend beyond a single security discipline
Experience within financial services or another regulated environment would be advantageous, as would exposure to frameworks such as ISO 27001 or NIST.
Who this will suit
This could suit someone currently working as a:
- Cyber Security Engineer
- Senior Cyber Security Analyst
- Security Operations Engineer
- Security Engineer
- Vulnerability Management Specialist with broader security experience
It is less likely to suit someone whose recent experience has been exclusively focused on Vulnerability Management reporting/governance, or someone operating at Head of Cyber / senior architecture level.
If you enjoy Vulnerability Management but want a role where you can also broaden your exposure across Cyber Security, this is a strong opportunity to take greater ownership while remaining hands-on.
To discuss the role confidentially, contact Amanda Evans at The Recruitment Company.
Skills mentioned
Apply for this job
Use the application link supplied with this listing to apply to The Recruitment Company. Check the destination before entering personal information.

