Overview
As the Interim Vulnerability Management Modernisation Lead for a VC-backed digital bank, you will take charge of establishing and executing a comprehensive vulnerability management framework. This senior role involves collaborating with internal teams and external partners to enhance the bank's overall security posture while communicating with executive and board-level stakeholders to present progress and risks.
Responsibilities
- Establish and own the end-to-end vulnerability management framework, operating model, and remediation processes.
- Improve vulnerability scanning, patching, and validation across the technology estate.
- Rationalise the application estate to identify and eliminate unnecessary or unsupported technology.
- Select and implement patch-management tooling and develop risk-based policies for various asset classes.
- Define responsibilities, service levels, and delivery expectations for managed service providers and hold them accountable.
- Produce vulnerability and remediation reports for senior executives and the board, ensuring integration into business-as-usual operations.
Requirements
- Demonstrable experience in establishing or modernising enterprise vulnerability management functions.
- Deep knowledge of vulnerability scanning platforms and scanning methodologies.
- Hands-on experience with enterprise patch-management tooling implementation.
- Strong technical judgement to assess exposure and apply risk-based approaches.
- Experience rationalising technology estates as part of remediation strategies.
- Proven ability to hold managed service providers accountable for delivery outcomes.
- Effective communication skills to convey technical information to executive and board-level audiences.
- Prior experience in a regulated financial services environment is essential; experience in a challenger bank or fintech is highly desirable.