Senior Vulnerability Manager - Home Office Cyber Security
- Civil Service
- Full Time
- Salford
- 49,850
Job Description
Job summary
Cyber Security at the Home Office is at the front end of protecting one of the largest government departments and safeguarding the critical digital infrastructure. Vulnerability Management is a critical service within this operation, delivering a managed approach to proactively identifying vulnerabilities and developing effective remediation strategies.
Where business needs allow, some roles may be suitable for a combination of office and home-based working. Where this is the case, employees will be expected to spend a minimum of 60% of their working time in the office. Applicants can raise any queries to the email address at the bottom of the advert.
Watch this short video to hear from members of Home Office Digital talking about the projects they work on and their experience of working here: Working for Home Office Digital.
Job description
The role of Vulnerability Management is to triage vulnerabilities by relevance and criticality to the organisation. Vulnerability Management then identify mitigations for those vulnerabilities and advise on implementing them.
Youll join an expert team of cyber professionals, committed to fighting cyber-attack across a complex network of systems. Youll be aided by a supportive organisational culture, and a commitment to further your continuous development.
Person specification
As a Senior Vulnerability Manager, your main day to day responsibilities will be:
- Vulnerability Identification Lead the process of identifying and classifying technical vulnerabilities in systems, applications and networks to identify security weaknesses and potential risks. Utilise vulnerability management tools/technologies to identify, assess and report on vulnerabilities.
- Risk Assessment Analyse and evaluate the results of vulnerability scans to determine the severity and potential impact of identified vulnerabilities, categorising them based on risk to assets and operations.
- Remediation Planning Collaborate with multiple departments, technical teams and senior stakeholders to recommend remediation plans and complex configuration changes in support of vulnerability remediation.
- Reporting Create and present detailed reports on vulnerability assessments, remediation efforts, and overall vulnerability management performance for stakeholders, management and technical teams.
- Incident Management Work closely with other security teams and technical resolver groups to ensure comprehensive approach to managing prioritised vulnerabilities.
- Tool management - Knowledge and understanding of approaches and tooling used to perform vulnerability assessments against large and complex infrastructure. Implementing continuous monitoring processes to identify new vulnerabilities and assess the effectiveness of remediation efforts over time.
- Vulnerability Management Service - Onboard assets into the appropriate vulnerability management tooling in line with the Threat and Vulnerability Management Service. Ensure that all vulnerability management activities align with service polices, standards and procedures.
Working Pattern
Due to the business requirements of this role, it is only available on a full-time basis. However, compressed hours are available.
Essential Skills
Youll have a demonstrable passion for Vulnerability Management, with the following skills or strong experience in:
- Driving improvements in vulnerability management processes and practices, working with security and technology teams to deliver technical and operational change.
- Conducting vulnerability assessments using recognised frameworks, understanding severity and contextualising risk within an organisational environment to support effective prioritisation.
- Implementing and operating technical vulnerability management tooling, ensuring effective deployment, maintenance and use of data to identify, analyse and communicate security risk.
- Managing security risk, working collaboratively with stakeholders to drive remediation and achieving good security outcomes aligned to organisational prioritises and risk appetite.
- Communicating complex technical vulnerability risk clearly and effectively, producing high quality written and verbal reports tailored to technical specialists and non-technical senior stakeholders.
- Coordinating effective incident response activities in fast-paced environments, engaging with cross-functional teams to triage, contain and remediate security incidents.
SFIA capability framework
Skills for the Information Age (SFIA) version 8 is the technical framework that sets the standard capability and development of all levels in the Home Office. This is a link to the capability framework: All skills A - Z English (sfia-online.org).
We use set SFIA technical skills to form our interview questions and we will assess you against these technical skills during the selection process.
The essential skills listed above are reflective of the Home Office Government Digital and Data Profession Career Framework (based on the industry standard SFIA framework). Use the SFIA Levels of responsibilityto understand what would be expected for each technical skills listed below.
Strategy and Architecture
- Security and Privacy
- Threat Intelligence (THIN) Level 3
- Governance, risk and compliance
- Risk management (BURM) Level 3
Delivery and Operation
- Service Management
- Incident Management (USUP) Level 3
- Security Operations (SCAD) Level 3
- Security services
- Vulnerability Assessment (VUAS) Level 3
Relationships and engagement
- Stakeholder management