The role:
Working in the Information Security team you will focus on Vulnerability and Threat Management across the Next technology estate, with a particular focus on our Warehouse environment and the technology utilised within it to help maintain an awareness of new and emerging security threats and trends.
You will be responsible for identifying, assessing, validating and communicating new vulnerabilities across the other technical teams, ensuring the vulnerability management process is followed. Where required you will work with other IT teams to provide guidance and recommend mitigation strategies for vulnerabilities.
As a Senior Vulnerability Management Engineer a knowledge of the MITRE Attack Framework would be advantageous. You will help manage and configure our vulnerability scanning and reporting tools as well as helping administer Next’s Bug Bounty programme.
Where required you will create reporting to summarise findings and recommendations for a variety of audiences. The role also requires you to take a lead in reviewing incoming threat intelligence in order to assess its relevance and severity in context to our business, where appropriate you will provide reports on threats of interest to senior stakeholders and work with the relevant teams to proactively assess, test and mitigate any risk.
You will also be expected to maintain an awareness of the changing threat landscape and industry standards. Proactively work with Incident Response and Engineering to identify tactics and techniques used by threats actors and opportunities to improve the security of our environment. Propose and support implementing suitable countermeasures for threats identified through intelligence, testing and objective validation.
As a Senior Vulnerability Management Engineer you will also help mentor more inexperienced members of the team. You will also take a lead role in coordinating and overseeing efforts to mitigate significant threats or vulnerabilities identified by the team.
The role involves participating in a shift rota.
A monthly visit to the Enderby Head Office in Leicester is required, with additional visits scheduled as needed by the business or management.
What you'll take on:
● Manage and maintain Vulnerability scanning and risk reporting tools.
● Take a lead role in planning in the estimation, scoping and delivery of key projects, ensuring progress is clearly communicated.
● Complete relevant security assessments, including debriefing key stakeholders on any
apparent risks
● Identify, execute and support requirements as part of RvB exercises.
● Ensure all relevant vulnerabilities are correctly triaged, risk assessed, logged and assigned to remediation teams.
● Support remediation teams with remediation strategies.
● Assist Incident Response team with the investigation and resolution of Security Incidents
when required.
● Create and maintain operation procedures, configuration and technical documentation to a
high standard.
● Manage and maintain metrics and reporting to demonstrate the effectiveness of our
vulnerability management programme.
● Subject matter expert for the Vulnerability Management team and helps coordinate efforts
when managing emergency remediation/mitigation.
● Maintain an awareness of new and emerging security threats and trends.
● Test or validate threat intelligence findings against our people, processes and technologies.
● Review threat intelligence and advise on recommended mitigation strategies where
appropriate.
● Act as a mentor for more inexperienced members of the Vulnerability Management team.
What you'll bring:
● Experience managing and maintaining a Vulnerability Management tool.
● In depth understanding of Information Security including malware, emerging threats, attacks and vulnerability management.
● Proven Information Technology experience with an excellent understanding of
network protocols and server infrastructure including network segmentation.
● Windows Server and/or Linux experience.
● Ability to take a lead role in coordinating the timely diagnosis and resolution of major issues.
● Adheres to and promotes high standards.
● Understand and operate change management
● A team player who is hardworking and self-motivated.
● Possess an inquisitive and proactive approach to identifying security gaps.
● Ability to effectively plan and prioritise workloads, and to measure and report on current
progress.
● Ability to remain calm under pressure and clearly communicate to all levels of management.
● Excellent attention to detail.
● Adheres to and promotes high standards.
● Understanding of vulnerability and threat assessment frameworks, such as: CVSS, CVE, CWE,OWASP, MITRE.
● Operational Technology (OT) management experience in vulnerability scanning.
● Competent at keeping up to date on CTI (Cyber Threat Intelligence)
Desirable
● Experience with security or compliance standards such as PCI-DSS or ISO27001.
● Understanding and experience of working for a Retail company.
● Foundational understanding of Cloud based infrastructure
● Relevant industry recognised security qualification
● Understanding of DevOps architecture and code scanning.
● Offensive Security experience
● Experience of SCADA (Supervisory Control and Data Acquisition) systems monitor, Programmable logic controller PLC and control warehouse equipment
● Experience of managing a TIP (Threat Intelligence Platforms)
● Experience of Custom AI usage
- 25% off most NEXT, MADE*, Lipsy*, Gap* and Victoria's Secret* products (*when purchased through NEXT)
- Company performance based bonus
- Sharesave scheme
- On-site Nursery available; OFSTED outstanding in all areas
- 10% off most partner brands & up to 15% off Branded Beauty
- Early VIP access to sale stock
- Access to fantastic discounts at our Staff Shops
- Restaurants with great food at amazing prices
- Access a digital GP and other free health and wellbeing services
- Free on-site parking
- Financial Wellbeing - Save, track and enhance your financial wellbeing
- Apprenticeship - Grow and develop on the job whilst gaining a qualification
- Direct to Work - Discount online and instore, collect your items the next day for free from your place of work or local store
- Support Networks - Access to Network Groups to empower and celebrate each other
- Wellhub - Discounted flexible monthly gym memberships, with apps, PT sessions and more
Skills Required
- Experience managing and maintaining a Vulnerability Management tool
- In-depth understanding of information security including malware, emerging threats and vulnerability management
- Proven IT experience with strong understanding of network protocols, server infrastructure and network segmentation
- Windows Server and/or Linux experience
- Ability to coordinate timely diagnosis and resolution of major security issues
- Understanding and operation of change management processes
- Ability to plan, prioritise workloads and produce metrics/reports on progress
- Calm under pressure with clear communication to all management levels
- Attention to detail and adherence to high standards
- Understanding of vulnerability and threat assessment frameworks: CVSS, CVE, CWE, OWASP
- Operational Technology (OT) vulnerability scanning/management experience
- Competent at keeping up to date on cyber threat intelligence (CTI)
- Knowledge of the MITRE Attack Framework
- Experience with security or compliance standards such as PCI-DSS or ISO27001
- Foundational understanding of cloud-based infrastructure
- Relevant industry recognised security qualification
- Understanding of DevOps architecture and code scanning
- Offensive security experience (e.g., pentesting, red teaming)
- Experience of SCADA systems, PLCs and control/warehouse equipment
- Experience managing a Threat Intelligence Platform (TIP)
- Experience administering a Bug Bounty programme
- Experience or exposure to custom AI usage in security contexts
- Experience working in a retail business (desirable)
What We Do
BD is one of the largest global medical technology companies in the world and is advancing the world of health by improving medical discovery, diagnostics and the delivery of care. The company supports the heroes on the frontlines of health care by developing innovative technology, services and solutions that help advance both clinical therapy for patients and clinical process for health care providers. BD and its 65,000 employees have a passion and commitment to help improve patient outcomes, improve the safety and efficiency of clinicians’ care delivery process, enable laboratory scientists to better diagnose disease and advance researchers’ capabilities to develop the next generation of diagnostics and therapeutics. BD has a presence in virtually every country and partners with organizations around the world to address some of the most challenging global health issues. By working in close collaboration with customers, BD can help enhance outcomes, lower costs, increase efficiencies, improve safety and expand access to health care. In 2017, BD welcomed C. R. Bard and its products into the BD family. For more information on BD, please visit bd.com.
.jpg)
.png)






