“It feels good to have a career with real purpose.”

The feeling's mutual
Two colleagues walking together and smiling.
Job Description
Senior Threat & Vulnerability Analyst

Contract Type: Permanent

Location: Alderley Park (Wilmslow) or Glasgow

Working style: Hybrid (50% home / office based)

 

Royal London is looking for a Senior Threat and Vulnerability Analyst to support the ongoing maturity and delivery of our enterprise patching and vulnerability management capability. Reporting to the Threat and Vulnerability Manager, you’ll help identify, prioritise, track and support the remediation of vulnerabilities across the Royal London estate, ensuring they are managed in line with business risk, regulatory expectations and agreed service levels. You will support the evolution of Royal London's Continuous Threat Exposure Management (CTEM) capability, helping prioritise remediation activities based on exploitability, exposure and business risk.

 

More about the role:

As Senior Threat and Vulnerability Analyst, you will play a key role in supporting Royal London’s patching and vulnerability management processes, controls and reporting. You will help ensure vulnerabilities identified through cyber tools, assessments, audits and third parties are understood, prioritised and managed through to closure.

You will:

  • Support the identification, triage, prioritisation, tracking and remediation of vulnerabilities across the Royal London estate.
  • Help mature and maintain the vulnerability management process, including the management of vulnerabilities identified through tooling, assessments, audits and third parties.
  • Ensure vulnerabilities are managed within documented SLAs, with compensating controls identified and implemented where required.
  • Produce metrics, management information and reporting with clear narrative, remediation updates and recommendations.
  • Support oversight of the patching and vulnerability management service delivered through our managed security service provider.
  • Work with operational teams, cyber security colleagues and third-party partners to support effective remediation activity.
  • Review and enhance processes, technologies and documentation used to support vulnerability management.
  • Contribute to governance, risk, compliance and reporting activity relating to vulnerability and patching risk.
  • Remain current on the threat landscape, vulnerability exploitation techniques and relevant cyber security practices.
  • Support the maintenance and improvement of asset inventory data used to underpin vulnerability management.

 

More about you:

  • Good knowledge and hands-on experience of vulnerability management tools, particularly Tenable One and similar enterprise vulnerability platforms.
  • Experience reviewing vulnerability scan data, producing reports and making clear remediation recommendations.
  • Good understanding of IT security, cyber security frameworks, security controls and vulnerability management practices.
  • Experience working with third-party providers, technology teams and business stakeholders.
  • Strong communication skills, with the ability to explain technical issues clearly and influence stakeholders.
  • An analytical and methodical approach to technical challenges, with strong attention to detail.
  • Understanding of exposure management, attack surface management or risk-based vulnerability prioritisation would be beneficial.
  • A collaborative, service-orientated mindset and the ability to work effectively across cyber security and wider technology teams.
  • Experience working in a regulated financial services environment would be beneficial.
  • Security qualifications such as CISSP, CISM, ISC2 or equivalent are desirable but not essential.

 

The following experience would be beneficial but is not essential:

  • Power BI dashboard and report development.
  • Power Automate or similar workflow automation platforms.
  • ServiceNow, including incident, request, change or CMDB processes.
  • Python or other scripting languages for automation, data analysis and security tool integration.

 

About Royal London

We’re the UK’s largest mutual life, pensions and investment company, offering protection, long‑term savings and asset management products and services. Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve. We've always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance.

Inclusion, diversity and belonging

We’re an inclusive employer. We celebrate and value different backgrounds, perspectives and cultures across Royal London, and we’re committed to creating a workplace where everyone feels they belong and can do their best work.