Technical Vulnerability Management Engineer
Key details
Job Description
Salary: £? - ? per year
Requirements
- Hands-on experience in penetration testing or offensive security.
- Good understanding of how vulnerabilities are discovered, exploited and remediated.
- Strong Linux knowledge and confidence working from the command line.
- Scripting experience using Python, Bash or similar.
- Familiarity with CVE, CVSS, NVD and common vulnerability management practices.
- A methodical approach to analysing technical risk and prioritising remediation.
- Strong communication skills with the ability to explain technical issues to non-security stakeholders.
- Experience in a technical security role such as Penetration Testing, Offensive Security, Application Security or Vulnerability Management.
- Experience with vulnerability management platforms such as Tenable, Qualys, Rapid7 or Microsoft Defender VM is beneficial.
- Knowledge of OWASP Top 10, security automation, enterprise vulnerability management or cloud infrastructure security is beneficial.
- Relevant certifications such as OSCP, CREST CRT or GPEN are beneficial.
Responsibilities
- Analyse newly published CVEs and security advisories to understand technical impact and exploitability.
- Assess the potential impact of vulnerabilities across enterprise infrastructure and systems.
- Identify affected assets using internal tooling and vulnerability data sources.
- Work closely with engineering and system owners to prioritise and coordinate remediation activities.
- Write Python, Bash or similar scripts to automate repetitive analysis and operational tasks.
- Produce clear technical documentation, vulnerability assessments and remediation guidance.
- Support ongoing improvements to vulnerability management processes.
Technologies
- Bash
- Cloud
- Support
- Linux
- OWASP
- Python
- Security
More
We are supporting one of the worlds leading technology companies in hiring a contractor to join our Information Security Assurance team. This is an excellent opportunity for someone with a background in penetration testing or offensive security who enjoys understanding how vulnerabilities work and helping engineering teams reduce security risk at scale. Rather than carrying out traditional penetration testing engagements, we analyse newly disclosed vulnerabilities, assess their potential impact across a large enterprise environment and work with internal stakeholders to drive remediation. The role is based in London with 3 days onsite and 2 days remote, offered on an initial 3-month contract with a strong expectation of long-term extension, and is available to start as soon as possible.
last updated 30 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Software Engineer jobs.
Source: DevITJobs • Last updated 7h ago