Threat & Vulnerability Manager (FTC)

Posted 3 Days Ago
Be an Early Applicant
London, Greater London, England, GBR
Hybrid
60K-65K Annually
Entry level
Digital Media • Marketing Tech
The Role
Own enterprise threat and vulnerability management, including vulnerability scanning, penetration testing, remediation, patching, risk prioritization, metrics, tooling integrations, and process improvement. Support broader security operations through threat monitoring, security control reviews, SIEM activities, incident response, endpoint and network protection, and security initiatives. Collaborate with infrastructure, application, external, and business stakeholders to improve organizational security posture.
Summary Generated by Built In
Job Description

We have a new opportunity for an experienced Threat and Vulnerability Manager to join our Technology team here at Penguin on a 7-month fixed-term contract to cover a period of parental leave. This role is offered with hybrid working from our office in Embassy Gardens, London. 

 

As Threat and Vulnerability Manager, you'll take ownership of our threat and vulnerability management capabilities, leading the identification, assessment and remediation of vulnerabilities across the business. Alongside this, you'll play a hands-on part in our wider security operations: supporting the security controls that protect our technical environment, monitoring internal and external cyber threats, and responding quickly to information security incidents. 

 

Supporting the Head of Security Operations, you'll help maintain and continually improve our cyber security attack surface, driving prompt and effective remediation and working with stakeholders across the business to strengthen our overall security posture. 

 

This is an important role in reducing our exposure to cyber security threats and helping to protect the resilience of our systems and services. 

 

About the team 

 

The Technology team provides expertise and effective solutions to Penguin Random House. We integrate flexibility and agility which supports our consistent way of working. We set ourselves up for success by holding ourselves accountable and welcoming change. Each member of the Technology team brings skill and initiative to their role; we take personal ownership within a one team culture, working collaboratively to meet expectations from our stakeholders who trust us to deliver. 

 

Key responsibilities: 

Threat and vulnerability management 

  • Responsible for ensuring that vulnerability detection and remediation controls and platforms are properly configured and operating effectively. 

  • Responsible for promptly assessing new or emerging vulnerabilities and leading internal efforts to resolve or mitigate as appropriate to the severity level, including guidance and recommendations on emergency patching based on appropriate threat assessments. 

  • As a subject matter expert, has product ownership for enterprise VM tooling in collaboration with our infrastructure and security architects. 

  • Coordinating vulnerability scanning and penetration testing, and managing the technical remediation of their findings. 

  • Plays a leadership role in the team to proactively challenge and drive incremental and continuous improvements in end-to-end vulnerability management processes, i.e. scopes, prioritises and leads service improvement initiatives for vulnerability management platforms and management processes. 

  • Provide leadership and direction to the PRH community on all aspects of vulnerability management and mitigation across user endpoints, servers, networks and applications. 

  • Continually improving PRH's security posture through collaborative and successful vulnerability remediation efforts with internal and external teams responsible for infrastructure and applications. 

  • Producing ad hoc, weekly and monthly metrics and KPIs evidencing vulnerability analysis, and reduction or mitigation of vulnerability risk. 

  • Chairing Patching and Vulnerability Management forums. 

  • Responsible for assurance of all BAU vulnerability management processes managed by PRH Security Operations or by our nominated MSSPs. 

  • Will drive technical integrations between VM platforms to leverage automation and threat/vulnerability intelligence. 

 

Security operations 

  • Monitoring internal and external cyber threats and ensuring our technical controls stay aligned to them. 

  • Supporting the operation of key security controls, including endpoint protection (anti-virus, encryption, mobile device management and network access control), DDoS protection, web security and email security (including phishing simulation). 

  • Supporting security incident and event management, including log reviews, identifying critical events and creating alerts. 

  • Rapid response, detection, isolation and remediation of information security incidents, and reporting to management on incidents and incident prevention activities. 

  • Conducting periodic reviews of security technology for adherence to policy, such as firewall policy, email allow-list and anti-virus exception reviews, and ensuring audit trails and system logs are reviewed in line with policy and audit requirements. 

  • Supporting the delivery of ongoing security initiatives and projects. 

 

What you'll bring 

 

Essential criteria: 

 

  • Demonstrable experience of using VM tooling at an enterprise level and supporting or leading enterprise VM programmes. 

  • Previous experience of patch management processes. 

  • Ability to demonstrate broad and deep vulnerability knowledge and experience across various domains including Infrastructure, Cloud, Applications and Networks. 

  • A good understanding of threats and threat vectors, and hands-on experience of information security incident handling. 

  • Ability to build and maintain collaborative relationships with various stakeholder groups, and to be an advocate for informed, risk-based vulnerability management. 

  • Good understanding of Web Application Security frameworks, common vulnerabilities and associated remediations. 

  • Excellent verbal and written communication skills, with the ability to explain the business impact of security risks, tools and policies to technical teams, management and business colleagues. 

  • Ability to work under pressure, with proven problem-solving and decision-making experience. 

 

Desirable criteria: 

 

  • Technical accreditations such as CISSP, SANS or other relevant security credentials. 

  • Ability to use scripting languages such as Python, Perl, PowerShell etc. 

  • Working knowledge of Open-Source Threat Intelligence capabilities. 

  • Experience of working with teams in an Agile environment. 

 

Application instructions 

 

Please apply with your CV by 23:59 on Wednesday 7th October 2026. Applications will be reviewed on a rolling basis and the advert may close at any time. We would encourage you to apply as soon as possible. 

 

AI 

 

Here at Penguin, we believe in the power of authenticity and human creativity. When you apply for a position, we want to encourage you to showcase your unique voice. Throughout our recruitment process, please share your own thoughts, experiences, and skills. This helps us get a true sense of who you are and what you might bring to our team. 

 

We celebrate creativity and diverse perspectives, so please be yourself! While we recognise AI tools can be helpful, we recommend using them thoughtfully to ensure your responses reflect you. 

 

Disability Confident 

 

As a Disability Confident Committed organisation, we offer interviews to candidates with a disability who meet the essential criteria for the role, and opt-in on their application form. The essential criteria for this role are listed as part of the 'What you'll bring' section. 

 

There may be times when the volume of applications means we cannot take all eligible candidates to interview. We encourage you to tell us about any reasonable adjustments you may need by emailing [email protected](opens in new window). Remember, you only need to share what you are comfortable with, for us to support your request. 

 

Salary 

 

The salary for this opportunity is £60,000-£65,000 depending on how your skills and experience align to the role, plus a generous bonus scheme and benefits. 

 

Hybrid working 

 

While our offices across the UK are places to connect, collaborate and celebrate with colleagues, we recognise that flexibility around where you work is just as important. 

 

For this role we expect that you will work from our head office in Embassy Gardens, London a minimum of 2 days per week (Tuesday & Thursday) with additional days for team meetings, townhalls etc. as required. There may also be occasional travel to our warehouse site in Frating, Colchester. 

Additional Information

 

 

Disclosure requirements pertaining to the collection of your personal data:

Responsible for processing the information provided in your application is the company specified in the job advertisement, with its registered office as indicated. The company processes your data for the purpose of establishing an employment relationship on the basis of Art. 6 (1) b GDPR / Section 26 (1) sentence 1 BDSG.

The retention period for your data is determined by the statutory time limits applicable in the respective country, beginning upon completion of the recruitment process. You can find these here.

You can contact the company’s Data Protection Officer at the above-mentioned postal address. 

Further information on data protection and your rights can be found here.
 

Recruiting-Platform powered by SmartRecruiters.

Skills Required

  • Enterprise-level experience using vulnerability management tooling and supporting or leading enterprise vulnerability management programs
  • Experience with patch management processes
  • Broad and deep vulnerability knowledge across infrastructure, cloud, applications, and networks
  • Understanding of threats and threat vectors, with hands-on information security incident handling experience
  • Ability to build collaborative stakeholder relationships and advocate for risk-based vulnerability management
  • Understanding of web application security frameworks, common vulnerabilities, and remediations
  • Excellent verbal and written communication skills, including explaining security risks to technical and business audiences
  • Problem-solving and decision-making experience, including the ability to work under pressure
  • Technical accreditations such as CISSP, SANS, or other relevant security credentials
  • Ability to use scripting languages such as Python, Perl, or PowerShell
  • Working knowledge of open-source threat intelligence capabilities
  • Experience working with teams in an Agile environment
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Gütersloh
16,426 Employees

What We Do

Bertelsmann is a media, services and education company that operates in about 50 countries around the world. It includes the entertainment group RTL Group, the trade book publisher Penguin Random House, the music company BMG, the service provider Arvato Group, Bertelsmann Marketing Services, the Bertelsmann Education Group and Bertelsmann Investments, an international network of funds. The company has 165,000 employees worldwide and generated revenues of €20.2 billion in the 2022 financial year. Bertelsmann stands for creativity and entrepreneurship. This combination promotes first-class media content and innovative service solutions that inspire customers around the world. Bertelsmann aspires to achieve climate neutrality by 2030.

Similar Jobs

SharkNinja Logo SharkNinja

Engineering Director - NPD

Beauty • Robotics • Design • Appliances • Manufacturing
In-Office
London, Greater London, England, GBR
4000 Employees

Samsara Logo Samsara

Account Executive

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
London, Greater London, England, GBR
4000 Employees
10K-150K Annually

Pfizer Logo Pfizer

Clinical Development Medical Director (MD required)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
3 Locations
121990 Employees
240K-400K Annually

UL Solutions Logo UL Solutions

Associate People Operations Partner

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
Basingstoke, Hampshire, England, GBR
15000 Employees

Similar Companies Hiring

MFour Data Research Thumbnail
Marketing Tech • Software
Irvine, CA
98 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account