Rodeo
Get started

Bertelsmann

Threat & Vulnerability Manager (FTC)

Greater London
£60k – £65k/yr
Posted about 17 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job Description

We have a new opportunity for an experienced Threat and Vulnerability Manager to join our Technology team here at Penguin on a 7-month fixed-term contract to cover a period of parental leave. This role is offered with hybrid working from our office in Embassy Gardens, London.

As Threat and Vulnerability Manager, you'll take ownership of our threat and vulnerability management capabilities, leading the identification, assessment and remediation of vulnerabilities across the business. Alongside this, you'll play a hands-on part in our wider security operations: supporting the security controls that protect our technical environment, monitoring internal and external cyber threats, and responding quickly to information security incidents.

Supporting the Head of Security Operations, you'll help maintain and continually improve our cyber security attack surface, driving prompt and effective remediation and working with stakeholders across the business to strengthen our overall security posture.

This is an important role in reducing our exposure to cyber security threats and helping to protect the resilience of our systems and services.

About the team

The Technology team provides expertise and effective solutions to Penguin Random House. We integrate flexibility and agility which supports our consistent way of working. We set ourselves up for success by holding ourselves accountable and welcoming change. Each member of the Technology team brings skill and initiative to their role; we take personal ownership within a one team culture, working collaboratively to meet expectations from our stakeholders who trust us to deliver.

Key responsibilities

Threat and vulnerability management

  • Responsible for ensuring that vulnerability detection and remediation controls and platforms are properly configured and operating effectively.
  • Responsible for promptly assessing new or emerging vulnerabilities and leading internal efforts to resolve or mitigate as appropriate to the severity level, including guidance and recommendations on emergency patching based on appropriate threat assessments.
  • As a subject matter expert, has product ownership for enterprise VM tooling in collaboration with our infrastructure and security architects.
  • Coordinating vulnerability scanning and penetration testing, and managing the technical remediation of their findings.
  • Plays a leadership role in the team to proactively challenge and drive incremental and continuous improvements in end-to-end vulnerability management processes, i.e. scopes, prioritises and leads service improvement initiatives for vulnerability management platforms and management processes.
  • Provide leadership and direction to the PRH community on all aspects of vulnerability management and mitigation across user endpoints, servers, networks and applications.
  • Continually improving PRH's security posture through collaborative and successful vulnerability remediation efforts with internal and external teams responsible for infrastructure and applications.
  • Producing ad hoc, weekly and monthly metrics and KPIs evidencing vulnerability analysis, and reduction or mitigation of vulnerability risk.
  • Chairing Patching and Vulnerability Management forums.
  • Responsible for assurance of all BAU vulnerability management processes managed by PRH Security Operations or by our nominated MSSPs.
  • Will drive technical integrations between VM platforms to leverage automation and threat/vulnerability intelligence.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Security operations

  • Monitoring internal and external cyber threats and ensuring our technical controls stay aligned to them.
  • Supporting the operation of key security controls, including endpoint protection (anti-virus, encryption, mobile device management and network access control), DDoS protection, web security and email security (including phishing simulation).
  • Supporting security incident and event management, including log reviews, identifying critical events and creating alerts.
  • Rapid response, detection, isolation and remediation of information security incidents, and reporting to management on incidents and incident prevention activities.
  • Conducting periodic reviews of security technology for adherence to policy, such as firewall policy, email allow-list and anti-virus exception reviews, and ensuring audit trails and system logs are reviewed in line with policy and audit requirements.
  • Supporting the delivery of ongoing security initiatives and projects.

What you'll bring

Essential criteria

  • Demonstrable experience of using VM tooling at an enterprise level and supporting or leading enterprise VM programmes.
  • Previous experience of patch management processes.
  • Ability to demonstrate broad and deep vulnerability knowledge and experience across various domains including Infrastructure, Cloud, Applications and Networks.
  • A good understanding of threats and threat vectors, and hands-on experience of information security incident handling.
  • Ability to build and maintain collaborative relationships with various stakeholder groups, and to be an advocate for informed, risk-based vulnerability management.
  • Good understanding of Web Application Security frameworks, common vulnerabilities and associated remediations.
  • Excellent verbal and written communication skills, with the ability to explain the business impact of security risks, tools and policies to technical teams, management and business colleagues.
  • Ability to work under pressure, with proven problem-solving and decision-making experience.

Desirable criteria

  • Technical accreditations such as CISSP, SANS or other relevant security credentials.
  • Ability to use scripting languages such as Python, Perl, PowerShell etc.
  • Working knowledge of Open-Source Threat Intelligence capabilities.
  • Experience of working with teams in an Agile environment.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Application instructions

Please apply with your CV by 23:59 on Wednesday 7th October 2026. Applications will be reviewed on a rolling basis and the advert may close at any time. We would encourage you to apply as soon as possible.

AI

Here at Penguin, we believe in the power of authenticity and human creativity. When you apply for a position, we want to encourage you to showcase your unique voice. Throughout our recruitment process, please share your own thoughts, experiences, and skills. This helps us get a true sense of who you are and what you might bring to our team.

We celebrate creativity and diverse perspectives, so please be yourself! While we recognise AI tools can be helpful, we recommend using them thoughtfully to ensure your responses reflect you.

Disability Confident

As a Disability Confident Committed organisation, we offer interviews to candidates with a disability who meet the essential criteria for the role, and opt-in on their application form. The essential criteria for this role are listed as part of the 'What you'll bring' section.

There may be times when the volume of applications means we cannot take all eligible candidates to interview. We encourage you to tell us about any reasonable adjustments you may need by emailing PRHCareersUK@penguinrandomhouse.co.uk(opens in new window). Remember, you only need to share what you are comfortable with, for us to support your request.

Salary

The salary for this opportunity is £60,000-£65,000 depending on how your skills and experience align to the role, plus a generous bonus scheme and benefits.

Hybrid working

While our offices across the UK are places to connect, collaborate and celebrate with colleagues, we recognise that flexibility around where you work is just as important.

For this role we expect that you will work from our head office in Embassy Gardens, London a minimum of 2 days per week (Tuesday & Thursday) with additional days for team meetings, townhalls etc. as required. There may also be occasional travel to our warehouse site in Frating, Colchester.

Additional Information

Disclosure requirements pertaining to the collection of your personal data: Responsible for processing the information provided in your application is the company specified in the job advertisement, with its registered office as indicated. The company processes your data for the purpose of establishing an employment relationship on the basis of Art. 6 (1) b GDPR / Section 26 (1) sentence 1 BDSG. The retention period for your data is determined by the statutory time limits applicable in the respective country, beginning upon completion of the recruitment process. You can find these here. You can contact the company’s Data Protection Officer at the above-mentioned postal address. Further information on data protection and your rights can be found here.

Recruiting-Platform powered by SmartRecruiters.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Greater London, England, United Kingdom

Sign up to applySee more jobs like this