Cyber Security Analyst – Vulnerability Management

Company: Morson Group
Apply for the Cyber Security Analyst – Vulnerability Management
Location: London
Job Description:

Overview

In this senior role, you lead vulnerability identification, assessment and prioritisation across infrastructure, endpoints, cloud and applications to drive remediation. You’ll interpret risk using CVSS and business impact, coordinate with cross-functional teams, and monitor emerging threats to safeguard the enterprise. You report to senior stakeholders, optimise processes and tooling, and shape vulnerability management across a complex environment. A strong focus is on risk-based decision making and clear communication of technical risk and remediation steps. This opportunity offers exposure to a mature security function and meaningful impact on risk posture.

Responsibilities

  • Lead identification, assessment and prioritisation of vulnerabilities across infrastructure, applications, endpoints and cloud environments
  • Analyse vulnerability scan results to differentiate genuine risks from false positives and low-impact findings
  • Assess vulnerabilities using CVSS, exploitability, asset criticality, exposure and business impact
  • Monitor emerging vulnerabilities, zero-days and threat intelligence
  • Collaborate with infrastructure, cloud, application, DevOps and IT operations teams to coordinate remediation
  • Track vulnerabilities through to resolution with risk-based timelines
  • Provide technical guidance and challenge remediation plans and compensating controls
  • Produce vulnerability reporting, dashboards and management information for technical and senior stakeholders
  • Identify trends and systemic weaknesses across the environment
  • Improve vulnerability management processes, tooling, automation and reporting

Key requirements

  • Significant experience in vulnerability management, assessment or cyber security operations
  • Strong understanding of vulnerability assessment methodologies and risk-based prioritisation
  • Hands-on experience with Tenable, Qualys, Rapid7 or similar
  • Strong understanding of CVSS, CVE, CWE and common vulnerability types
  • Experience analysing vulnerabilities across Windows, Linux, network infrastructure, cloud and/or applications
  • Good understanding of patching, configuration management and security controls
  • Proven experience driving remediation with technical teams
  • Strong analytical and problem-solving skills with ability to communicate risk to technical and non-technical stakeholders
  • Eligible for UK SC security clearance
  • Stakeholder communication
  • Analytical thinking
  • Problem-solving
  • Tenable
  • Qualys
  • Rapid7

…

Posted: October 5th, 2026