Role Overview
We are seeking an experienced Vulnerability Management Engineer to own vulnerability discovery, prioritisation, and remediation tracking across Azure and GCP environments during a critical integration programme.
This role requires strong Azure expertise, with GCP experience desirable.
You will work closely with engineering teams to identify, prioritise, and remediate security vulnerabilities while leveraging Infrastructure-as-Code and automation to improve security outcomes.
Responsibilities
- Vulnerability Discovery & Triage
- Scan Azure and GCP infrastructure for known vulnerabilities using Datadog, Sentinel, or equivalent tooling.
- Integrate with SCA/SBOM tools such as Snyk for dependency scanning.
- Prioritise vulnerabilities based on CVSS score, exploitability, and business impact.
- Maintain a live vulnerability register and risk dashboard.
- Remediation Governance
- Maintain and execute emergency patching runbooks.
- Coordinate patch deployment across engineering teams.
- Track remediation SLAs and escalate blockers where necessary.
- Validate remediation activities through re-scanning and verification.
- Automation & Infrastructure-as-Code
- Use Terraform to automate vulnerability remediation workflows.
- Build CI/CD pipelines for patch verification and evidence collection.
- Automate scan scheduling and reporting.
- Develop reusable runbooks for common remediation activities.
- Integration Support
- Assess Azure and GCP security posture during a major cloud integration programme.
- Identify integration-related vulnerabilities and emerging attack surfaces.
- Coordinate with infrastructure teams to ensure secure system migrations.
- Support Snowflake security assessments, including access controls, encryption, and auditing.
- Continuous Improvement
- Support AI-assisted security analysis and automation initiatives.
- Evaluate threat intelligence and emerging vulnerabilities.
- Recommend security hardening opportunities based on industry best practice.
- Produce vulnerability intelligence and reporting to support detection engineering teams.
Required Experience & Skills
- Vulnerability Management & Security
- Strong experience in Vulnerability Management and/or Application Security Engineering.
- Deep hands-on Azure administration experience, including subscriptions, resource groups, IAM, and networking.
- Experience with vulnerability scanning and management platforms such as Datadog and Microsoft Sentinel.
- Technical Engineering
- Strong Terraform and Infrastructure-as-Code experience.
- Python and/or PowerShell Scripting for automation and reporting.
- SQL skills for reporting and vulnerability analysis.
- Good understanding of CVSS scoring and risk prioritisation methodologies.
- Cloud & Data Platforms
- Azure Security Centre, Azure Policy, and Entra ID experience.
- Understanding of GCP security concepts desirable.
- Knowledge of Snowflake security fundamentals.
- Experience with container security and vulnerability scanning.
- Security & Compliance
- Knowledge of DORA, FCA, and SOC2 requirements.
- Understanding of patch management and change control processes.
- Experience with SBOM and Software Composition Analysis (SCA) tooling.
- Comfortable working in a fast-paced, regulated environment.