R

Cloud Security Posture & Vulnerability Manager

icon building Company : Royal London
icon briefcase Job Type : Full Time

Number of Applicants

 : 

000+

Click to reveal the number of candidates who applied for this job.
icon loader
icon loader

Let AI Supercharge Your Job Hunt!

JobCopilot scans 500,000+ company career sites daily to find jobs for you

Never miss an opportunity Save hours by auto-filling applications forms Land more interviews with tailored applications
happy man
thunder iconActivate JobCopilot

Job Description - Cloud Security Posture & Vulnerability Manager


Job Title: Cloud Security Posture & Vulnerability Manager


Contract Type: Permanent


Location: Edinburgh / Alderley


Working style: Hybrid 50% home/office based


Closing date: 6th March 2026


 


Intro


The Cloud Security Posture & Vulnerability Manager plays a pivotal role in ensuring Royal London’s cloud environments remain secure, resilient, and compliant. You will lead Royal London’s approach to cloud security configuration baselines, policy‑as‑code, continuous monitoring, vulnerability triage and prioritisation, and risk‑based remediation. Working closely with engineering, platform and architecture teams, you will embed cloud security controls into DevOps workflows, reduce configuration drift and privilege debt, and ensure alignment to industry frameworks (Mitre, NIST, CIS).


This hands-on role demands expertise in cloud security, strong collaboration, and the ability to operate in a data‑driven, multi‑cloud environment. You will influence the evolution of our cloud security programme, drive automation, support incident response, and ensure audit‑ready evidence across all cloud security domains.


 


About the role


·       Own and drive the multi‑cloud CSPM strategy, including standards, guardrails, baselines and policy‑as‑code aligned to cyber security benchmarks.


·       Manage cloud misconfiguration detection, automated reporting, and controls assurance across Azure and AWS.


·       Establish and oversee the enterprise vulnerability lifecycle for cloud services, VMs, containers, and serverless workloads.


·       Triage and prioritise vulnerabilities using CVSS or vendor scoring; coordinate remediation with engineering teams and ensure adherence to patching SLAs.


·       Develop CIEM controls to reduce privilege debt, enforce least‑privilege principles, detect toxic combinations, and strengthen identity‑related risk posture.


·       Provide cloud security consultancy, including architecture reviews, Terraform/IaC analysis, and threat modelling using structured frameworks (e.g. Mitre).


·       Develop automation for drift detection, vulnerability scanning, remediation, and compliance evidence.


·       Partner with engineering and platform teams to embed cloud security in CI/CD workflows.


·       Support incident response, threat analysis and the evolution of cloud security governance, monitoring and reporting.


·       Contribute to the development of cloud security policies, maturity roadmaps, and best‑practice guidance.


About you


·       Proven experience in cloud security across Azure and AWS, including CSPM, CIEM, vulnerability management and secure software development practices.


·       Certifications such as CCSP, Azure Security Engineer Associate, AWS Security Specialty, GIAC Cloud Security Automation or CISM are highly desirable.


·       Experience of TenableOne, Wiz, Sentinel One or Similar CSPM tooling.


·       Strong understanding of security frameworks and standards (Mitre, ISO 27001, NIST, CIS).


·       Experience with CI/CD, Infrastructure‑as‑Code, container security and serverless architectures.


·       Deep knowledge of cyber security and operational resilience trends, technologies and regulatory requirements, ideally within financial services.


·       Excellent communication, influencing and leadership skills, with the ability to translate complex security concepts to technical and non‑technical stakeholders.


·       Strong strategic thinking coupled with the ability to understand technical detail.


·       Highly proactive mindset, strong stakeholder management, and proven ability to drive continuous improvement.


·       Experience working cross‑functionally with engineering, architecture, suppliers and partners.


·       Ability to perform under pressure, maintain professionalism, and support the organisation during high‑severity incidents.


About Royal London


We’re the UK’s largest mutual life, pensions and investment company, offering protection, long‑term savings and asset management products and services. Our People Promise to our colleagues is that we will all work somewhere inclusive, responsible, enjoyable and fulfilling. This is underpinned by our Spirit of Royal London values; Empowered, Trustworthy, Collaborate, Achieve. We've always been proud to reward employees by offering great workplace benefits such as 28 days annual leave in addition to bank holidays, an up to 14% employer matching pension scheme and private medical insurance.


Inclusion, diversity and belonging


We’re an Inclusive employer. We celebrate and value different backgrounds and cultures across Royal London.


Original job Cloud Security Posture & Vulnerability Manager posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Auto-Apply to Cloud Security Posture & Vulnerability Manager Jobs with your AI JobCopilot

thunder icon Auto-Apply with AI

Similar Cloud Security Posture & Vulnerability Manager Jobs in the UK

GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast! Find the best jobs in the UK, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.