NHS Supply Chain
Vulnerability Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Vulnerability Manager
Function: Cyber Security
Location: Hybrid Worker – Expectation is two days per week on site at our Nottingham office
Contract type: 6 Month Fixed Term Contract
Salary: Offered on a starting salary of £ 60,994
Closing Date: Thursday 17th September
NHS Supply Chain currently has an opportunity for a Vulnerability Manager to join our team during an exciting period of transformation, working to make it easier for the NHS to put patients first.
The NHS Supply Chain Cyber Security Team continues to evolve and expand its capabilities to support organisational resilience and secure service delivery. The team continues to grow, building in-house cyber capabilities, and there will be a number of exciting opportunities as we continue on this journey.
The Vulnerability Manager is responsible for leading and continuously improving NHS Supply Chain’s Vulnerability Management Service, ensuring cyber security vulnerabilities are identified, assessed, prioritised, remediated and reported in a timely and risk-based manner across the technology estate.
Working within a Service Integration and Management (SIAM) operating model, the role will provide oversight and governance across multiple managed service providers, including the Cyber Security Service Provider (CSSP), infrastructure, application and modern workplace providers.
The postholder will act as the authority for vulnerability management, ensuring that cyber risks are understood, communicated and addressed in a manner that protects critical services, while supporting regulatory compliance and operational resilience.
Every day you will…
- Own and develop the organisation's Vulnerability Management Strategy, Framework, Policies and Standards
- Lead the delivery and continuous improvement of vulnerability management capabilities across the organisation
- Drive governance processes covering vulnerability identification, assessment, prioritisation, remediation, exception management and reporting.
- Act as Service Owner for Vulnerability Management within the SIAM model.
- Coordinate activities across multiple service providers to ensure effective identification and remediation of vulnerabilities.
- Hold suppliers accountable for delivery against agreed vulnerability remediation targets and contractual obligations
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What can we offer you?
- Hybrid working opportunities, giving you the flexibility to work collaboratively in the office and remotely.
- We recognise our employees' hard work and contributions with annual bonus schemes, long service, and colleague recognition awards.
- 27 days holiday plus bank holidays
- We are dedicated to your development, through in-house training, support, and access to external qualifications to maximise your potential.
- A focus on your well-being offering 1 day of paid well-being leave and free access to the 24/7 Employee Assistance Programme
- Generous pension scheme (with us contributing 12% when you contribute 6%)
- Access to our Flexible Benefits Scheme, where you can choose from a variety of benefits such as Life Insurance, Critical Illness Cover, Income Protection, Health Cash Plan, Dental Insurance, and additional pension contributions that suit you.
- 2 days of paid volunteering leave allowing you to give back to your community.
- Access to many discounts from the Blue Light Card to NHS Discounts.
NHS Supply Chain, who are we?
Our role is to support the NHS to save lives and improve health. We are a part of the NHS family, and our role is to source, deliver and supply healthcare products, services and food for NHS trusts and healthcare organisations across England and Wales.
We serve every NHS Trust and operate a national network of distribution centres, managing relationships with more than a thousand suppliers and delivering more than 8,000,000 orders each year to more than 17,000 locations. Doing all of this on behalf of the NHS gives NHS staff more time to focus on their main priority of providing excellent patient care.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What skills will help you thrive in this role?
- Strong leadership and influencing skills.
- Excellent supplier and stakeholder management capabilities.
- Strong analytical and risk assessment skills.
- Ability to communicate technical cyber risks to non-technical audiences.
- Excellent reporting and presentation skills.
- Ability to challenge constructively and drive accountability.
- Strong organisational and prioritisation skills.
Desirable qualifications:
- CISSP, CISM, CRISC, GIAC certification, ITIL Foundation, SIAM Foundation, ISO 27001 Lead Auditor or Lead Implementer, Cyber Assessment Framework (CAF) knowledge
Our Inclusive Commitment
At NHS Supply Chain, we are committed to building an inclusive environment where difference is not only valued, but celebrated, giving everyone the opportunity to thrive in their career. Developing our people is key to our success, so if this role sounds like the right next step in your career but your experience doesn’t match perfectly with the job advert, we encourage you to still apply.
Struggling to complete our application form, and require additional support? Reach out to our Talent Acquisition team at careers@supplychain.nhs.uk who will be happy to help you with alternative ways to apply.
We reserve the right to close any vacancy from further submissions when we have received sufficient applications from which to make a shortlist. Please apply without delay if you wish to be considered for this role.
SCCL is a company Registered in England and Wales, with company number 10881715, to act as the management function of the NHS Supply Chain.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills