All Jobs Vacancy

Vulnerability Management Consultant

Posted 1 day ago by Whitehall Resources

Role Description

The Vulnerability Management Consultant operates within the Operational Integrator (OI) function in a multi-supplier (SIAM) environment, supporting the governance and coordination of vulnerability management activities across suppliers.

The role assists in ensuring vulnerabilities are identified, tracked, prioritised, and reported in accordance with client policies and agreed remediation timelines. Working with suppliers, service teams and security stakeholders, the consultant provides visibility of vulnerability status and supports the maintenance of accurate reporting and audit evidence.

Vulnerability Tracking & Coordination

  • Support the monitoring of vulnerabilities from identification through to closure
  • Ensure vulnerability records are maintained and updated by suppliers
  • Assist in tracking remediation progress against agreed service levels
  • Escalate overdue or high-risk vulnerabilities through agreed governance channels

Supplier Engagement (SIAM Model)

  • Coordinate with suppliers to obtain vulnerability status updates
  • Support the collection and validation of supplier vulnerability reports
  • Ensure reporting formats and data standards are applied consistently
  • Identify gaps in vulnerability information, ownership, or reporting

Vulnerability Reporting & Visibility

  • Produce routine vulnerability management reports
  • Support development of dashboards and metrics
  • Assist in identifying:
  • Aging vulnerabilities
  • Recurring issues
  • SLA breaches
  • Emerging vulnerability trends

Governance & Process Compliance

  • Support adherence to agreed vulnerability management processes
  • Ensure supplier activities align with client policies and standards
  • Assist with documenting risk acceptance and exception processes
  • Maintain evidence required for audits and assurance activities

Assurance & Evidence Support

  • Collect and organise vulnerability management evidence
  • Support compliance and assurance reviews
  • Maintain audit-ready documentation and reporting records
  • Assist in demonstrating process effectiveness to stakeholders

Skills and experience

Essential

Experience in cyber security, information security, service management, or governance roles

Understanding of vulnerability management principles

Knowledge of basic vulnerability risk concepts including:

CVSS, KEV etc

Risk ratings

Remediation tracking

Strong analytical and reporting skills

Experience working with multiple stakeholders

Desirable

  • Exposure to SIAM or multi-supplier environments
  • Familiarity with vulnerability management tooling and reporting outputs
  • Understanding of cyber security governance and assurance
  • Experience in regulated or defence environments
Rate:
Not specified
Location:
United Kingdom
IR35 Status:
Inside
Remote Status:
Not specified
Industry:
Cybersecurity
Seniority Level:
Not Specified

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job