Cyber Security Lead – Vulnerability Management
Protect Social Security Scotland's digital services, systems, and sensitive information from emerging cyber threats. Lead the delivery and continuous improvement of Vulnerability Management services. Drive the identification, assessment, prioritisation, and remediation of vulnerabilities.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
We are seeking an experienced and motivated Cyber Security Lead – Vulnerability Management to join the Digital Risk & Security branch within Digital Delivery & Change. This role is responsible for leading the delivery and continuous improvement of Vulnerability Management services, helping to protect Social Security Scotland’s digital services, systems, and sensitive information from emerging cyber threats.
As a technical lead within the Security Operations function, you will lead a small team of specialist security professionals and provide leadership and expertise across the organisation’s vulnerability and exposure management capabilities. Working closely with infrastructure, application, cloud, and security teams, you will drive the identification, assessment, prioritisation, and remediation of vulnerabilities, ensuring that cyber risks are effectively managed and reduced across a complex, cloud-first technology estate.
You will lead the operational delivery and development of key Vulnerability Management services, including:
- Vulnerability and Exposure Discovery
- Vulnerability Triage, Risk Assessment and Reporting
- Risk-Based Vulnerability Prioritisation
- Security Configuration and Hardening Assurance
- Patch and Remediation Governance
- Asset Discovery and Attack Surface Management
- Cloud Security and Vulnerability Monitoring
- Vulnerability Metrics, Reporting, and Continuous Improvement
- Threat-Informed Risk Assessment and Remediation Planning
If you are passionate about reducing cyber risk, improving security resilience, and helping protect critical public services, we would welcome your application.
The Vulnerability Management Lead is responsible for protecting the confidentiality, integrity, and availability of information and information systems used by government and Partners Across Government.
- Performs security risk, vulnerability assessments, and business impact analysis for complex information systems or risk-based projects.
- Investigates security breaches in accordance with established procedures and recommends required actions and supports / follows up to ensure these are implemented.
- Specifies requirements for environment, data, resources and tools. Interprets, executes and documents complex test scripts using agreed methods and standards.
- Contributes to the development of cyber security policy, standards and guidelines appropriate to business, technology and legal requirements and in accordance with best professional and industry practice.
- Understands “voice of the customer” and develops mechanisms to proactively sense adoption and usage patterns of consumer technologies by end users so that policy can align with need.
Searching for Cyber Security roles that provide visa sponsorship? Connect with international employers through Cyber Security Jobs with Visa Sponsorship opportunities actively seeking talented professionals.
- Leads the identification, assessment and remediation of security vulnerabilities across infrastructure, endpoints, applications and cloud services, using threat intelligence and risk-based prioritisation to reduce cyber risk.
- Has oversight of security administration processes and checks that all requests for support are dealt with according to agreed procedures.
- Contributes to the development of cyber security policy, standards and guidelines appropriate to business, technology and legal requirements and in accordance with best professional and industry practice.
- Deliver specific pieces of work resulting from the Cyber Security Strategy, related to cyber business risk and information control/protection requirements.
- Champion incident management, incident investigation and response policy and/or incident management and investigation processes, procedures and systems.
- Performs security risk, vulnerability assessments, and business impact analysis for complex information systems or risk-based projects.
- Leads and directs Cyber Security Analysts to create test cases using in-depth technical analysis of risks and typical vulnerabilities and to produce test scripts, materials and test packs to test new and existing software or services.
- Specifies requirements for environment, data, resources and tools. Interprets, executes and documents complex test scripts using agreed methods and standards.
- Maintains current knowledge of malware attacks, and other cyber security threats.
- Maintains knowledge of specific specialisms, provides detailed advice regarding their application and executes specialised tasks.
We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.
For this post, the following Success Profile elements will be assessed:
Experience
- Experience of designing and performing vulnerability and/or configuration non-compliance risk assessments using appropriate risk assessment methodologies to effectively and consistently manage exposure risks in complex IT environments with competing priorities.
- Experience of designing and implementing safe multi-platform test programmes for systems, products, applications or processes, selecting suitable techniques, tools and test strategies to identify vulnerabilities, and determine whether they are exploitable, adapting your testing approach based on findings.
- Leadership - Level 3
- Communicating and Influencing - Level 3
Explore our comprehensive directory of visa sponsorship jobs from employers worldwide who are ready to sponsor talented international professionals.
Technical / Professional Skills:
This role is aligned to Lead Cyber Security Analyst within the Government Digital and Data Profession.
These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage. Please review the following to understand the skill expectations: Cyber security: operations - gov.scot
How To Apply
Apply online, you must provide a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet the Experience and Behaviours listed in the Success Profiles above.
Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action.
Please see our candidate guidance for more information on acceptable and unacceptable uses of AI in recruitment
Should a large number of applications be received, an initial sift may be completed using the CV and Supporting Statement against the first Experience criteria. Candidates who pass the initial sift will have their applications fully assessed.
Successful candidates will be invited to an interview which will assess the Experience and Behaviours, and a Technical Assessment comprising a 10 minute presentation which will assess the Technical Skills.
There may be a telephone interview prior to the final interview stage.
Full details of the interview and assessment process will be shared with shortlisted candidates once the sift has been completed.
We aim to provide feedback on request. However, where a large number of applications are received, it may not be possible to give feedback to candidates who are not invited to interview or assessment. Feedback will be available on request to all candidates who attend an interview or assessment.
Expected Timeline (subject to change)
Sift - w/c 24th August
Interview – w/c 7th September
Location - In Person in either Dundee or Glasgow
Reserve List
In the event that there are more successful candidates than posts available, a reserve list will be kept for up to 12 months.
About Us
Social Security Scotland is an Executive Agency of the Scottish Government. Our benefits help people from all walks of life in Scotland. We offer rewarding careers and employ people across Scotland in a wide range of professions and roles. We are committed to recruiting a diverse workforce that is representative of the clients we serve. Find more about us here.
We offer a supportive and inclusive working environment along with a wide range of employee benefits. Find out more about what we offer.
Interested in opportunities specifically in United Kingdom? Discover our dedicated Visa Sponsorship Jobs in United Kingdom page featuring roles from top employers in this location.
GDD Pay Supplement
This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000 annual GDD pay supplement, which is paid monthly - pay supplements are reviewed regularly.
Working Pattern
Our standard hours are 35 hours per week and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location, which will be either Glasgow or Dundee. If you have specific questions about the role you are applying for, please contact us.
Security checks
Successful candidates must complete the Baseline Personnel Security Standard (BPSS), before they can be appointed. BPSS is comprised of four main pre-employment checks – Identity, Right to work, Employment History and a Criminal Record check (unspent convictions).
You can find out more about BPSS on the UK Government website, or read about the different levels of security checks in our Candidate Guide.
This post requires the successful candidate to clear additional National Security Vetting clearance (Security Check) before a start date can be offered. Further information regarding National Security Vetting clearance can be found here - United Kingdom Security Vetting: Applicant - GOV.UK
Equality Statement
Social Security Scotland are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.
Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance with any part of our recruitment process, please contact us at [email protected].
Find out more about our commitment to diversity and how we offer and support recruitment adjustments for anyone who needs them.
Right to Work in the UK
Social Security Scotland is an approved sponsor under the UK Visa and Immigration (UKVI) Skilled Worker route. Please note that UK immigration guidance, including skill and salary thresholds and eligible occupations, is reviewed regularly and subject to change. If you require visa sponsorship, you should check the latest criteria to confirm whether this role meets current requirements before applying. You can find further advice on Gov.UK - Skilled Worker visa: Overview - GOV.UK
Further Information
Social Security Scotland’s recruitment processes are underpinned by the recruitment principles of the Civil Service Commissioner, which outline that selection for appointment be made on merit on the basis of fair and open competition - Recruitment - Civil Service Commission
If you feel at any time your application has not been treated in accordance with the values in the Civil Service Code and/or if you feel the recruitment has been conducted in such a way that conflicts with the Civil Service Commissioner’s Recruitment Principles, you can make a complaint, by contacting Social Security Scotland at [email protected] in the first instance. If you are not satisfied with the response you receive you can contact the Civil Service Commissioner.
The successful candidate will be expected to remain in post for a minimum of 3 years unless successful in gaining promotion to a higher Band or Grade.
Find out more about our organisation, what we offer staff members and how to apply on our Careers Website.
Read our Candidate Guide for further information on our recruitment and application processes.
If you experience any difficulties accessing our website or completing the online application form, please contact the Resourcing Team via [email protected] .
Apply before 23:55 on Thursday 20th August
Contact Name - Resourcing Team
Contact email – [email protected]
Similar Jobs
Explore other opportunities that match your interests