Skip to main content
Posted 12 August, 2026

Vulnerability Management Consultant

Damia Group LTD
Preston, ENG, GB Full Time

Job Description

\n

Vulnerability Management Consultant - Location: Inverness or Preston, 5 days onsite - £500-568 per day depending upon experience Duration: 31/03/2027

\n

This temporary contract is inside IR35 and will require working under the direction of the client delivery manager as part of a multi-disciplinary team. The successful candidate will follow established delivery processes and working practices.

\n

Due to the secure nature of the position and working environment, you must have, or be eligible to obtain Security Clearance

\n

More details relating to UK Security Clearance can be found here:

\n

United Kingdom Security Vetting: clearance levels - GOV.UK

\n

The Vulnerability Management Consultant operates within the Operational Integrator (OI) function in a multi-supplier (SIAM) environment, supporting the governance and coordination of vulnerability management activities across suppliers. The role supports the governance and visibility of vulnerability management activities across suppliers, ensuring risks are tracked, reported, and evidenced consistently without performing technical vulnerability remediation.

\n

The role assists in ensuring vulnerabilities are identified, tracked, prioritised, and reported in accordance with client policies and agreed remediation timelines. Working with suppliers, service teams and security stakeholders, the consultant provides visibility of vulnerability status and supports the maintenance of accurate reporting and audit evidence.

\n

This is a governance and coordination role and does not perform vulnerability scanning, security testing, patch deployment, or technical remediation activities.

\n

Key Deliverables

\n

Vulnerability reporting packs
\n Vulnerability status and remediation tracking
\n Supplier vulnerability performance metrics
\n Audit-ready evidence and reporting records
\n Governance inputs to security forums

\n

Vulnerability Tracking & Coordination

\n

Support the monitoring of vulnerabilities from identification through to closure
\n Ensure vulnerability records are maintained and updated by suppliers
\n Assist in tracking remediation progress against agreed service levels
\n Escalate overdue or high-risk vulnerabilities through agreed governance channels
\n Supplier Engagement (SIAM Model)

\n

Coordinate with suppliers to obtain vulnerability status updates
\n Support the collection and validation of supplier vulnerability reports
\n Ensure reporting formats and data standards are applied consistently
\n Identify gaps in vulnerability information, ownership, or reporting
\n Vulnerability Reporting & Visibility

\n

Produce routine vulnerability management reports
\n Support development of dashboards and metrics
\n Assist in identifying:
\n Aging vulnerabilities
\n Recurring issues
\n SLA breaches
\n Emerging vulnerability trends
\n Governance & Process Compliance

\n

Support adherence to agreed vulnerability management processes
\n Ensure supplier activities align with client policies and standards
\n Assist with documenting risk acceptance and exception processes
\n Maintain evidence required for audits and assurance activities
\n Assurance & Evidence Support

\n

Collect and organise vulnerability management evidence
\n Support compliance and assurance reviews
\n Maintain audit-ready documentation and reporting records
\n Assist in demonstrating process effectiveness to stakeholders

\n

Your skills and experience

\n

Essential

\n

Experience in cyber security, information security, service management, or governance roles
\n Understanding of vulnerability management principles

\n

Knowledge of basic vulnerability risk concepts including:
\n CVSS, KEV etc
\n Risk ratings
\n Remediation tracking
\n Strong analytical and reporting skills
\n Experience working with multiple stakeholders

\n

Desirable

\n

Exposure to SIAM or multi-supplier environments
\n Familiarity with vulnerability management tooling and reporting outputs
\n Understanding of cyber security governance and assurance
\n Experience in regulated or defence environments

\n

Damia Group Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept our Data Protection Policy which can be found on our website.

\n

Please note that no terminology in this advert is intended to discriminate on the grounds of a person's gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and ability to perform the duties of the job.

\n

Should the role require the successful candidate to undergo and be eligible for UK Security Vetting. Clearance sponsorship will be provided where required. Due to the nature of the work, candidates should meet the relevant residency requirements. If applicable, Reserved Post nationality restrictions will be confirmed by the client. Damia is committed to inclusive recruitment and welcomes applicants from all backgrounds.

\n

Damia Group is acting as an Employment Business in relation to this vacancy and in accordance to Conduct Regulations 2003.