Haystack
← Back to Jobs
Remote
Temporary/Casual
Technology
ME

Cyber Security Analyst - Vulnerability Management

Morson EdgeLondon, UK🇬🇧United KingdomPosted 9 Sept 2026

Why This Role Stands Out

This remote Cyber Security Analyst role offers a fantastic opportunity to lead vulnerability management within a reputable organization, driving significant impact through strategic risk assessment and remediation. If you are a skilled mid-senior professional with a knack for analysis and a proactive approach to security, you will thrive in this position. Apply today to leverage your expertise and advance your career in a dynamic cybersecurity environment.

Quick Overview

Salary
£600 - £650/mo
Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Remote
Location
London, UK, United Kingdom
Posted
20 hours ago
AWSAzureKubernetes

Job Description

Cyber Security Analyst - Vulnerability Management - £600-£650 per day - Inside IR35 - Remote with occasional attendance to a site in central Southampton.

My client is looking for an experienced Senior Vulnerability Analyst to join their Cyber Security team, taking a lead role in identifying, assessing and managing vulnerabilities across a complex enterprise technology environment.

This is a senior position requiring someone who can go beyond simply identifying vulnerabilities. You'll be expected to understand the underlying risk, prioritise remediation and work closely with infrastructure, cloud, application and security teams to drive vulnerabilities through to resolution.

Security Clearance -

Eligibility for UK Security Check (SC) clearance is a mandatory requirement for this role. Candidates who already hold active SC clearance will be prioritised.

Key Responsibilities -

  • Lead the identification, assessment and prioritisation of vulnerabilities across infrastructure, applications, endpoints and cloud environments.
  • Analyse vulnerability scan results, distinguishing genuine risks from false positives and low-impact findings.
  • Assess vulnerabilities using CVSS, exploitability, asset criticality, exposure and business impact.
  • Monitor emerging vulnerabilities, zero-days and relevant threat intelligence.
  • Work closely with infrastructure, cloud, application, DevOps and IT operations teams to coordinate remediation.
  • Track vulnerabilities through to resolution, ensuring remediation is completed within agreed risk-based timescales.
  • Provide technical guidance and challenge remediation plans, risk acceptances and proposed compensating controls where appropriate.
  • Produce vulnerability reporting, dashboards and management information for technical and senior stakeholders.
  • Identify trends, recurring vulnerabilities and systemic weaknesses across the environment.
  • Help improve vulnerability management processes, tooling, automation and reporting.


Essential Experience -

  • Significant experience in vulnerability management, vulnerability assessment or cyber security operations.
  • Strong understanding of vulnerability assessment methodologies and risk-based prioritisation.
  • Hands-on experience with enterprise vulnerability management platforms such as Tenable, Qualys, Rapid7 or similar.
  • Strong understanding of CVSS, CVE, CWE and common vulnerability types.
  • Experience analysing vulnerabilities across Windows, Linux, network infrastructure, cloud and/or applications.
  • Good understanding of patching, configuration management and security controls.
  • Proven experience working with technical teams to drive vulnerability remediation.
  • Strong analytical and problem-solving skills, with the ability to communicate technical risk clearly to both technical and non-technical stakeholders.
  • Eligible for UK SC security clearance.


Desirable Experience -

  • Active UK SC security clearance.
  • Experience working within Defence, Nuclear, Critical National Infrastructure (CNI) or other highly regulated and security-conscious organisations.
  • Experience with Azure and/or AWS vulnerability management.
  • Experience with container, Kubernetes or DevSecOps security.
  • Knowledge of application security and common web application vulnerabilities.
  • Experience using SIEM, EDR and threat intelligence alongside vulnerability data.
  • Knowledge of NIST, CIS, ISO 27001 or Cyber Essentials.
  • Relevant security certifications such as CISSP, CISM, GIAC, OSCP or similar.

The Ideal Candidate -

My client is looking for someone who combines strong technical vulnerability analysis skills with the ability to operate confidently at a senior level.
You'll be comfortable getting into the technical detail, while also being able to explain what the vulnerability means, how serious it is, what needs to be done and why.
This is an excellent opportunity for a senior vulnerability professional to join a complex organisation where cyber security, risk management and continuous improvement are key priorities.


Similar jobs