Rodeo
Get started

Kensington Mortgages

Operational Security Lead and Vulnerability Manager

United Kingdom
Posted 1 day ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

We're Recruiting: Operational Security Lead & Cyber Vulnerability Manager

Location: Hybrid - 1 x month in Marlow
Department: Information Security
Working Hours: Monday-Friday

Are you an experienced cyber security professional with a passion for security operations, incident response, and vulnerability management?

We're looking for an Operational Security Lead & Cyber Vulnerability Manager to play a critical role in protecting Kensington's technology estate, leading our operational cyber security capability, and driving continual improvements to our security posture.

This is an excellent opportunity to join a growing Information Security function, working closely with senior stakeholders across the business to ensure cyber risks are effectively identified, managed, and mitigated.

About the Role

Reporting to the Chief Information Security Officer, you'll lead the day-to-day operational cyber security function, overseeing security operations, cyber incident management, infrastructure and cloud vulnerability management, and third-party security oversight.

You'll be responsible for ensuring security risks are managed appropriately, coordinating incident response activities, driving remediation programs, and helping strengthen Kensington's overall cyber resilience.

This role combines hands-on security expertise with leadership, governance, and stakeholder engagement, making it ideal for someone who enjoys operating at both a strategic and operational level.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key Responsibilities

  • Lead the operational cyber security capability across the organisation.
  • Manage cyber incidents and coordinate effective response and recovery activities.
  • Oversee infrastructure and cloud vulnerability management programs.
  • Drive continuous reduction in cyber risk exposure.
  • Lead security monitoring, threat intelligence, and threat management activities.
  • Manage third-party security incidents and supplier security risks.
  • Support compliance testing and security assurance activities.
  • Oversee security governance, service requests, and operational controls.
  • Lead phishing simulations and security awareness initiatives.
  • Support firewall, network, and security configuration reviews.

What We're Looking For

You'll have a strong background in cyber security operations and be comfortable operating within a fast-paced, highly regulated environment.

Essential Experience

  • Cyber Security Operations and Cyber Defence.
  • Vulnerability Management and remediation.
  • Security Incident Response and Major Incident Management.
  • Security Monitoring and SIEM platforms.
  • Threat Intelligence.
  • Cloud Security, ideally Azure.
  • Data Loss Prevention (DLP).
  • Network Security.
  • Security Governance and Risk Management.
  • Working within regulated environments.

Technical Knowledge

You'll ideally have experience with:

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job
  • Vulnerability scanning and reporting tools.
  • Security testing methodologies.
  • Network architecture and infrastructure technologies.
  • Security compliance frameworks, including NIST.
  • Threat actor tactics and attack techniques.
  • Security assurance and compliance reviews.
  • Infrastructure and cloud security controls.

Skills & Behaviours

We're looking for someone who can:

  • Make informed decisions during security incidents and risk events.
  • Prioritise effectively in high-pressure environments.
  • Build strong relationships across technical and non-technical teams.
  • Communicate complex cyber security concepts clearly to senior stakeholders.
  • Influence, challenge, and drive positive security outcomes.
  • Lead teams and support the development of others.
  • Maintain a strong governance and control mindset.

Qualifications

Essential:

  • Degree qualified or equivalent experience in Cyber Security, Information Security, Computer Science, or a related discipline.

Desirable:

  • CISSP
  • CISM
  • Vulnerability Management certifications
  • Incident Response certifications

Why Join Kensington?

At Kensington, you'll have the opportunity to influence and develop our cyber security capability while working with modern technologies and security frameworks. You'll play a key role in protecting the organisation, shaping security strategy, and helping us build a resilient and secure operating environment.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber Security Operations
Vulnerability Management
Incident Response
SIEM Platforms
Threat Intelligence
Cloud Security
Azure
Data Loss Prevention
Network Security
Security Governance
Risk Management
NIST Framework
Security Assurance
Phishing Simulations
Stakeholder Management
Compliance Testing

Location

United Kingdom

Sign up to applySee more jobs like this