Now hiring

Senior Vulnerability Management Engineer @ HCLTech

Gracechurch Street 70, London AreaOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £30,000 - 50,000 per year

Requirements: 3–6 years of experience in vulnerability management or information security.Deep expertise in enterprise VM platforms such as Qualys VMDR, Tenable Security Centre / Tenable.io, or Rapid7 InsightVM.Strong understanding of CVE/CVSS v3.1 scoring, EPSS, and the CISA Known Exploited Vulnerabilities (KEV) catalogue.Experience with web application scanning tools such as Burp Suite Pro, OWASP ZAP, Tenable Web App Scanning, or HCL AppScan.Experience with cloud security posture tools such as AWS Inspector, Microsoft Defender for Cloud, Prisma Cloud, or Wiz.Experience with container and image vulnerability scanning tools such as Trivy, Snyk, Anchore, or Aqua Security.Automation and API integration experience using Python, REST APIs, and ServiceNow VR module configuration.SIEM integration experience with Splunk or Microsoft Sentinel.CMDB-driven asset correlation experience with ServiceNow CMDB.Network and infrastructure knowledge sufficient to assess vulnerability exploitability.Patch management workflow knowledge across Windows, Linux, and network devices.Experience consuming threat intelligence feeds to contextualise vulnerabilities.Familiarity with compliance frameworks such as ISO 27001, NIST CSF, CIS Controls, PCI DSS, or SOC 2 as they relate to vulnerability management.Strong risk communication skills.Excellent programme management skills.Analytical and data-driven approach.Collaborative working style.Proactive threat awareness.Clear and structured documentation skills.Preferred certifications include Qualys Certified Specialist – VMDR / TruRisk, Tenable Certified Security Engineer, CISSP, CEH, OSCP, CySA+, PenTest+, GIAC Vulnerability Assessor, Microsoft Certified: Security Operations Analyst (SC-200), or ITIL 4 Foundation/Managing Professional. Responsibilities: Own and operate the enterprise vulnerability management programme across endpoints, servers, network devices, web applications, and cloud.Design and maintain scan policies, asset groups, and scanning schedules to ensure full coverage.Perform risk-based vulnerability prioritisation using CVSS, asset criticality, exposure, threat intelligence, and business context.Translate vulnerability findings into actionable remediation tasks and define acceptance criteria for closure.Define, publish, and enforce the VM SLA policy and escalate breaches to asset owners and management.Lead the vulnerability exception and risk acceptance process, including compensating controls, residual risk documentation, and formal sign-off.Integrate VM tooling with SIEM, ITSM, and CMDB systems for automated ticket creation and asset correlation.Automate vulnerability reporting and remediation tracking using Python, REST APIs, or ServiceNow workflows.Conduct threat-informed vulnerability analysis and identify exploitable CVEs requiring emergency response.Lead response to zero-day vulnerabilities, including impact assessment, emergency patching or compensating controls, and stakeholder communication.Own web application vulnerability management and integrate DAST/SAST findings into the unified VM programme.Manage cloud vulnerability posture across hybrid cloud environments.Produce monthly VM programme dashboards, KPIs, and trend analysis for management review.Act as L2 escalation for L1 analysts and mentor team members.Lead or support internal VM audits and contribute to compliance evidence. Technologies: AIAPIAWSCloudCMDBSupportITILITSMLinuxNetworkOWASPPrismaPythonRESTSecurityServiceNowSplunkVRWebWindowsAnsibleAzureDevOpsFirewallSpark More:

We are a $13+ billion global technology company with more than 224,000 people across 60 countries, delivering capabilities in digital, engineering, cloud, and AI through a broad portfolio of technology services and products. We bring a startup mindset and an idea-first culture to everything we do, and we want people who are driven to make an impact. This Senior Vulnerability Management Engineer role is based in London, UK in a hybrid mode at a client location. We offer a supportive, diverse, and global team, competitive compensation and benefits, opportunities to upskill and work on exciting projects, and a strong focus on wellbeing, CSR, diversity, and employee engagement.

last updated 34 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores