×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Director, Vulnerability Management

Job in Manchester, Greater Manchester, M9, England, UK
Listing for: Fitch Group, Inc.
Full Time position
Listed on 2026-01-15
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
Position: Director, Vulnerability Management )

Director, Vulnerability Management (Manchester)

Join to apply for the Director, Vulnerability Management (Manchester) role at F Group, Inc.

Requisition : 49163 Business Unit: Fitch Group Category: Information Technology Location: Manchester, GB Date Posted: Jan 8, 2026

Fitch Group is currently seeking a Director of Vulnerability Risk based out of our Manchester office.

We are seeking a Director to lead our Vulnerability Management (VM) team. This role is ideal for an experienced security leader with a risk mindset who can oversee all aspects of vulnerability management, including identification, risk prioritisation, and remediation of vulnerabilities discovered. The ideal candidate for this role will bring innovative ideas on how to consistently apply risk prioritisation through automation, leveraging AI where appropriate.

  • Application of a risk mindset with consideration for the company’s set of standing security controls
  • Ideas on opportunities to strengthen protection of our critical assets
  • Strong collaboration across the vulnerability management teams and stakeholders
  • Delivering real-time metrics reports
  • Remediation tracking aligned with organisational risk priorities

This is a new role to oversee a recently established unified vulnerability management programme, covering infrastructure and cloud scanning, application security testing, and penetration testing.

How You’ll Make An Impact
  • Define and execute the strategic roadmap for the Unified Vulnerability Management programme, including resource planning, performance tracking, and establishing and reporting on metrics.
  • Lead the end-to-end vulnerability management lifecycle using a consistent, risk-based assessment methodology that evaluates likelihood, impact, control environment and Fitch specific business context, ensuring timely remediation and compliance with internal policies.
  • Govern the intake, normalisation, and triage of findings originating from tools and assessments to ensure alignment with a unified lifecycle management process.
  • Manage vulnerabilities identified from scanning tools covering open source, custom source code, dynamic application scanning, static application scanning, infrastructure scanning, and cloud security posture management solutions (SCA, SAST, DAST, infrastructure, CSPM).
  • Provide risk informed visibility to stakeholders through clear dashboards and other reporting mechanisms which indicate remediation expectations.
  • Ensure proper reporting of vulnerabilities to stakeholders and drive remediation efforts from an Information Security perspective.
  • Develop strong partnerships with engineering, application development, and infrastructure teams to align remediation workflows and streamline ticketing processes for opening and closing vulnerabilities.
  • Maintain and track team workload, ensuring transparency and accountability.
  • Collaborate with subject matter experts across Info Sec and Technology to contextualise findings, validate assessments, resolve ambiguity and accelerate closure without compromising risk posture.
  • Own and ope rationalise Fitch’s cyber risk taxonomy, threat intelligence, compensating control analysis, and architectural context to ensure findings are prioritised appropriately.
  • Perform contextual analyses for vulnerability risk prioritisation based on business criticality, cloud architecture details, system and application architecture, and data confidentiality.
  • Produce and maintain dashboards, metrics and trend analyses to facilitate consumption of risk information and enable responses to requests for executive reporting and audit requests.
  • Deliver VM team projects on time and on budget, ensuring alignment with department goals, organisational goals and regulatory requirements.
You May Be a Good Fit If

The ideal candidate will have 7-10 years of progressive leadership experience in Information Security, with at least 2 years in a dedicated Vulnerability Management role. They should demonstrate strong leadership skills, experience managing vulnerabilities across SAST, DAST, SCA, infrastructure, and CSPM solutions, and excellent communication and collaboration abilities for engaging technical teams and senior stakeholders.

What Would Make You Stand Out
  • 7+ years of progressive security experience, with at least 3+ years assessing and managing vulnerability risks for multi-cloud enterprise systems.
  • Experience applying industry frameworks and compliance standards (NIST, DORA) to apply risk classifications during the vulnerability lifecycle management process.
  • Experience producing contextual analysis for vulnerability risk prioritisation based on system criticality, cloud architecture details, system and application architecture, and data confidentiality.
  • Experience coordinating management of multiple vulnerability scanning tools and managing vulnerabilities identified from scanning tools covering open source, custom code, dynamic application scanning, static application scanning, infrastructure scanning, and cloud security posture management…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary