Threat and Vulnerability Management Lead

Nuffield Health, City of Westminster

Threat and Vulnerability Management Lead

Salary not available. View on company website.

Nuffield Health, City of Westminster

  • Full time
  • Temporary
  • Onsite working

Posted 1 week ago, 14 Jul | Get your application in now before you're too late!

Closing date: Closing date not specified

Job ref: 3ffe57bc6bae475483a51806b7134780

Location ref: City of Westminster

Full Job Description

This is an exciting opportunity to shape and mature our vulnerability management capability, driving the evolution from traditional vulnerability management to a risk-based Exposure Management and CTEM approach. You will define the operating model, influence strategic direction, enhance tooling and processes, and work closely with technology and business stakeholders to reduce cyber risk across a complex healthcare environment.,

  • Lead and continuously improve Nuffield Health's enterprise-wide Threat and Vulnerability Management programme, driving the transition to a mature Exposure Management and CTEM operating model.
  • Own the end-to-end vulnerability lifecycle, ensuring effective discovery, risk-based prioritisation, remediation governance, exception management and reporting.
  • Develop and manage the VM tooling, patching and automation roadmap, enhancing security visibility, ITSM integration, scanning coverage and operational efficiency.
  • Partner with internal technology teams and third-party providers to drive timely remediation, oversee patch deployment activities and strengthen accountability for risk reduction.
  • Deliver meaningful dashboards, KPIs and executive reporting that provide clear insight into cyber exposure, remediation progress and overall security posture.

    Proven expertise leading Threat and Vulnerability Management (TVM) within a complex enterprise environment, with strong technical knowledge across on-premises, cloud and internet-facing infrastructure.
  • Hands-on experience with vulnerability management platforms such as Qualys and/or Microsoft Defender for Endpoint, including configuration, scanning, analysis and reporting.
  • Strong understanding of risk-based and exposure-led vulnerability prioritisation, leveraging threat intelligence, EPSS, attack-path analysis, asset criticality and business impact alongside CVSS.
  • Experience owning the full vulnerability lifecycle, including discovery, triage, remediation governance, exception management, executive reporting and continuous improvement.
  • Knowledge of security frameworks and standards including ISO 27001, Cyber Essentials Plus and CIS Controls.
  • Excellent stakeholder management, communication and influencing skills, with the ability to translate technical risks into actionable business outcomes.
  • Strategic mindset with the ability to build and mature a security capability, drive CTEM adoption, and measure success through meaningful exposure reduction metrics.

    We want you to love coming to work, feeling healthy, happy and valued. That's why we've developed a benefits package with you in mind. Here, you can choose from a range of fitness, lifestyle, health and fitness wellbeing rewards, such as free gym membership, health assessments, retail discounts and pension options.

Direct job link

https://www.jobs24.co.uk/job/threat-vulnerability-management-lead-127107783

About this company

Nuffield Health

View full company profile