
Search by job, company or skills

The Vulnerability Response Specialist is part of the Vulnerability Response Squad, an operational extension of the Vulnerability Advisory (VA) and Security Vulnerability Lifecycle Management (SVLM) functions, established to provide enhanced response capability and 24x7 coverage for notable vulnerability events. Following assessment and prioritisation by VA, the squad assumes end-to-end ownership of high-risk vulnerabilities, including zero-day, out-of-band (OOB), actively exploited, and other critical threats. Leveraging Incident Management processes, the role drives stakeholder coordination, communications, escalation, risk mitigation, and remediation activities through to closure, ensuring timely reduction of cyber risk exposure. The ideal candidate combines strong vulnerability management knowledge, incident coordination experience, analytical thinking, and stakeholder management skills, with the ability to analyse large volumes of vulnerability and threat intelligence data, translate technical risk into business impact, and drive timely remediation in a fastpaced 24x7 cyber response environment. Regular on-site presence is required to support stakeholder engagement, operation and incident coordination, and management of critical vulnerability events. Role Purpose Act as the operational response arm of the VA and SVLM functions by providing 24x7 coverage and end-to-end management of notable vulnerabilities. Following assessment by VA, the role leverages Incident Management processes to coordinate stakeholders, drive communications, escalate risks, and accelerate mitigation and remediation activities through to closure, ensuring timely reduction of cyber risk exposure. Key Responsibilities Vulnerability Response Management • Assume operational ownership of notable vulnerabilities following VA assessment and prioritisation. • Drive end-to-end response activities for zero-day, out-of-band (OOB), actively exploited, and other highprofile vulnerabilities. • Coordinate cross-functional stakeholders to execute mitigation and remediation activities. • Establish and lead vulnerability response bridges, action tracking, and escalation activities. • Drive execution of vulnerability response playbooks and response procedures • Maintain continuous oversight of vulnerability response activities until risk mitigation or remediation is completed. Incident Management & Stakeholder Coordination PUBLIC • Leverage Incident Management processes to accelerate remediation and stakeholder mobilisation. • Coordinate Cyber Defence, Platform Teams, Asset Owners, Technology SMEs, and Incident Management teams during vulnerability events. • Drive stakeholder communications, executive updates, situation reporting, and escalation activities. • Escalate critical risks, blockers, and delayed remediation activities through appropriate governance channels. • Support post-incident reviews and continuous improvement initiatives. Remediation Oversight • Drive remediation activities through to closure, ensuring accountability and timely execution. • Track remediation commitments, milestones, dependencies, and residual risks. • Challenge and escalate overdue actions where required. • Validate completion of agreed mitigation and remediation actions. • Support management reporting on remediation progress and risk reduction outcomes. 24x7 Vulnerability Response Coverage • Participate in on-call, weekend, after-hours, and follow-the-sun support arrangements. • Provide operational coordination during high-severity vulnerability events outside standard business hours. • Support continuous vulnerability response coverage for critical cyber threats. • Ensure timely stakeholder mobilisation during active exploitation and major vulnerability incidents. Key Skills & Experience Vulnerability Management • Strong understanding of vulnerability management concepts, CVE, CVSS, exploitability assessment, threat intelligence, and cyber risk management. • Ability to understand vulnerability assessments and translate risk into actionable remediation plans. • Knowledge of vulnerability prioritisation, attack surface exposure, and threat landscape trends. Incident & Crisis Management • Experience coordinating Major Incident, Cyber Incident, or Technology Incident response activities. • Strong understanding of escalation management, crisis communications, and stakeholder coordination. • Experience leading bridge calls, action tracking, executive reporting, and operational response activities Remediation Governance & Oversight PUBLIC • Experience driving remediation activities across multiple technology and infrastructure teams. • Understanding of remediation governance, risk reduction strategies, compensating controls, and risk treatment plans. • Ability to influence stakeholders and drive accountability for remediation outcomes.
Job ID: 151477315