Threat & Vulnerability Manager (FTC) at Bertelsmann-Jobs | GB | Rezi

Threat & Vulnerability Manager (FTC) at Bertelsmann-Jobs

Threat & Vulnerability Manager (FTC)

Bertelsmann-Jobs · GB

Today

Threat & Vulnerability Manager (FTC)

Bertelsmann-Jobs · GB

3 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Threat & Vulnerability Manager (FTC) role.

Rezi rewrites your resume against Bertelsmann-Jobs's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Threat & Vulnerability Manager (FTC) posting at Bertelsmann-Jobs — free, in seconds.

About the Role

This role is for an experienced Threat and Vulnerability Manager on a 7-month fixed-term contract to cover parental leave. You will own the threat and vulnerability management capabilities, leading identification, assessment, and remediation of vulnerabilities. You will also support security operations, monitor threats, and respond to incidents, working to improve the company's security posture and reduce cyber risk.

Responsibilities

  • Ensure vulnerability detection and remediation controls and platforms are properly configured and operating effectively.
  • Promptly assess new or emerging vulnerabilities and lead internal efforts to resolve or mitigate them based on severity.
  • Provide guidance and recommendations on emergency patching based on threat assessments.
  • Act as a subject matter expert and product owner for enterprise VM tooling in collaboration with infrastructure and security architects.
  • Coordinate vulnerability scanning and penetration testing, and manage the technical remediation of findings.
  • Proactively challenge and drive improvements in end-to-end vulnerability management processes.
  • Scope, prioritize, and lead service improvement initiatives for vulnerability management platforms and processes.
  • Provide leadership and direction on vulnerability management and mitigation across endpoints, servers, networks, and applications.
  • Continually improve security posture through collaborative vulnerability remediation efforts.
  • Produce metrics and KPIs evidencing vulnerability analysis and risk reduction.
  • Chair Patching and Vulnerability Management forums.
  • Assure all BAU vulnerability management processes managed by Security Operations or nominated MSSPs.
  • Drive technical integrations between VM platforms to leverage automation and threat/vulnerability intelligence.
  • Monitor internal and external cyber threats and ensure technical controls align.
  • Support the operation of key security controls, including endpoint protection, DDoS protection, web security, and email security.
  • Support security incident and event management, including log reviews and alert creation.
  • Respond rapidly to, detect, isolate, and remediate information security incidents.
  • Report to management on incidents and incident prevention activities.
  • Conduct periodic reviews of security technology for adherence to policy.
  • Ensure audit trails and system logs are reviewed in line with policy and audit requirements.
  • Support the delivery of ongoing security initiatives and projects.

Requirements

  • Demonstrable experience of using VM tooling at an enterprise level and supporting or leading enterprise VM programmes.
  • Previous experience of patch management processes.
  • Ability to demonstrate broad and deep vulnerability knowledge and experience across Infrastructure, Cloud, Applications, and Networks.
  • Good understanding of threats and threat vectors.
  • Hands-on experience of information security incident handling.
  • Ability to build and maintain collaborative relationships with various stakeholder groups.
  • Ability to be an advocate for informed, risk-based vulnerability management.
  • Good understanding of Web Application Security frameworks, common vulnerabilities, and associated remediations.
  • Excellent verbal and written communication skills, with the ability to explain the business impact of security risks, tools, and policies to diverse audiences.
  • Ability to work under pressure.
  • Proven problem-solving and decision-making experience.

Skills

  • CISSP
  • SANS
  • Python
  • Perl
  • PowerShell
  • Open-Source Threat Intelligence

Location

  • Embassy Gardens, London
  • Frating, Colchester

Work Type

  • Hybrid working
  • Fixed-term contract

Experience Level

  • Experienced

Education Level

  • Technical accreditations such as CISSP, SANS or other relevant security credentials
  • Degree

Salary/Compensations

  • £60,000-£65,000

Benefits

  • Generous bonus scheme

About the Company

  • The Technology team provides expertise and effective solutions to Penguin Random House.
  • We integrate flexibility and agility which supports our consistent way of working.
  • We set ourselves up for success by holding ourselves accountable and welcoming change.
  • Each member of the Technology team brings skill and initiative to their role; we take personal ownership within a one team culture, working collaboratively to meet expectations from our stakeholders who trust us to deliver.

Equal Opportunity

  • As a Disability Confident Committed organisation, we offer interviews to candidates with a disability who meet the essential criteria for the role, and opt-in on their application form.
  • We encourage you to tell us about any reasonable adjustments you may need by emailing [email protected](opens in new window).