Initial 3 months with strong expectation of long-term extension
To start ASAP
About the role
We're supporting one of the world's leading technology companies in hiring a contractor to join their Information Security Assurance team.
This is an excellent opportunity for someone with a background in penetration testing or offensive security who enjoys understanding how vulnerabilities work and helping engineering teams reduce security risk at scale.
Rather than carrying out traditional penetration testing engagements, you'll analyse newly disclosed vulnerabilities, assess their potential impact across a large enterprise environment and work with internal stakeholders to drive remediation.
Responsibilities
Analyse newly published CVEs and security advisories to understand technical impact and exploitability. Assess the potential impact of vulnerabilities across enterprise infrastructure and systems. Identify affected assets using internal tooling and vulnerability data sources. Work closely with engineering and system owners to prioritise and coordinate remediation activities. Write Python, Bash or similar scripts to automate repetitive analysis and operational tasks. Produce clear technical documentation, vulnerability assessments and remediation guidance. Support ongoing improvements to vulnerability management processes.
About you
You'll ideally have experience in a technical security role such as Penetration Testing, Offensive Security, Application Security or Vulnerability Management, together with:
Hands-on experience in penetration testing or offensive security. Good understanding of how vulnerabilities are discovered, exploited and remediated. Strong Linux knowledge and confidence working from the command line. Scripting experience using Python, Bash or similar. Familiarity with CVE, CVSS, NVD and common vulnerability management practices. A methodical approach to analysing technical risk and prioritising remediation. Strong communication skills with the ability to explain technical issues to non-security stakeholders.
Desirable
Experience with one or more of the following would be beneficial:
Vulnerability management platforms (Tenable, Qualys, Rapid7, Microsoft Defender VM or similar). OWASP Top 10. Security automation. Enterprise vulnerability management. Cloud infrastructure security. Relevant certifications such as OSCP, CREST CRT, GPEN or similar Only candidates based in UK and eligible to work in UK are allowed
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!