Damia Group
Vulnerability Management Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Vulnerability Management Consultant
Location: Inverness or Preston, 5 days onsite
Rate: £500-568 per day depending upon experience
Duration: 31/03/2027
This temporary contract is inside IR35 and will require working under the direction of the client delivery manager as part of a multi-disciplinary team. The successful candidate will follow established delivery processes and working practices.
Due to the secure nature of the position and working environment, you must have, or be eligible to obtain Security Clearance. More details relating to UK Security Clearance can be found here: United Kingdom Security Vetting: clearance levels - GOV.UK
Role Overview
The Vulnerability Management Consultant operates within the Operational Integrator (OI) function in a multi-supplier (SIAM) environment, supporting the governance and coordination of vulnerability management activities across suppliers. The role supports the governance and visibility of vulnerability management activities across suppliers, ensuring risks are tracked, reported, and evidenced consistently without performing technical vulnerability remediation.
The role assists in ensuring vulnerabilities are identified, tracked, prioritised, and reported in accordance with client policies and agreed remediation timelines. Working with suppliers, service teams, and security stakeholders, the consultant provides visibility of vulnerability status and supports the maintenance of accurate reporting and audit evidence.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
This is a governance and coordination role and does not perform vulnerability scanning, security testing, patch deployment, or technical remediation activities.
Key Deliverables
- Vulnerability reporting packs
- Vulnerability status and remediation tracking
- Supplier vulnerability performance metrics
- Audit-ready evidence and reporting records
- Governance inputs to security forums
Responsibilities
Vulnerability Tracking & Coordination
- Support the monitoring of vulnerabilities from identification through to closure
- Ensure vulnerability records are maintained and updated by suppliers
- Assist in tracking remediation progress against agreed service levels
- Escalate overdue or high-risk vulnerabilities through agreed governance channels
Supplier Engagement (SIAM Model)
- Coordinate with suppliers to obtain vulnerability status updates
- Support the collection and validation of supplier vulnerability reports
- Ensure reporting formats and data standards are applied consistently
- Identify gaps in vulnerability information, ownership, or reporting
Vulnerability Reporting & Visibility
- Produce routine vulnerability management reports
- Support development of dashboards and metrics
- Assist in identifying:
- Aging vulnerabilities
- Recurring issues
- SLA breaches
- Emerging vulnerability trends


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Governance & Process Compliance
- Support adherence to agreed vulnerability management processes
- Ensure supplier activities align with client policies and standards
- Assist with documenting risk acceptance and exception processes
- Maintain evidence required for audits and assurance activities
Assurance & Evidence Support
- Collect and organise vulnerability management evidence
- Support compliance and assurance reviews
- Maintain audit-ready documentation and reporting records
- Assist in demonstrating process effectiveness to stakeholders
Skills and Experience
Essential
- Experience in cyber security, information security, service management, or governance roles
- Understanding of vulnerability management principles
- Knowledge of basic vulnerability risk concepts including:
- CVSS, KEV, etc.
- Risk ratings
- Remediation tracking
- Strong analytical and reporting skills
- Experience working with multiple stakeholders
Desirable
- Exposure to SIAM or multi-supplier environments
- Familiarity with vulnerability management tooling and reporting outputs
- Understanding of cyber security governance and assurance
- Experience in regulated or defence environments
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location