← All jobs

Vulnerability Management Analyst

London, United Kingdom Full-time
Cyber Security EngineerDevSecOpsSOC AnalystSecurity AnalystCompliance Analyst

Archer is matching candidates to this role at Barclays. Create a free profile and Archer will check you against this role and every other live role, showing you exactly where you match.

Join us a Vulnerability Management Analyst with BPL CIO- own the end-to-end vulnerability lifecycle across the entire estate: from scanning orchestration through triage, prioritisation, SLA assignment, remediation tracking, exception management, and reporting. You are the single point of accountability for knowing, at any moment, what vulnerabilities exist in the organisation’s systems, how severe they are in the context of the business, who is responsible for fixing them, and whether they are being fixed within agreed timescales.

 

This role is critical because vulnerability management sits at the intersection of several key processes in the CISO operating model. The pre-release security sign-off process checks a service’s open vulnerability backlog before approving a production release — if a service has critical vulnerabilities open beyond SLA, it cannot ship new features. The monthly Risk and Compliance Steerco reviews vulnerability trends as a key risk indicator. The Board receives quarterly reporting on mean time to remediate and open vulnerability counts. The PCI DSS compliance programme depends on quarterly internal and external scanning with clean results. All of this runs through you.

 

The role requires a particular kind of judgement. You will deal with hundreds or thousands of vulnerability findings from multiple scanning tools (SAST, SCA, DAST, infrastructure scanning, CSPM, container scanning, penetration testing). Most of those findings will not be equally important. Your job is to contextualise them: a critical CVSS vulnerability in an internet-facing payment API is fundamentally different from the same CVSS score on an internal development tool with no access to sensitive data. You prioritise based on exploitability, business context, exposure, and regulatory sensitivity — not just generic severity scores.

 

If you are someone who combines analytical rigour with excellent stakeholder management skills— someone who can triage a thousand findings into a prioritised, actionable list and then work across a dozen engineering teams to ensure the right things get fixed in the right order — this role will suit you.

 

To be successful as a Vulnerability Management Analyst, you should have experience with;

  • Demonstrable experience in vulnerability management, security operations, or a related security discipline where you have been responsible for managing vulnerability findings from identification through to verified remediation
  • Experience with vulnerability scanning tools across multiple domains: infrastructure scanning (Tenable, Qualys, Rapid7, or equivalent), application scanning (SAST/DAST/SCA tools such as Semgrep, Snyk, Checkmarx, or Burp Suite), and cloud or container scanning (Wiz, Prisma Cloud, Trivy, or cloud-native equivalents)
  • Understanding of CVSS scoring and, critically, the ability to contextualise vulnerabilities beyond raw CVSS scores
  • Experience with contextual vulnerability prioritisation approaches: SSVC, EPSS, CISA KEV, or equivalent frameworks that move beyond generic severity to business-contextualised priority
  • Data analysis and dashboard creation skills
  • Familiarity with PCI DSS Vulnerability management requirements
  • Experience managing vulnerability exceptions and risk acceptances in a structured, documented process
  • Competence with ticketing and workflow tools (Jira, ServiceNow, or equivalent) for creating, tracking, and reporting on vulnerability remediation at scale

 

Some other highly valued skills may include;

  • Understanding of cloud and container vulnerability scanning: the differences between image scanning, registry scanning, and runtime scanning; the challenges of scanning ephemeral containers and serverless functions; and the implications of shared responsibility models for vulnerability ownership
  • Experience coordinating ASV (Approved Scanning Vendor) scans for PCI DSS, including scope definition, false positive management, and the rescan/remediation cycle required to achieve a clean quarterly scan
  • Payments or financial services experience, particularly in an environment subject to PCI DSS vulnerability management requirements.
  • Understanding of software composition analysis (SCA) and open-source dependency risk. The ability to assess the risk of a vulnerable transitive dependency in the context of how it is actually used in the application, rather than treating every SCA finding as equally urgent
  • Experience with exploit intelligence feeds (Recorded Future, Mandiant, CISA KEV) and using exploit availability and active exploitation status to inform prioritisation
  • Scripting skills (Python, Bash, or equivalent) for automating data extraction, normalisation, and reporting from scanning tools and APIs.
  • Experience operating vulnerability management in an agile or DevOps environment, including sprint-aligned remediation tracking and integration with CI/CD pipeline scan results
  • Background in penetration testing, security engineering, or software development — technical depth helps you write better tickets, validate remediations more effectively, and have more credible conversations with engineering teams

 

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills

 

The successful candidate will be based in London. Our offices are located at 7 Westferry Circus (new BPL office).

 

This role is 3 days per week office-based presence expected.

 

Apply knowing you're qualified

One free profile is all it takes. Archer checks you against this role and every other live role we list, and shows you exactly which requirements you meet before you apply.

More roles like this

See all matching roles

Not quite the right role?

Archer scans thousands of live roles and surfaces the ones you genuinely match, each with a clear explanation of why. It keeps working after you apply, so you hear about roles you would never have found by searching.

Create your free profile