Vulnerability Management Engineer

Mccabe & Barton — United Kingdom · Posted ~12 hours ago

Senior Contract Hybrid £600-£750 per day

Skills

Vulnerability management Vulnerability discovery Vulnerability prioritization Remediation tracking Azure Infrastructure as Code Security automation CVSS assessment Security governance Terraform Google Cloud Platform Datadog Microsoft Sentinel Snyk SCA SBOM CVSS

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A large organization undergoing a major technology integration is seeking an experienced Vulnerability Management Engineer for a six-month engagement. The role covers vulnerability discovery and triage across cloud infrastructure, risk prioritization, remediation governance, security dashboards, and automation using infrastructure-as-code and security tooling.

Highlights

Six-month security engineering contract focused on vulnerability discovery, prioritization, remediation governance, and security automation across cloud environments, with strong exposure to Azure and infrastructure-as-code.

Description

Vulnerability Management Engineer London (Hybrid) £600 p/d - £750 p/d inside IR35 6-month contract Role Overview We are seeking an experienced Vulnerability Management Engineer to own vulnerability discovery, prioritisation, and remediation tracking across Azure and GCP environments during a critical integration programme. This role requires strong Azure expertise, with GCP experience desirable. You will work closely with engineering teams to identify, prioritise, and remediate security vulnerabilities while leveraging Infrastructure-as-Code and automation to improve security outcomes. Responsibilities Vulnerability Discovery & Triage Scan Azure and GCP infrastructure for known vulnerabilities using Datadog, Sentinel, or equivalent tooling.Integrate with SCA/SBOM tools such as Snyk for dependency scanning.Prioritise vulnerabilities based on CVSS score, exploitability, and business impact.Maintain a live vulnerability register and risk dashboard.Remediation Governance Maintain and execute emergency patching runbooks.Coordinate patch deployment across engineering teams.Track remediation SLAs and escalate blockers where necessary.Validate remediation activities through re-scanning and verification.Automation & Infrastructure-as-Code Use Terraform to automate vulnerability remediation workflows.Build CI/CD pipelines for patch verification and evidence collection.Automate scan scheduling and reporting.Develop reusable runbooks for common remediation activities.Integration Support Assess Azure and GCP security posture during a major cloud integration programme.Identify integration-related vulnerabilities and emerging attack surfaces.Coordinate with infrastructure teams to ensure secure system migrations.Support Snowflake security assessments, including access controls, encryption, and auditing.Continuous Improvement Support AI-assisted security analysis and automation initiatives.Evaluate threat intelligence and emerging vulnerabilities.Recommend security hardening opportunities based on industry best practice.Produce vulnerability intelligence and reporting to support detection engineering teams.Required Experience & SkillsVulnerability Management & Security Strong experience in Vulnerability Management and/or Application Security Engineering.Deep hands-on Azure administration experience, including subscriptions, resource groups, IAM, and networking.Experience with vulnerability scanning and management platforms such as Datadog and Microsoft Sentinel.Technical Engineering Strong Terraform and Infrastructure-as-Code experience.Python and/or PowerShell Scripting for automation and reporting.SQL skills for reporting and vulnerability analysis.Good understanding of CVSS scoring and risk prioritisation methodologies.Cloud & Data Platforms Azure Security Centre, Azure Policy, and Entra ID experience.Understanding of GCP security concepts desirable.Knowledge of Snowflake security fundamentals.Experience with container security and vulnerability scanning.Security & Compliance Knowledge of DORA, FCA, and SOC2 requirements.Understanding of patch management and change control processes.Experience with SBOM and Software Composition Analysis (SCA) tooling.Comfortable working in a fast-paced, regulated environment.