HCLTech
Vulnerability Management Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products.
HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here. We’ve always approached our work with an idea-first attitude because every one of our accomplishments —no matter how big or small —can be traced back to an idea’s single spark.
It’s that spark —that inner drive —that sets our people apart from our competitors. It enables us not just to pull off game-changing feat after game-changing feat but to better our world in the process. We want you to find your spark. Because that’s what drives you to be better, be more and ultimately, be more fulfilled.
Domain
Vulnerability Management (Cross-Domain)
Level
L1 – Junior
Location
On-site / Hybrid London, UK
Experience
2– 3 years in IT security / infrastructure support
Education
B.Tech / BCA / B.Sc. (Computer Science / IT / Cybersecurity) or equivalent
Role Description
The L1 Vulnerability Management Analyst supports the organisation's vulnerability identification and tracking programme across End User Computing, Data Center, Network, and Application Infrastructure domains. The role focuses on executing scheduled scans, processing scan outputs, tracking remediation progress, and co-ordinating with patch teams to drive closure of identified vulnerabilities.
Key Responsibilities
- Execute scheduled vulnerability scans across endpoint, server, network, and application environments using tools such as Qualys, Tenable Nessus, or Rapid7 InsightVM.
- Process and validate scan results: filter false positives, normalise findings, and classify vulnerabilities by CVE, CVSS score, and asset criticality.
- Distribute vulnerability reports to the relevant patch management and infrastructure teams (EUC, Data Center, Networks, App Infra) for remediation.
- Track remediation status against defined SLAs (Critical: 72 hrs, High: 7 days, Medium: 30 days, Low: 90 days) and follow up with asset owners.
- Update vulnerability tracking dashboards and ITSM tickets with remediation progress and exceptions.
- Assist in maintaining the asset inventory and ensuring scan coverage across all known assets.
- Flag newly identified critical or zero-day vulnerabilities to the L2 engineer and SOC team immediately.
Technical Skills & Knowledge
- Basic understanding of vulnerability scanning concepts: authenticated vs unauthenticated scans, scan policies, and asset groups.
- Familiarity with vulnerability management tools: Qualys VMDR, Tenable Nessus, or Rapid7 InsightVM.
- Ability to read and interpret CVE entries, CVSS v3 scores, and vendor advisories.
- Basic knowledge of OS platforms (Windows, Linux) and network devices sufficient to contextualise findings.
- Awareness of common vulnerability categories: unpatched OS/applications, misconfigurations, end-of-life software, weak credentials.
- Working knowledge of ITSM platforms (ServiceNow, Remedy) for ticket creation and tracking.
- Basic Excel / reporting skills for vulnerability metrics and trend tracking.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Soft Skills & Competencies
- Detail-oriented – accurately classifies and tracks large volumes of vulnerability data.
- Good written communication for distributing reports and following up on remediation.
- Organised and deadline-driven to maintain SLA adherence across multiple teams.
- Team player – works closely with patch, SOC, and infrastructure teams.
- Willingness to learn threat landscape and security concepts rapidly.
Preferred Certifications
- CompTIA Security+
- Qualys Certified Specialist – Vulnerability Management
- Tenable Nessus Fundamentals (Tenable University)
- ITIL 4 Foundation
- CEH (Certified Ethical Hacker) – advantageous
Domain
Vulnerability Management (Cross-Domain)
Level
L2 – Mid-Level
Location
On-site / Hybrid - London, UK
Experience
3 – 6 years in vulnerability management / information security
Education
B.Tech (Computer Science / Cybersecurity / IT) or equivalent
Role Summary
The L2 Senior Vulnerability Management Engineer owns the organisation's end-to-end vulnerability management programme, spanning EUC, Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement of the VM programme.
Key Responsibilities
- Own and operate the enterprise vulnerability management programme across all technology domains (endpoints, servers, network devices, web applications, cloud).
- Design and maintain scan policies, asset groups, and scanning schedules in Qualys VMDR / Tenable Security Centre / Rapid7 InsightVM to ensure full coverage.
- Perform risk-based vulnerability prioritisation: correlate CVSS scores with asset criticality, exposure, threat intelligence (EPSS, CISA KEV), and business context.
- Translate vulnerability findings into actionable remediation tasks for patch management teams across EUC, Data Center, Networks, and Application Infra; define acceptance criteria for closure.
- Define, publish, and enforce the VM SLA policy; escalate breaches to asset owners and management.
- Lead the vulnerability exception and risk acceptance process: assess compensating controls, document residual risk, and obtain formal sign-off.
- Integrate VM tooling with SIEM (Splunk, Microsoft Sentinel), ITSM (ServiceNow VR module), and CMDB for automated ticket creation and asset correlation.
- Automate vulnerability reporting and remediation tracking using Python, REST APIs (Qualys/Tenable API), or ServiceNow workflows.
- Conduct threat-informed vulnerability analysis: monitor NVD, CISA KEV, vendor security advisories, and threat intelligence feeds to identify exploitable CVEs requiring emergency response.
- Lead response to zero-day vulnerabilities: assess impact across the estate, co-ordinate emergency patching or compensating controls, and communicate status to security leadership.
- Own web application vulnerability management: integrate DAST/SAST findings (Burp Suite, Checkmarx, Veracode) into the unified VM programme.
- Manage cloud vulnerability posture: AWS Inspector, Microsoft Defender for Cloud, or Prisma Cloud for hybrid cloud environments.
- Produce monthly VM programme dashboards, KPIs, and trend analysis for CISO and management review.
- Act as L2 escalation for L1 analysts; mentor team members and review scan configurations and reports.
- Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Technical Skills & Knowledge
- Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre / Tenable.io, or Rapid7 InsightVM.
- Strong understanding of CVE/CVSS v3.1 scoring, EPSS (Exploit Prediction Scoring), and CISA Known Exploited Vulnerabilities (KEV) catalogue.
- Experience with web application scanning: Burp Suite Pro, OWASP ZAP, Tenable Web App Scanning, or HCL AppScan.
- Cloud security posture: AWS Inspector, Microsoft Defender for Cloud, Prisma Cloud, or Wiz.
- Container and image vulnerability scanning: Trivy, Snyk, Anchore, or Aqua Security.
- Automation and API integration: Python scripting, REST API calls to Qualys/Tenable/Rapid7; ServiceNow VR module configuration.
- SIEM integration: Splunk, Microsoft Sentinel – correlating vulnerability data with threat events.
- CMDB-driven asset correlation: ServiceNow CMDB, ensuring VM data reflects accurate asset inventory.
- Patch management workflow knowledge across Windows (SCCM/Intune), Linux (Satellite/Ansible), and network devices – to drive effective remediation co-ordination.
- Threat intelligence: experience consuming TI feeds (MISP, OpenCTI, commercial TI platforms) to contextualise vulnerabilities.
- Familiarity with compliance frameworks: ISO 27001, NIST CSF, CIS Controls, PCI DSS, SOC 2 – as they relate to vulnerability management.
Preferred Certifications
- Qualys Certified Specialist – VMDR / TruRisk
- Tenable Certified Security Engineer (TCSE)
- Certified Information Systems Security Professional (CISSP) – or working towards
- Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP)
- CompTIA CySA+ or PenTest+
- GIAC Vulnerability Assessor (GEVA)
- Microsoft Certified: Security Operations Analyst (SC-200) – advantageous for Azure environments
- ITIL 4 Foundation or Managing Professional
Benefits
- A supportive, diverse, and global team with a brilliant culture.
- Competitive compensation and benefits that includes up to 20 days’ vacation per year, various insurances like Term life and Business Travel insurance. These are apart from the statutory benefits applicable in the country. Employee benefits are regulated by an internal policy that contains full details regarding the entitlement and conditions for the benefits as per the law of the land.
- Total Wellbeing is our focus. Alongside your professional excellence, you join the likeminded colleagues to create a larger impact within the company and society at large in your chosen area of passion - CSR Council, Diversity Council, Women Connect, Sparks – Engagement Champion to name a few.
To know more about us visit – www.hcltech.com
For more information on how we process your personal data, please refer to HCLTech’s Candidate Data Privacy Notice.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location