HomeJobsNorth WestManchesterCyber Security Manager - Vulnerability Management
Back to all jobs
⚡ Source: ReedRef: 56992653

Cyber Security Manager - Vulnerability Management

Statera Talent·Manchester, North West·Posted 6 days ago
💰 £100-120k/year⭐ Senior
Tailor my CV for this job — Free

Job description

Original text imported from Reed

Statera Talent is working on a senior Cyber Security leadership role with a well respect global financial organisation.

This is a high-visibility position focused on leading a global vulnerability risk programme across a complex technology environment. It would suit someone who can combine technical security knowledge with strong risk judgement, stakeholder management and the ability to drive remediation across multiple teams.

The role sits around vulnerability risk, but it is broader than simply managing scan outputs. The successful candidate will help bring together security findings from across infrastructure, cloud, application security, open-source software and testing activity, then ensure the business has a clear, risk-based view of what needs to be prioritised.

The role

You will be responsible for leading and developing a vulnerability risk function across a global technology environment.

This will include improving how security findings are assessed, prioritised, tracked and reported, while working closely with security, engineering, infrastructure, application and technology teams to ensure remediation is aligned to business risk.

The role will involve:

  • Leading a global vulnerability risk programme
  • Bringing structure and consistency to how vulnerabilities are assessed and prioritised
  • Overseeing findings from infrastructure, cloud, application security, open-source software and security testing
  • Helping define what should be treated as a genuine business risk priority
  • Working with technical teams to support effective remediation
  • Producing clear dashboards, metrics and reporting for senior stakeholders
  • Improving governance, process and visibility across the vulnerability lifecycle
  • Supporting a more risk-based approach to vulnerability management

What this role is really about

  • This is not just a role focused on identifying security issues.
  • It is about helping the business answer:
  • What are our most important security weaknesses?
  • Which issues genuinely carry the greatest business risk?
  • Who owns the fix?
  • How quickly are issues being remediated?
  • What does senior leadership need to know?

Relevant backgrounds

We are interested in speaking with people from a range of Cyber Security backgrounds. Your current job title does not need to be specifically vulnerability focused.

The key requirement is experience owning, leading or playing a significant role in vulnerability management, remediation tracking, risk prioritisation and stakeholder reporting within a sizeable or complex organisation.

Experience likely to be useful

The successful candidate is likely to have experience with some or all of the following:

  • Vulnerability management across infrastructure, cloud and applications
  • Risk-based prioritisation beyond basic severity scoring
  • Security testing outputs such as SAST, DAST, SCA, infrastructure scanning, CSPM or penetration testing
  • Working with engineering, infrastructure, application and security teams to drive remediation
  • Executive-level reporting, dashboards, metrics or risk updates
  • Building, improving or maturing security processes
  • Leading people, projects or security programmes
  • Operating in a global or enterprise-scale environment

Apply today to find out more!

SpeedCV AI

Key skills

AI-extracted from the job advert

Must-have skills
Vulnerability management across infrastructure, cloud and applicationsRisk-based prioritisationRemediation trackingSecurity testing outputs (SAST, DAST, SCA, infrastructure scanning, CSPM or penetration testing)Executive-level security reportingSecurity governance
Nice-to-have
CSPM toolingOpen-source software security (SCA)Penetration testing programme managementCloud security posture management
Soft skills
Stakeholder managementRisk judgementLeadershipCommunicationPrioritisationInfluencing without authority
SpeedCV AI

Application advice

5 AI-generated recommendations to maximise your chances.

1

⭐ Lead your CV personal statement with explicit mention of 'global vulnerability risk programme' ownership — the advert flags this as the core mandate in the opening paragraph.

2

📊 Quantify your remediation impact: e.g. 'Reduced critical vulnerability backlog by 62% across 4,000 assets within 6 months' — the advert specifically asks how quickly issues are remediated.

3

🛠️ List each tool category explicitly (SAST, DAST, SCA, CSPM, infrastructure scanning) in a dedicated Skills section — the advert names all five and ATS will scan for them individually.

4

🎯 Include a bullet demonstrating executive-level reporting: e.g. 'Produced monthly risk dashboards for CISO and board, covering 3 global regions' — the advert calls out senior stakeholder visibility as a key deliverable.

5

🌐 Highlight experience in complex, multi-team environments (engineering, infrastructure, application, security) to show you can drive cross-functional remediation — the advert emphasises this coordination repeatedly.

NEW
AI SpeedCV

Suggested CV bullets

3 bullets our AI drafted for this specific advert, mirroring its ATS keywords.

How to tailor your CV

Add these 3 bullets under your most recent experience:

  • Established a risk-based vulnerability prioritisation framework across 6,000 assets spanning on-premises infrastructure and three cloud platforms, reducing critical backlog by 58% within 9 months.
  • Unified SAST, DAST, SCA and CSPM findings into a single governance dashboard, enabling the CISO to report on top-20 business risks to the board on a fortnightly cadence.
  • Led cross-functional remediation working groups across 5 engineering and infrastructure squads, improving mean-time-to-remediate for high-severity vulnerabilities from 47 days to 18 days.

Free to copy — tailoring requires a 30-sec CV upload.

NEW
AI cover letter

Your cover letter is ready

We've drafted a cover letter for Statera Talent. Preview the opening, then unlock the full personalised version.

Letter preview — tailored to Statera Talent

Dear Hiring Manager,

Statera Talent's search for a Cyber Security Manager – Vulnerability Management at a global financial organisation is precisely the kind of leadership challenge I have been building towards. My experience in risk-based vulnerability prioritisation and cross-functional remediation governance maps directly to the programme maturity and executive visibility this role demands.

My background in leading vulnerability risk functions across complex, multi-cloud environments has equipped me to consolidate findings from SAST, DAST, SCA, CSPM and infrastructure scanning into a coherent, business-risk-aligned view. I have worked alongside engineering, infrastructure and application teams to enforce remediation SLAs, and have delivered monthly dashboards to C-suite stakeholders covering critical exposure trends across global technology estates. I understand that vulnerability management at this level is fundamentally a risk communication and governance challenge, not simply a scanning exercise.

Get my personalised letter — free

Free signup, no card needed. Export to PDF/Word requires a £1.99 trial (14 days).

SpeedCV exclusive
SpeedCV AI

Interview questions

10 questions generated from this advert.

Technical

  • How do you move beyond CVSS scores to build a genuinely risk-based vulnerability prioritisation model?
  • Walk us through how you would integrate findings from SAST, DAST, SCA and CSPM into a single unified risk view.
  • What metrics and KPIs would you put in front of a CISO to demonstrate the health of a global vulnerability programme?
  • How do you handle vulnerability ownership disputes between infrastructure, application and engineering teams?
  • Describe your approach to tracking remediation SLAs at scale across a complex, multi-cloud environment.

Behavioural

  • Tell me about a time you had to convince senior leadership to prioritise a security risk that was not on their radar.
  • Describe a situation where you inherited a poorly structured vulnerability programme — what did you change and what was the outcome?
  • Give an example of driving remediation across teams who did not report to you and had competing priorities.
  • Tell me about a time a critical vulnerability required rapid escalation — how did you manage communication upwards and across teams?
  • Describe how you have improved governance or process visibility within a security function and the measurable impact it had.
SpeedCV AINEW

STAR answer examples

Model answers using the Situation-Task-Action-Result framework. Adapt to your own experience.

1Question

Describe a situation where you inherited a poorly structured vulnerability programme — what did you change and what was the outcome?

Situation: When I joined a 3,500-person financial services firm, the vulnerability programme consisted of weekly Qualys scan exports emailed to 12 different team inboxes with no ownership model or SLA framework. Task: I was asked to build a coherent, risk-prioritised programme within one quarter. Action: I introduced a risk-scoring model layering asset criticality and exploitability on top of CVSS, created a centralised Jira-based remediation tracker with defined owners, and ran fortnightly triage calls with infrastructure and engineering leads. Result: Within four months, critical vulnerability closure rates improved from 34% to 79%, and the CISO was able to present a clean risk heatmap to the board for the first time.
2Question

Give an example of driving remediation across teams who did not report to you and had competing priorities.

Situation: A CSPM scan identified 47 high-severity misconfigurations across three AWS accounts owned by separate product engineering teams, all of whom had active sprint commitments. Task: I needed full remediation within 30 days to meet a regulatory deadline without formal authority over any of the teams. Action: I escalated the business-risk context to each team's engineering director, translated each finding into a one-page impact brief in non-technical language, and negotiated a shared backlog slot with the CTO's support. I held weekly 20-minute standups to unblock dependencies. Result: All 47 findings were remediated in 26 days, and the process was adopted as the standard model for future cross-team security sprints.

Similar jobs

View all