About this role
Salary: £65,000 - 65,000 per year
Requirements: Experience managing and maintaining a vulnerability management tool.In-depth understanding of information security, including malware, emerging threats, attacks, and vulnerability management.Proven information technology experience with an excellent understanding of network protocols and server infrastructure, including network segmentation.Windows Server and/or Linux experience.Ability to take a lead role in coordinating the timely diagnosis and resolution of major issues.Adheres to and promotes high standards.Understands and operates change management.Team player who is hardworking and self-motivated.Inquisitive and proactive approach to identifying security gaps.Ability to effectively plan and prioritise workloads, and to measure and report on current progress.Ability to remain calm under pressure and clearly communicate to all levels of management.Excellent attention to detail.Understanding of vulnerability and threat assessment frameworks such as CVSS, CVE, CWE, OWASP, and MITRE.Operational Technology (OT) management experience in vulnerability scanning.Competent at keeping up to date on Cyber Threat Intelligence (CTI).Desirable: experience with security or compliance standards such as PCI-DSS or ISO27001.Desirable: understanding and experience of working for a retail company.Desirable: foundational understanding of cloud-based infrastructure.Desirable: relevant industry-recognised security qualification.Desirable: understanding of DevOps architecture and code scanning.Desirable: offensive security experience.Desirable: experience of SCADA systems monitoring, Programmable Logic Controller (PLC), and control warehouse equipment.Desirable: experience of managing a TIP (Threat Intelligence Platforms).Desirable: experience of custom AI usage. Responsibilities: Manage and maintain vulnerability scanning and risk reporting tools.Take a lead role in planning, estimation, scoping, and delivery of key projects, ensuring progress is clearly communicated.Complete relevant security assessments, including debriefing key stakeholders on any apparent risks.Identify, execute, and support requirements as part of RvB exercises.Ensure all relevant vulnerabilities are correctly triaged, risk assessed, logged, and assigned to remediation teams.Support remediation teams with remediation strategies.Assist the Incident Response team with the investigation and resolution of security incidents when required.Create and maintain operational procedures, configuration, and technical documentation to a high standard.Manage and maintain metrics and reporting to demonstrate the effectiveness of our vulnerability management programme.Act as subject matter expert for the Vulnerability Management team and help coordinate efforts when managing emergency remediation and mitigation.Maintain awareness of new and emerging security threats and trends.Test or validate threat intelligence findings against our people, processes, and technologies.Review threat intelligence and advise on recommended mitigation strategies where appropriate.Act as a mentor for more inexperienced members of the Vulnerability Management team.Take a lead role in coordinating and overseeing efforts to mitigate significant threats or vulnerabilities identified by the team.Participate in a shift rota.Visit our Enderby Head Office in Leicester monthly, with additional visits as needed by the business or management. Technologies: AICloudDevOpsSupportLESSLinuxNetworkOWASPPLCSecurityWindows More:
We are partnering directly with NEXT to hire for this role. You will join our Information Security team, focusing on Vulnerability and Threat Management across our technology estate, with particular emphasis on our warehouse environment and the technology used within it. We help maintain awareness of new and emerging security threats and trends, manage vulnerability scanning and reporting tools, and support our Bug Bounty programme. The role involves reviewing threat intelligence, supporting incident response and engineering teams, producing reports for a range of audiences, mentoring less experienced team members, and coordinating mitigation efforts for significant threats or vulnerabilities. The position includes participation in a shift rota and requires a monthly visit to our Enderby Head Office in Leicester, with additional visits as required.
last updated 34 week of 2026