Royal London
Senior Threat & Vulnerability Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Contract Type: Permanent
Location: Alderley Park (Wilmsley) or Glasgow
Working style: Hybrid (50% home / office based)
Royal London is looking for a Senior Threat and Vulnerability Analyst to support the ongoing maturity and delivery of our enterprise patching and vulnerability management capability. Reporting to the Threat and Vulnerability Manager, you’ll help identify, prioritise, track and support the remediation of vulnerabilities across the Royal London estate, ensuring they are managed in line with business risk, regulatory expectations and agreed service levels. You will support the evolution of Royal London's Continuous Threat Exposure Management (CTEM) capability, helping prioritise remediation activities based on exploitability, exposure and business risk.
More about the role:
As Senior Threat and Vulnerability Analyst, you will play a key role in supporting Royal London’s patching and vulnerability management processes, controls and reporting. You will help ensure vulnerabilities identified through cyber tools, assessments, audits and third parties are understood, prioritised and managed through to closure.
You will:
- Support the identification, triage, prioritisation, tracking and remediation of vulnerabilities across the Royal London estate.
- Help mature and maintain the vulnerability management process, including the management of vulnerabilities identified through tooling, assessments, audits and third parties.
- Ensure vulnerabilities are managed within documented SLAs, with compensating controls identified and implemented where required.
- Produce metrics, management information and reporting with clear narrative, remediation updates and recommendations.
- Support oversight of the patching and vulnerability management service delivered through our managed security service provider.
- Work with operational teams, cyber security colleagues and third-party partners to support effective remediation activity.
- Review and enhance processes, technologies and documentation used to support vulnerability management.
- Contribute to governance, risk, compliance and reporting activity relating to vulnerability and patching risk.
- Remain current on the threat landscape, vulnerability exploitation techniques and relevant cyber security practices.
- Support the maintenance and improvement of asset inventory data used to underpin vulnerability management.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
More about you:
- Good knowledge and hands-on experience of vulnerability management tools, particularly Tenable One and similar enterprise vulnerability platforms.
- Experience reviewing vulnerability scan data, producing reports and making clear remediation recommendations.
- Good understanding of IT security, cyber security frameworks, security controls and vulnerability management practices.
- Experience working with third-party providers, technology teams and business stakeholders.
- Strong communication skills, with the ability to explain technical issues clearly and influence stakeholders.
- An analytical and methodical approach to technical challenges, with strong attention to detail.
- Understanding of exposure management, attack surface management or risk-based vulnerability prioritisation would be beneficial.
- A collaborative, service-orientated mindset and the ability to work effectively across cyber security and wider technology teams.
- Experience working in a regulated financial services environment would be beneficial.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Security qualifications such as CISSP, CISM, ISC2 or equivalent are desirable but not essential.
The following experience would be beneficial but is not essential:
- Power BI dashboard and report development.
- Power Automate or similar workflow automation platforms.
- ServiceNow, including incident, request, change or CMDB processes.
- Python or other scripting languages for automation, data analysis and security tool integration.
About Royal London
We’re the UK’s largest mutual life, pensions and investment company, offering protection, long-term savings and asset management products and services. Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve. We've always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance.
Inclusion, diversity and belonging
We’re an inclusive employer. We celebrate and value different backgrounds, perspectives and cultures across Royal London, and we’re committed to creating a workplace where everyone feels they belong and can do their best work.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills