Government Digital Service
Head of Vulnerability Management

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Please note this role requires DV Clearance
The Government Cyber Unit's mission is to protect public services from cyber threats and digital resilience failures. We are working to achieve a step change in our cyber and digital resilience across government, through delivery of the Government Cyber Action Plan, and working closely with departments and national technical authorities including the National Cyber Security Centre to deliver. This is a challenging time to be working in cyber security and digital resilience, but we have an incredible opportunity to make a difference to people’s lives and promote national security by protecting the public services and national infrastructure they rely on. We work at the forefront of shaping the UK’s national response to emerging cyber and technology issues - from the increasingly complex range of state-sponsored cyber-attacks and supply chain compromises, through to the transformational benefits and security challenges of frontier AI and quantum computing.
We are committed to creating an inclusive and supportive working environment where people can learn, develop and do their best work. Continuous professional development and a focus on wellbeing is core to our unit culture. We welcome applications from candidates who share this ethos and are excited by our mission.
The Government Cyber Coordination Centre (GC3) coordinates the cross-Government response to cyber security vulnerabilities, threats, and incidents, and enables cyber defenders across Government to work together and to “defend as one”. The GC3 is a joint initiative sponsored by the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC). This role is based in DSIT, but you should expect to work closely alongside colleagues from both sponsoring organisations, and wider Government and the public sector.
Job description
Please Note - Former DSIT recruitment campaigns are continuing as usual, but candidates should be aware that following the Government’s announcement on the changes to some civil service departments, roles will be subject to the machinery of government moves and will ultimately be in one of the new departments. We will provide more information if you are selected for a role. This work remains of high importance to the civil service, and we thank you for your continued interest.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
We are looking for an experienced vulnerability management professional to set the strategic direction for vulnerability management across government and coordinate action to reduce cyber risk through the effective identification, mitigation and remediation of vulnerabilities. This role reports to the Deputy Director for Government Cyber Operations.
Responsibilities
- Set the strategic direction for vulnerability management across government, leading the government’s approach to identifying, triaging, mitigating, and remediating vulnerabilities across departments
- Work closely with the Government Cyber Unit’s accountability team to establish and operate governance, policy, assurance and risk/performance reporting structures for vulnerability management across government
- Understand and report on government’s aggregate exposure to vulnerabilities, and performance remediating or otherwise mitigating vulnerabilities
- Lead the operation of central vulnerability management services, including the Vulnerability Reporting Service (VRS) and Vulnerability Monitoring Service (VMS), ensuring delivery of a quality service that efficiently and effectively reduces risk at-scale, and driving continuous improvement
- Work closely with the Government Cyber Unit’s Services team to build and continually improve central vulnerability management services, providing SME input and direction for the product roadmap
- Work closely with the GC3 Incident Management function to support the cross-government response to critical vulnerabilities, enabling a rapid understanding of risk, clear communications to decision makers, and a coordinated and informed response across government
- Support teams across DSIT and the NCSC working to reduce vulnerabilities at source, both through improving underlying technology and reducing the attack surface
- Advise ministers, senior officials, and IT and cyber security leadership across government on the risk from vulnerabilities, and the operational response to these
- Engage closely with stakeholders and customers across government, including wider DSIT, the NCSC, and departmental IT and cyber security teams
- Line manage lead analysts in the vulnerability management team, and provide coaching and support to staff across the GC3


Get help with your application
Your very own career expert that helps elevate your application to the next level.
The post holder may be required to support out of hours on call rotas for responding to cyber and digital resilience incidents, for which remuneration and/or flexible working arrangements will be available.
Person specification
We’re looking for someone with:
- Significant experience leading vulnerability management in a large, complex organisation, and a deep understanding of vulnerabilities and vulnerability management practices
- Strong leadership skills, with the ability to set strategic direction, lead cross-functional teams, and lead delivery in a complex environment
- Strong stakeholder engagement and influencing skills, with the ability to build trusted relationships, manage competing priorities, and achieve consensus
- The ability to provide clear and highly credible advice to senior decision makers, including translating complex vulnerability information for a non-technical audience
- The ability to balance strategic objectives, operational risks, and competing stakeholder requirements
DSIT cannot offer Visa sponsorship to candidates through this campaign. DSIT holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location