Coforge
Vulnerability Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role: Vulnerability Engineer
Location: London, UK
Work-mode: Hybrid - 3 days weekly from office
Skills: Vulnerability, Qualys, PowerShell and Microsoft SCCM/MECM
We at Coforge are looking for a Vulnerability Engineer in London, UK.
Scope & Description of Required Work
The requirement is for one EUP Vulnerability Engineer to provide the following services:
- Own the technical investigation and remediation of complex endpoint vulnerabilities across the workstation estate.
- Analyse and prioritise findings from Qualys and other approved security platforms, considering technical impact, business risk and remediation feasibility.
- Perform structured root cause analysis for vulnerabilities, failed deployments, recurring non-compliance and endpoint health issues.
- Design, test and deliver sustainable engineering fixes that remove underlying causes and reduce repeated manual remediation.
- Create, test, peer review and deploy enterprise application packages, security updates and configuration changes through Microsoft SCCM/MECM and related endpoint tooling.
- Develop and maintain PowerShell automation for detection, remediation, validation, reporting and operational health checks.
- Troubleshoot SCCM/MECM client health, software distribution, content delivery, deployment status and patch installation failures.
- Use controlled pilot groups, technical validation and rollback planning to reduce deployment risk.
- Work with the End User Platform and Security teams to agree remediation strategy, technical ownership and delivery priorities.
- Recommend improvements to packaging standards, deployment controls, vulnerability workflows, reporting and endpoint engineering processes.
- Produce clear technical documentation, remediation records, runbooks, knowledge articles and audit evidence.
- Provide accurate progress, risk and dependency updates for vulnerability, compliance and service reporting.
- Support remediation across physical workstations, laptops and Citrix virtual desktop environments.
- Apply ITIL best practice across Incident, Request, Problem and Change management activities.
- Perform system administration and advanced troubleshooting within Windows, Active Directory, Group Policy and Microsoft 365 environments.
- Ensure solutions comply with TMHCC security policies, technical standards, controls and agreed service levels.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Out of Scope
- Activities not explicitly listed in the Scope & Description of Required Work.
- Changes to production services that have not completed the required TMHCC change control and approval process.
- Ownership of security policy, risk acceptance decisions or business risk sign-off.
- Work on unsupported platforms or systems outside the agreed endpoint estate unless separately authorised.
Deliverables & Delivery Milestones
- Prioritised vulnerability remediation backlog based on approved security data and agreed delivery priorities.
- Tested and peer-reviewed SCCM/MECM packages, security updates and configuration changes.
- Production-ready PowerShell detection, remediation and validation scripts.
- Root cause analysis records for recurring vulnerabilities, failed deployments and endpoint health issues.
- Pilot, validation and rollback evidence for controlled deployments.
- Runbooks, knowledge articles, remediation records and audit evidence.
- Regular progress, risk, dependency and outcome reporting.
- Delivery milestones and target dates to be agreed during onboarding and maintained through the applicable planning and change processes.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Acceptance Criteria
- Agreed vulnerability remediation activities are completed in line with approved priorities, change controls and service levels.
- Delivered packages, scripts and configuration changes pass agreed testing, peer review, pilot and technical validation requirements before production deployment.
- Remediation includes clear evidence of outcome, validation results and rollback arrangements where applicable.
- Root causes and recurring failure patterns are documented, with permanent engineering actions or technical debt items recorded where required.
- Technical documentation, runbooks, knowledge articles, remediation records and audit evidence are complete, accurate and stored in the agreed TMHCC location.
- Progress, risks, dependencies and blockers are reported accurately through the agreed governance process.
- Solutions comply with TMHCC security policies, technical standards and operational processes.
- Deliverables are accepted by the TMHCC Hiring Manager or nominated technical owner.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location