Gazelle Global
Threat and Vulnerability Management Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Threat and Vulnerability Management Engineer
London / Onsite
Contract
The role is part of the group which encompasses Infrastructure and Service Management across Bank, International Securities, and the 15+ countries in which these entities operate. The position is responsible for working in the Threat and Vulnerability Management function.
This function integrates secure practices into the development lifecycle and aligns with service transition processes to ensure compliance with internal controls and regulatory standards. It plays a critical role in governance, audit readiness, and the continuous improvement of the organization’s security posture, while also serving as the central coordination point for all vulnerability-related activities across DES.
The successful candidate must demonstrate proven experience in leading teams and fostering a culture of technical excellence. They will be expected to establish best practices for risk identification and remediation planning, while also influencing stakeholders and delivering competitive advantage for global organisations by protecting against external threats and potential security vulnerabilities.
Your Responsibilities
Key Responsibilities
Strategic Leadership & Vision
- Design, development, operation and management of the department’s Threat and Vulnerability Management (TVM) strategy and roadmaps, ensuring alignment with business requirements, services, strategic goals, and IT risk appetite.
- Develop short, medium, and long-term strategic goals and objectives for DES TVM, including documenting the current environment and defining the future roadmap.
- Define measurable, repeatable processes and reporting metrics, subject to continuous improvement.
- Define the DES Threat and Vulnerability function’s Key Risk Indicators (KRIs) and govern accordingly. Produce regular KPI, MI, and risk management data for senior management.
- Responsible for identifying cost-saving and optimisation opportunities within MUS EMEA and the wider group.
Operational Oversight & Technical Execution
- Lead a team of Threat and Vulnerability Engineers to deliver best practice operations and strategic development, shaping the department’s security posture while adhering to policies and procedures.
- Oversee the successful deployment of routine and out-of-band security patches across IT infrastructure.
- Automate patch deployments and associated post-deployment check-outs.
- Triage vulnerabilities into “Fix, Acknowledge, and Investigate” categories using industry-aligned risk rating methodologies.
- Use ServiceNow Application Vulnerability Response (AVR) and Vulnerability Response (VR) modules to manage and report on vulnerabilities and violations across the estate, integrating with dashboards and workflows for visibility and accountability.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Risk Management & Remediation
- Work with other technology teams to provide in-depth analysis of vulnerabilities and impacts to key stakeholders.
- Collaborate with application teams to ensure secure coding practices and timely remediation of vulnerabilities, aligned with criticality-based policy enforcement.
- Prioritise weaknesses in IT infrastructure and applications using manual and automated methods, including results from Static Application Testing (SAST) and Software Composition Analysis (SCA) tooling (in conjunction with the Service Transition team).
- Influence stakeholders to prioritise and drive remediation of process and technology gaps
- Work with Cyber Security, Application Teams, and IT Risk to ensure controls are met and vulnerabilities are addressed across infrastructure and applications.
- Engage and support Cyber Security for remediation of penetration test findings.
- Engage with Internal and External Auditors as the SME on all matters relating to VM.
Stakeholder Engagement & Culture
- Act as the primary Service Matter Expert and point of contact for the Threat and Vulnerability Management function within DES.
- Work closely with industry partners, vendors, and the wider technology ecosystem to leverage external expertise and best practices. Conduct market research to identify emerging risk and vulnerability trends.
- Build strong relationships across Bank and Securities functions (e.g. IT Risk & Control, Cyber Security, Operational Risk), underpinned by trust and core values.
- Lead by example in building relationships across the Bank, strengthening peer networks and collaboration.
- Promote values-led culture, fostering inclusivity and diversity.
- Champion staff cyber education and awareness to embed a proactive cyber-focused culture.
- Promote a dynamic, delivery-driven culture that works alongside Technology and Business units to provide responsive resolutions and value-driven solutions.
Your Profile
Skills and Experience
Leadership & Team Development
- Proven experience of directly managing a team of Threat and Vulnerability Engineers, including mentoring, developing, and guiding security professionals in a collaborative, high-performing environment.
- Strong strategic thinking and visionary skills with the ability to co-develop and drive the function’s technical vision, strategy, and roadmap aligned with business goals and risk appetite.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Technical Expertise & Security Operations
- Prior extensive experience working within infrastructure environments and cloud platforms (AWS, Azure, Oracle), with a high-level understanding of platforms, operating systems, and technologies.
- Proven capability in creating and executing comprehensive threat and vulnerability management programmes, including vulnerability scanning, penetration testing, and security awareness training.
- Proficiency in using vulnerability scanning tools (e.g. Tenable, Qualys, Rapid7, Veracode, JFrog Xray), threat intelligence platforms, and incident response tools.
- Prior experience implementing automated solutions for vulnerability scanning, threat detection, and incident response, with a focus on continuous process improvement.
Risk Management & Threat Intelligence
- Strong familiarity with security frameworks and standards (e.g. NIST, ISO 27001), and deep understanding of security concepts including vulnerability management, threat intelligence, incident response, and offensive security techniques.
- Experience in gathering and analysing threat intelligence to understand emerging threats, attack vectors, and threat actors. Maintains up-to-date knowledge of the latest security threats, vulnerabilities, and best practices.
- Strong analytical and problem-solving skills to analyse data, identify patterns and develop effective solutions to mitigate risk.
Communication & Stakeholder Engagement
- Proven ability to communicate effectively with senior management, providing governance and risk oversight.
- Excellent verbal and written communication skills to report findings and collaborate across cross-functional Technology and non-Technology teams.
- Ability to translate technical risks into business-relevant language for both technical and non-technical stakeholders, including executive leadership.
Education / Qualifications
Essential
- Recognised cybersecurity certification: CISSP and/or CISM
- Strong knowledge of:
- Ivanti LANDesk, Qualys, Splunk
- Windows Server/Desktop, RHEL/OEL Linux
- PowerShell and Python scripting
- Proven experience leading strategic security initiatives and process automation in large-scale environments
Desirable
- Additional certifications: CCSP
- Familiarity with:
- CyberArk PAM, ServiceNow SecOps Vulnerability Response / Application Vulnerability Response.
- VMWare, Nutanix, Java VM
- MSSQL, Oracle, MongoDB
- Red Hat Satellite, Active Directory, LDAP, Kerberos
- Confluence, JIRA
- GDPR and SOX compliance frameworks
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location