en

Expertise

Our specialist consultants are experts across a range of disciplines, connecting you with the right talent for your permanent, temporary, contract, or interim jobs. Share your requirements and our experts will get in touch.

Submit a vacancy
Accounting & Finance Partner with us to find highly skilled accounting and finance professionals who will drive your organisation’s financial success. Legal Access top-tier legal talent through our network of the UK's most recognised in-house and law firm specialists. Procurement & Supply Chain Let us connect you with procurement and supply chain experts who can optimise your operations and deliver results. Technology Hire innovative tech professionals to lead your organisation’s digital transformation and cutting-edge projects. Banking & Financial Services Connect with exceptional financial services talent across diverse roles and sectors. Risk, Compliance & Financial Crime Strengthen your team with experienced professionals in risk management, compliance, and financial crime prevention. Human Resources Recruit HR leaders who will empower your workforce and drive organisational growth. Sales & Commercial Hire dynamic sales and commercial professionals who align with your goals and drive business growth across industries. Business Support Connect with skilled administrative and support professionals who will enhance efficiency across your organisation. Projects, Change & Transformation Bring on board change-makers who will lead successful transformations and drive innovation within your business. Manufacturing & Engineering Access technical specialists who combine expertise and innovation to elevate your manufacturing and engineering capabilities. Marketing Collaborate with creative marketing professionals who will amplify your brand’s presence and deliver impactful campaigns.
Expertise

Our specialist consultants are experts across a range of disciplines, connecting you with the right talent for your permanent, temporary, contract, or interim jobs. Share your requirements and our experts will get in touch.

Submit a vacancy
Jobs

Let our industry specialists listen to your aspirations and present your story to the most esteemed organisations in the UK, as we collaborate to write the next chapter of your successful career.

See all jobs
About Robert Walters UK

Since our establishment in 1985, our belief remains the same: Building strong relationships with people is vital in a successful partnership.

Learn more

Work for us

Our people are the difference. Hear stories from our people to learn more about a career at Robert Walters UK

Learn more

Threat and Vulnerability Lead

Save job

My client, an International Bank, are currently looking to hire a Threat and Vulnerability Lead to join their growing team in London. For this role you will be required to work in their London office up to 3 times per week.

About the Threat and Vulnerability Lead role:

The successful candidate must demonstrate proven experience in leading teams and fostering a culture of technical excellence. They will be expected to establish best practices for risk identification and remediation planning, while also influencing stakeholders and delivering competitive advantage for global organisations by protecting against external threats and potential security vulnerabilities.

NUMBER OF DIRECT REPORTS:

Circa 5

KEY RESPONSIBILITIES

Strategic Leadership & Vision

  • Lead the design, development, operation and management of the department’s Threat and Vulnerability Management (TVM) strategy and roadmaps, ensuring alignment with business requirements, services, strategic goals, and IT risk appetite.
  • Develop short, medium, and long-term strategic goals and objectives for DES TVM, including documenting the current environment and defining the future roadmap.
  • Define measurable, repeatable processes and reporting metrics, subject to continuous improvement.
  • Define the DES Threat and Vulnerability function’s Key Risk Indicators (KRIs) and govern accordingly. Produce regular KPI, MI, and risk management data for senior management.
  • Responsible for identifying cost-saving and optimisation opportunities within MUS EMEA and the wider group.

Operational Oversight & Technical Execution:

  • Lead a team of Threat and Vulnerability Engineers to deliver best practice operations and strategic development, shaping the department’s security posture while adhering to my client's policies and procedures.
  • Oversee the successful deployment of routine and out-of-band security patches across IT infrastructure.
  • Automate patch deployments and associated post-deployment check-outs.
  • Triage vulnerabilities into “Fix, Acknowledge, and Investigate” categories using industry-aligned risk rating methodologies.
  • Use ServiceNow Application Vulnerability Response (AVR) and Vulnerability Response (VR) modules to manage and report on vulnerabilities and violations across the estate, integrating with dashboards and workflows for visibility and accountability.

Risk Management & Remediation:

  • Work with other technology teams to provide in-depth analysis of vulnerabilities and impacts to key stakeholders.
  • Collaborate with application teams to ensure secure coding practices and timely remediation of vulnerabilities, aligned with criticality-based policy enforcement.
  • Prioritise weaknesses in IT infrastructure and applications using manual and automated methods, including results from Static Application Testing (SAST) and Software Composition Analysis (SCA) tooling (in conjunction with the Service Transition team).
  • Influence stakeholders to prioritise and drive remediation of process and technology gaps
  • Work with Cyber Security, Application Teams, and IT Risk to ensure controls are met and vulnerabilities are addressed across infrastructure and applications.
  • Engage and support Cyber Security for remediation of penetration test findings.
  • Engage with Internal and External Auditors as the SME on all matters relating to VM.

Stakeholder Engagement & Culture

  • Act as the primary Service Matter Expert and point of contact for the Threat and Vulnerability Management function within DES.
  • Work closely with industry partners, vendors, and the wider technology ecosystem to leverage external expertise and best practices. Conduct market research to identify emerging risk and vulnerability trends.
  • Build strong relationships across Bank and Securities functions (e.g. IT Risk & Control, Cyber Security, Operational Risk), underpinned by trust core values.
  • Lead by example in building relationships across the Bank, strengthening peer networks and collaboration
  • Champion staff cyber education and awareness to embed a proactive cyber-focused culture.
  • Promote a dynamic, delivery-driven culture that works alongside Technology and Business units to provide responsive resolutions and value-driven solutions.

SKILLS AND EXPERIENCE

Leadership & Team Development

  • Proven experience of directly managing a team of Threat and Vulnerability Engineers, including mentoring, developing, and guiding security professionals in a collaborative, high-performing environment.
  • Strong strategic thinking and visionary skills with the ability to co-develop and drive the function’s technical vision, strategy, and roadmap aligned with business goals and risk appetite.

Technical Expertise & Security Operations

  • Prior extensive experience working within infrastructure environments and cloud platforms (AWS, Azure, Oracle), with a high-level understanding of platforms, operating systems, and technologies.
  • Proven capability in creating and executing comprehensive threat and vulnerability management programmes, including vulnerability scanning, penetration testing, and security awareness training.
  • Proficiency in using vulnerability scanning tools (e.g. Tenable, Qualys, Rapid7, Veracode, JFrog Xray), threat intelligence platforms, and incident response tools.
  • Prior experience implementing automated solutions for vulnerability scanning, threat detection, and incident response, with a focus on continuous process improvement.

Risk Management & Threat Intelligence

  • Strong familiarity with security frameworks and standards (e.g. NIST, ISO 27001), and deep understanding of security concepts including vulnerability management, threat intelligence, incident response, and offensive security techniques.
  • Experience in gathering and analysing threat intelligence to understand emerging threats, attack vectors, and threat actors. Maintains up-to-date knowledge of the latest security threats, vulnerabilities, and best practices.
  • Strong analytical and problem-solving skills to analyse data, identify patterns and develop effective solutions to mitigate risk.

EDUCATION / QUALIFICATIONS/ TECHNICAL COMPETENCIES

Essential

  • Recognised cybersecurity certification: CISSP and/or CISM
  • Strong knowledge of:
    • Ivanti LANDesk, Qualys, Splunk
    • Windows Server/Desktop, RHEL/OEL Linux
    • PowerShell and Python scripting
  • Proven experience leading strategic security initiatives and process automation in large-scale environments

Desirable

  • Additional certifications: CCSP
  • Familiarity with:
    • CyberArk PAM, ServiceNow SecOps Vulnerability Response / Application Vulnerability Response.
    • VMWare, Nutanix, Java VM
    • MSSQL, Oracle, MongoDB
    • Red Hat Satellite, Active Directory, LDAP, Kerberos
    • Confluence, JIRA
    • GDPR and SOX compliance frameworks

Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates

Contract Type: Permanent

Specialism: Technology & Digital

Focus: Information Security

Industry: Banking

Salary: £100,000 - £120,000 per annum

Workplace Type: Hybrid

Experience Level: Senior Management

Location: London

Job Reference: GOWSUD-44A47A0A

Date posted: 18 March 2026

Consultant: Darius Goodarzi