McCabe & Barton
Vulnerability Management Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Vulnerability Management Engineer
London (Hybrid, 3 Days in Office)
£600 p/d - £750 p/d inside IR35
6-month contract
Role Overview
We are seeking an experienced Vulnerability Management Engineer to own vulnerability discovery, prioritisation, and remediation tracking across Azure and GCP environments during a critical integration programme. This role requires strong Azure expertise, with GCP experience desirable.
You will work closely with engineering teams to identify, prioritise, and remediate security vulnerabilities while leveraging Infrastructure-as-Code and automation to improve security outcomes.
Responsibilities
Vulnerability Discovery & Triage
- Scan Azure and GCP infrastructure for known vulnerabilities using Datadog, Sentinel, or equivalent tooling.
- Integrate with SCA/SBOM tools such as Snyk for dependency scanning.
- Prioritise vulnerabilities based on CVSS score, exploitability, and business impact.
- Maintain a live vulnerability register and risk dashboard.
Remediation Governance
- Maintain and execute emergency patching runbooks.
- Coordinate patch deployment across engineering teams.
- Track remediation SLAs and escalate blockers where necessary.
- Validate remediation activities through re-scanning and verification.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Automation & Infrastructure-as-Code
- Use Terraform to automate vulnerability remediation workflows.
- Build CI/CD pipelines for patch verification and evidence collection.
- Automate scan scheduling and reporting.
- Develop reusable runbooks for common remediation activities.
Integration Support
- Assess Azure and GCP security posture during a major cloud integration programme.
- Identify integration-related vulnerabilities and emerging attack surfaces.
- Coordinate with infrastructure teams to ensure secure system migrations.
- Support Snowflake security assessments, including access controls, encryption, and auditing.
Continuous Improvement
- Support AI-assisted security analysis and automation initiatives.
- Evaluate threat intelligence and emerging vulnerabilities.
- Recommend security hardening opportunities based on industry best practice.
- Produce vulnerability intelligence and reporting to support detection engineering teams.
Required Experience & Skills
Vulnerability Management & Security


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Strong experience in Vulnerability Management and/or Application Security Engineering.
- Deep hands-on Azure administration experience, including subscriptions, resource groups, IAM, and networking.
- Experience with vulnerability scanning and management platforms such as Datadog and Microsoft Sentinel.
Technical Engineering
- Strong Terraform and Infrastructure-as-Code experience.
- Python and/or PowerShell Scripting for automation and reporting.
- SQL skills for reporting and vulnerability analysis.
- Good understanding of CVSS scoring and risk prioritisation methodologies.
Cloud & Data Platforms
- Azure Security Centre, Azure Policy, and Entra ID experience.
- Understanding of GCP security concepts desirable.
- Knowledge of Snowflake security fundamentals.
- Experience with container security and vulnerability scanning.
Security & Compliance
- Knowledge of DORA, FCA, and SOC2 requirements.
- Understanding of patch management and change control processes.
- Experience with SBOM and Software Composition Analysis (SCA) tooling.
- Comfortable working in a fast-paced, regulated environment.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location