Skip to main content
AfterDuty

Vulnerability Management Specialist

HCLTech · London, Greater London

Type
Contract
Posted
5 days ago

Overview

Your ability to follow strict procedures and document findings accurately supports vulnerability tracking.

About this role

We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products.HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here. We’ve always approached our work with an idea-first attitude because every one of our accomplishments —no matter how big or small —can be traced back to an idea’s single spark.

It’s that spark —that inner drive —that sets our people apart from our competitors. It enables us not just to pull off game-changing feat after game-changing feat but to better our world in the process. We want you to find your spark. Because that’s what drives you to be better, be more and ultimately, be more fulfilled.

Domain

Vulnerability Management (Cross-Domain)

Level

L1 – Junior

Experience

2– 3 years in IT security / infrastructure support

Education

B.Tech / BCA / B.Sc. (Computer Science / IT / Cybersecurity) or equivalent

The L1 Vulnerability Management Analyst supports the organisation's vulnerability identification and tracking programme across End User Computing, Data Center, Network, and Application Infrastructure domains. The role focuses on executing scheduled scans, processing scan outputs, tracking remediation progress, and co-ordinating with patch teams to drive closure of identified vulnerabilities.

KEY RESPONSIBILITIES

  • Execute scheduled vulnerability scans across endpoint, server, network, and application environments using tools such as Qualys, Tenable Nessus, or Rapid7 InsightVM.
  • Process and validate scan results: filter false positives, normalise findings, and classify vulnerabilities by CVE, CVSS score, and asset criticality.
  • Distribute vulnerability reports to the relevant patch management and infrastructure teams (EUC, Data Center, Networks, App Infra) for remediation.
  • Track remediation status against defined SLAs (Critical: 72 hrs, High: 7 days, Medium: 30 days, Low: 90 days) and follow up with asset owners.
  • Update vulnerability tracking dashboards and ITSM tickets with remediation progress and exceptions.
  • Assist in maintaining the asset inventory and ensuring scan coverage across all known assets.
  • Flag newly identified critical or zero-day vulnerabilities to the L2 engineer and SOC team immediately.

TECHNICAL SKILLS & KNOWLEDGE

  • Basic understanding of vulnerability scanning concepts: authenticated vs unauthenticated scans, scan policies, and asset groups.
  • Familiarity with vulnerability management tools: Qualys VMDR, Tenable Nessus, or Rapid7 InsightVM.
  • Ability to read and interpret CVE entries, CVSS v3 scores, and vendor advisories.
  • Basic knowledge of OS platforms (Windows, Linux) and network devices sufficient to contextualise findings.
  • Awareness of common vulnerability categories: unpatched OS/applications, misconfigurations, end-of-life software, weak credentials.
  • Working knowledge of ITSM platforms (ServiceNow, Remedy) for ticket creation and tracking.
  • Basic Excel / reporting skills for vulnerability metrics and trend tracking.

SOFT SKILLS & COMPETENCIES

  • Detail-oriented – accurately classifies and tracks large volumes of vulnerability data.
  • Good written communication for distributing reports and following up on remediation.
  • Organised and deadline-driven to maintain SLA adherence across multiple teams.
  • Team player – works closely with patch, SOC, and infrastructure teams.
  • Willingness to learn threat landscape and security concepts rapidly.

PREFERRED CERTIFICATIONS

  • CompTIA Security+
  • Qualys Certified Specialist – Vulnerability Management
  • Tenable Nessus Fundamentals (Tenable University)
  • ITIL 4 Foundation
  • CEH (Certified Ethical Hacker) – advantageous

Domain

Vulnerability Management (Cross-Domain)

Level

L2 – Mid-Level

Experience

3 – 6 years in vulnerability management / information security

Education

B.Tech (Computer Science / Cybersecurity / IT) or equivalent

ROLE SUMMARY

The L2 Senior Vulnerability Management Engineer owns the organisation's end-to-end vulnerability management programme, spanning EUC, Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement of the VM programme.

KEY RESPONSIBILITIES

  • Own and operate the enterprise vulnerability management programme across all technology domains (endpoints, servers, network devices, web applications, cloud).
  • Design and maintain scan policies, asset groups, and scanning schedules in Qualys VMDR / Tenable Security Centre / Rapid7 InsightVM to ensure full coverage.
  • Perform risk-based vulnerability prioritisation: correlate CVSS scores with asset criticality, exposure, threat intelligence (EPSS, CISA KEV), and business context.
  • Translate vulnerability findings into actionable remediation tasks for patch management teams across EUC, Data Center, Networks, and Application Infra; define acceptance criteria for closure.
  • Define, publish, and enforce the VM SLA policy; escalate breaches to asset owners and management.
  • Lead the vulnerability exception and risk acceptance process: assess compensating controls, document residual risk, and obtain formal sign-off.
  • Integrate VM tooling with SIEM (Splunk, Microsoft Sentinel), ITSM (ServiceNow VR module), and CMDB for automated ticket creation and asset correlation.
  • Automate vulnerability reporting and remediation tracking using Python, REST APIs (Qualys/Tenable API), or ServiceNow workflows.
  • Conduct threat-informed vulnerability analysis: monitor NVD, CISA KEV, vendor security advisories, and threat intelligence feeds to identify exploitable CVEs requiring emergency response.
  • Lead response to zero-day vulnerabilities: assess impact across the estate, co-ordinate emergency patching or compensating controls, and communicate status to security leadership.
  • Own web application vulnerability management: integrate DAST/SAST findings (Burp Suite, Checkmarx, Veracode) into the unified VM programme.
  • Manage cloud vulnerability posture: AWS Inspector, Microsoft Defender for Cloud, or Prisma Cloud for hybrid cloud environments.
  • Produce monthly VM programme dashboards, KPIs, and trend analysis for CISO and management review.
  • Act as L2 escalation for L1 analysts; mentor team members and review scan configurations and reports.
  • Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence.

TECHNICAL SKILLS & KNOWLEDGE

  • Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre / Tenable.io, or Rapid7 InsightVM.
  • Strong understanding of CVE/CVSS v3.1 scoring, EPSS (Exploit Prediction Scoring), and CISA Known Exploited Vulnerabilities (KEV) catalogue.
  • Experience with web application scanning: Burp Suite Pro, OWASP ZAP, Tenable Web App Scanning, or HCL AppScan.
  • Cloud security posture: AWS Inspector, Microsoft Defender for Cloud, Prisma Cloud, or Wiz.
  • Container and image vulnerability scanning: Trivy, Snyk, Anchore, or Aqua Security.
  • Automation and API integration: Python scripting, REST API calls to Qualys/Tenable/Rapid7; ServiceNow VR module configuration.
  • SIEM integration: Splunk, Microsoft Sentinel – correlating vulnerability data with threat events.
  • CMDB-driven asset correlation: ServiceNow CMDB, ensuring VM data reflects accurate asset inventory.
  • Patch management workflow knowledge across Windows (SCCM/Intune), Linux (Satellite/Ansible), and network devices – to drive effective remediation co-ordination.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Working to legislation & regulation
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 3 days ago

  • Full-time

    £61,440 – £69,120Estimated

    Your risk assessment and analytical skills from policing transfer directly to cyber assurance.

    Posted 5 days ago

  • Director - Risk Management

    SHI International · London

    Full-time

    Your threat assessment and multi-agency command experience directly transfer to building enterprise risk frameworks and governance.

    Posted 5 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 5 days ago