Penguin Random House UK
Threat & Vulnerability Manager (FTC)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Experienced Threat and Vulnerability Manager
We have a new opportunity for an experienced Threat and Vulnerability Manager to join our Technology team here at Penguin on a 7-month fixed-term contract to cover a period of parental leave. This role is offered with hybrid working from our office in Embassy Gardens, London.
As Threat and Vulnerability Manager, you'll take ownership of our threat and vulnerability management capabilities, leading the identification, assessment and remediation of vulnerabilities across the business. Alongside this, you'll play a hands-on part in our wider security operations: supporting the security controls that protect our technical environment, monitoring internal and external cyber threats, and responding quickly to information security incidents.
Supporting the Head of Security Operations, you'll help maintain and continually improve our cyber security attack surface, driving prompt and effective remediation and working with stakeholders across the business to strengthen our overall security posture.
This is an important role in reducing our exposure to cyber security threats and helping to protect the resilience of our systems and services.
About the Team
The Technology team provides expertise and effective solutions to Penguin Random House. We integrate flexibility and agility which supports our consistent way of working. We set ourselves up for success by holding ourselves accountable and welcoming change. Each member of the Technology team brings skill and initiative to their role; we take personal ownership within a one team culture, working collaboratively to meet expectations from our stakeholders who trust us to deliver.
The Role
Key Responsibilities:
Threat and Vulnerability Management
- Responsible for ensuring that vulnerability detection and remediation controls and platforms are properly configured and operating effectively.
- Responsible for promptly assessing new or emerging vulnerabilities and leading internal efforts to resolve or mitigate as appropriate to the severity level, including guidance and recommendations on emergency patching based on appropriate threat assessments.
- As a subject matter expert, has product ownership for enterprise VM tooling in collaboration with our infrastructure and security architects.
- Coordinating vulnerability scanning and penetration testing, and managing the technical remediation of their findings.
- Plays a leadership role in the team to proactively challenge and drive incremental and continuous improvements in end-to-end vulnerability management processes, i.e. scopes, prioritises and leads service improvement initiatives for vulnerability management platforms and management processes.
- Provide leadership and direction to the PRH community on all aspects of vulnerability management and mitigation across user endpoints, servers, networks and applications.
- Continually improving PRH's security posture through collaborative and successful vulnerability remediation efforts with internal and external teams responsible for infrastructure and applications.
- Producing ad hoc, weekly and monthly metrics and KPIs evidencing vulnerability analysis, and reduction or mitigation of vulnerability risk.
- Chairing Patching and Vulnerability Management forums.
- Responsible for assurance of all BAU vulnerability management processes managed by PRH Security Operations or by our nominated MSSPs.
- Will drive technical integrations between VM platforms to leverage automation and threat/vulnerability intelligence.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Security Operations
- Monitoring internal and external cyber threats and ensuring our technical controls stay aligned to them.
- Supporting the operation of key security controls, including endpoint protection (anti-virus, encryption, mobile device management and network access control), DDoS protection, web security and email security (including phishing simulation).
- Supporting security incident and event management, including log reviews, identifying critical events and creating alerts.
- Rapid response, detection, isolation and remediation of information security incidents, and reporting to management on incidents and incident prevention activities.
- Conducting periodic reviews of security technology for adherence to policy, such as firewall policy, email allow-list and anti-virus exception reviews, and ensuring audit trails and system logs are reviewed in line with policy and audit requirements.
- Supporting the delivery of ongoing security initiatives and projects.
What You'll Bring
Essential Criteria:
- Demonstrable experience of using VM tooling at an enterprise level and supporting or leading enterprise VM programmes.
- Previous experience of patch management processes.
- Ability to demonstrate broad and deep vulnerability knowledge and experience across various domains including Infrastructure, Cloud, Applications and Networks.
- A good understanding of threats and threat vectors, and hands-on experience of information security incident handling.
- Ability to build and maintain collaborative relationships with various stakeholder groups, and to be an advocate for informed, risk-based vulnerability management.
- Good understanding of Web Application Security frameworks, common vulnerabilities and associated remediations.
- Excellent verbal and written communication skills, with the ability to explain the business impact of security risks, tools and policies to technical teams, management and business colleagues.
- Ability to work under pressure, with proven problem-solving and decision-making experience.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Criteria:
- Technical accreditations such as CISSP, SANS or other relevant security credentials.
- Ability to use scripting languages such as Python, Perl, PowerShell etc.
- Working knowledge of Open-Source Threat Intelligence capabilities.
- Experience of working with teams in an Agile environment.
Application Instructions
Please apply with your CV by 23:59 on Wednesday 7th October 2026. Applications will be reviewed on a rolling basis and the advert may close at any time. We would encourage you to apply as soon as possible.
AI
Here at Penguin, we believe in the power of authenticity and human creativity. When you apply for a position, we want to encourage you to showcase your unique voice. Throughout our recruitment process, please share your own thoughts, experiences, and skills. This helps us get a true sense of who you are and what you might bring to our team.
We celebrate creativity and diverse perspectives, so please be yourself! While we recognise AI tools can be helpful, we recommend using them thoughtfully to ensure your responses reflect you.
Disability Confident
As a Disability Confident Committed organisation, we offer interviews to candidates with a disability who meet the essential criteria for the role, and opt-in on their application form. The essential criteria for this role are listed as part of the 'What you'll bring' section.
There may be times when the volume of applications means we cannot take all eligible candidates to interview. We encourage you to tell us about any reasonable adjustments you may need by emailing PRHCareersUK@penguinrandomhouse.co.uk. Remember, you only need to share what you are comfortable with, for us to support your request.
Salary
The salary for this opportunity is £60,000-£65,000 depending on how your skills and experience align to the role, plus a generous bonus scheme and benefits.
Hybrid Working
While our offices across the UK are places to connect, collaborate and celebrate with colleagues, we recognise that flexibility around where you work is just as important.
For this role we expect that you will work from our head office in Embassy Gardens, London a minimum of 2 days per week (Tuesday & Thursday) with additional days for team meetings, townhalls etc. as required. There may also be occasional travel to our warehouse site in Frating, Colchester.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location