This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Security Incident & Vulnerability Management Consultant operates within the Operational Integrator (OI) function to support the transition to a multi-supplier (SIAM) model within a Defence environment. The role focuses on understanding, aligning and governing existing high-severity security incident management (S3/S4) and vulnerability management processes across suppliers. Ensuring a consistent, risk-based approach in line with client policy and regulatory requirements, supported by appropriate evidence. The outcome is a coherent, evidence-driven view of security risk, covering both active incidents and underlying vulnerabilities, with processes standardised and ready for BAU handover. This is a governance and coordination role, not a hands-on SOC, incident response, or vulnerability remediation function.
Job Responsibility
Governance & Process Alignment
Review and align existing supplier processes for high-severity incident management (S3/S4) and vulnerability management
Ensure processes are consistent across suppliers and aligned to client policy and regulatory requirements
Establish and govern incident severity classification, escalation thresholds, vulnerability prioritisation approaches
Coordinate multiple suppliers to ensure consistent handling of incidents and vulnerabilities
Act as integration point across suppliers
Identify and manage gaps in process maturity, coverage, data quality and compliance
Govern lifecycle of high-severity incidents
Ensure suppliers detect, escalate, and maintain structured incident records
Oversee vulnerability lifecycle
Validate remediation timelines and SLA adherence
Define evidence requirements for incident and vulnerability management
Support domain-specific reporting and governance forums
Establish transition baseline for BAU handover
Requirements
Experience in security incident management, vulnerability management, or cyber governance roles
Strong understanding of incident management lifecycle (detect, respond, recover)
Strong understanding of vulnerability lifecycle (identify, prioritise, remediate, validate)
Experience working in multi-supplier or SIAM environments
Ability to interpret outputs from SOC and vulnerability tooling without direct ownership
Nice to have
Familiarity with NIST CSF, NCSC or UK Government security guidance
Experience in Defence sector or highly regulated environments