Vulnerability & Patch Management Engineer

Company: Shawbrook Bank
Apply for the Vulnerability & Patch Management Engineer
Location: London
Job Description:

Overview

In this role you will own the vulnerability management lifecycle across the estate, from detection to remediation. You will coordinate patching across on‑prem and cloud environments, prioritize risks, and report on metrics to leadership. You’ll work with infrastructure, security and application teams to improve speed and coverage, support compliance, and handle critical or zero‑day threats. This is an opportunity to strengthen Shawbrook’s security posture within a fast‑paced, collaborative culture.

Pay / Benefits

  • Headspace mindfulness app
  • Peppy fertility/menopause support
  • EAP – employee wellbeing resources
  • Cycle to work scheme
  • Gym membership discounts
  • Contributory pension and death in service

Responsibilities

  • Own vulnerability management lifecycle from scanning to closure
  • Coordinate patch management across servers, endpoints, network devices, and 3rd‑party apps
  • Prioritize vulnerabilities by severity and business risk (CVSS, threat intel)
  • Track SLAs, escalate high‑risk issues to stakeholders
  • Report vulnerability and patch KPIs to Service Delivery and CTO leadership
  • Coordinate with vendors and internal teams for timely patches
  • Support audit/compliance (ISO 27001, Cyber Essentials, PCI‑DSS) with accurate records
  • Continuously improve processes, tooling and automation to speed remediation
  • Act as escalation point for critical/zero‑day vulnerabilities

Key requirements

  • Proven experience in vulnerability management, patch management or IT security operations
  • Experience with vulnerability scanners (Qualys, Rapid7) and patch platforms (Ninja One, Ivanti, Intune)
  • Familiarity with CVSS, NIST risk frameworks
  • Experience in ITIL‑aligned service delivery (change and incident management)
  • Strong stakeholder management across infrastructure, cloud, infosec and application teams
  • Ability to report clearly to technical and non‑technical audiences
  • Relevant certifications (e.g. CompTIA Security+, CISSP, ITIL Foundation) advantageous
  • Stakeholder management
  • Clear reporting and communication
  • Collaborative cross‑functional working
  • Qualys
  • Rapid7
  • Ninja One

…

Posted: October 5th, 2026