Role Description:
The Senior Vulnerability Analyst holds subject-matter responsibility for vulnerability management in one or more domains (e.g. infrastructure, workplace, applications). The role ensures that vulnerabilities and configuration weaknesses are analysed in context, prioritised based on risk, and sustainably remediated. The Senior Vulnerability Analyst acts as a key expert and sparring partner for Governance, Security Problem Management and technical teams.
Key Responsibilities
- Assume ownership for vulnerability management within defined domains (e.g. servers, endpoints, networks, applications).
- Perform deep-dive analysis of complex findings and derive risk-based recommendations.
- Align remediation strategies and priorities with platform, application and service owners.
- Support definition and monitoring of KPIs/KRIs for vulnerability and patch compliance.
- Contribute to the definition and refinement of security baselines and configuration standards.
- Work closely with Security Problem Managers to identify recurring issues and systemic weaknesses.
- Provide coaching and subject-matter support to Junior and Regular Vulnerability Analysts.
- Support internal and external audits, reviews and management reporting for vulnerability management.
- Take a leading role in case of emergency patch activities.
Specialist knowledge (work experience, further qualification):
- Several/5+ years of relevant experience in vulnerability management, cyber security or closely related IT security roles.
- Deep understanding of vulnerabilities, exploitation techniques and defensive measures, ideally aligned with frameworks such as MITRE ATT&CK.
- Experience leading enterprise-wide remediation governance and KPI/KRI ownership.
- Strong exposure to exposure management, CSPM and attack surface management.
- Experience supporting audits, compliance readiness and executive reporting.
- Advanced automation and workflow integration experience.
- Experience handling zero-day vulnerability coordination and enterprise escalation management.
- Strong expertise in at least one major technology domain (e.g. infrastructure, endpoints, network or applications).
- Experience with vulnerability scanning tools and their integration with ITSM/ticketing systems (e.g Tenable, Qualys, Rapid7)
- Hands-on experience with cloud and container environments (e.g. AWS/Azure/GCP, security groups, Kubernetes, Docker image vulnerabilities).