• Own the end-to-end vulnerability management lifecycle across our products and supporting technology, from identification and validation through prioritisation, remediation tracking, risk acceptance and reporting.
• Triage and validate findings from multiple sources, including SAST, DAST, SCA, secrets scanning, penetration testing and web application scanning.
• Work closely with Engineering and Product teams to drive remediation of vulnerabilities, helping teams understand technical risk, agree appropriate remediation actions and meet defined remediation timelines.
• Partner with teams responsible for integrating security tooling into our CI/CD pipelines, helping improve the quality, coverage and effectiveness of that tooling.
• Develop and continuously improve risk-based vulnerability prioritisation, considering exploitability, asset exposure, business criticality, threat intelligence and compensating controls rather than relying solely on scanner severity.
• Identify recurring vulnerability patterns and root causes, working with engineering teams to reduce systemic weaknesses rather than repeatedly fixing individual findings.
• Continuously improve vulnerability management processes, dashboards and workflows, bringing strong technical ownership and ideas for making the programme more scalable and effective.
• Support the security review of software supply chain risks, including dependency management, build pipeline security and relevant secure software development practices.
• Review and validate findings from cloud security and CSPM platforms, helping Infrastructure and Engineering teams prioritise and remediate cloud vulnerabilities and configuration weaknesses.
• Research emerging cloud threats, vulnerabilities and misconfiguration patterns and recommend appropriate mitigations.
• Support the implementation and improvement of cloud security controls and security baselines where required.