Open in the current public read path; this is not an employer guarantee.Last observed October 5, 2026
Classification
Modern power-system classification not yet published for this listing.Legacy source industry field: Not Specified
Pay provenance
Estimated benchmark; not employer-provided
Job Description
London – UK (Hybrid)
Key Responsibilities
As part of the continued expansion of our cybersecurity program, we are seeking a Analyst, Threat & Vulnerability Management with a primary focus on applications and cloud environments.
In this role, you will support and execute vulnerability management activities across the full lifecycle — from identification through remediation — helping prioritize risks based on business and operational impact across application, cloud, and broader technology environments.
Working closely with Cybersecurity, IT, application, cloud, engineering, and business stakeholders, you will help strengthen the organization's security posture and contribute to the continuous improvement of our Threat & Vulnerability Management program.
Execute vulnerability management activities across the full lifecycle, including discovery, assessment, prioritization, tracking, and remediation validation. Analyze vulnerability and threat data to identify high-risk exposures, trends, and remediation priorities across application and cloud environments. Coordinate with application teams, cloud engineering, DevOps, infrastructure, cybersecurity, and business stakeholders to assess impact, drive remediation, and support timely resolution of vulnerabilities. Assist with remediation and vulnerability treatment activities, including validation of fixes and follow-up on outstanding issues.
The specialist is responsible for monitoring and ensuring IT systems adhere to internal and external compliance requirements. They conduct risk assessments and participate in compliance audits, identifying gaps and recommending improvements to processes and controls. The role requires the development and implementation of procedures that align with information and cyber security standards. Working closely with other IT and business units, the specialist helps maintain a secure and compliant environment. They must skilfully manage multiple priorities and communicate findings diplomatically to stakeholders. The position also involves staying updated on regulatory changes and best practices to proactively address potential compliance issues.
Requirements
2–3+ years of experience in threat and vulnerability management, cybersecurity operations, application security, cloud security, security engineering, or related cybersecurity roles.
Experience working with vulnerability management and scanning tools such as Tenable (Nessus), Qualys, Wiz, Cloudflare, or similar, along with endpoint or cloud security platforms where applicable.
Experience assessing, prioritizing, and tracking vulnerabilities through remediation in enterprise application and cloud environments.
Experience working in or supporting application security, cloud security, infrastructure security, or DevSecOps environments is strongly preferred.
Strong understanding of CVSS scoring and the ability to interpret severity ratings in the context of business impact, exploitability, asset criticality, and remediation prioritization.
Familiarity with vulnerabilities affecting web applications, APIs, operating systems, cloud platforms, containers, and misconfigurations in cloud-native environments.
Ability to analyze technical findings and translate them into clear, actionable insights for both technical and non-technical stakeholders.
Strong analytical, organizational, and communication skills, with the ability to collaborate across cybersecurity, IT, application development, cloud, engineering, and business teams.
Demonstrated ability to work independently, support process maturity, and contribute to a proactive, risk-informed security culture.
Relevant certifications such as CISSP, CEH, OSCP, CISM, CCSP, AWS/Azure security certifications, or similar are preferred.
2-4 Years of experience in IT privacy, compliance, or systems engineering. Bachelor’s degree in Information Technology, Computer Science, or related field. Familiarity with SOX audits and cyber security standards. Strong organizational and analytical skills. Effective communication and teamwork abilities.