Search
Header navigation
Head of Vulnerability Management

Head of Vulnerability Management

remoteHybrid
ExpiresExpires: Expiring in less than 3 weeks
IT
£75,105 - £87,305 per year

Job summary

Please note this role requires DV Clearance

The Government Cyber Unit's mission is to protect public services from cyber threats and digital resilience failures. We are working to achieve a step change in our cyber and digital resilience across government, through delivery of the Government Cyber Action Plan, and working closely with departments and national technical authorities including the National Cyber Security Centre to deliver. This is a challenging time to be working in cyber security and digital resilience, but we have an incredible opportunity to make a difference to people’s lives and promote national security by protecting the public services and national infrastructure they rely on. We work at the forefront of shaping the UK’s national response to emerging cyber and technology issues - from the increasingly complex range of state-sponsored cyber-attacks and supply chain compromises, through to the transformational benefits and security challenges of frontier AI and quantum computing.

We are committed to creating an inclusive and supportive working environment where people can learn, develop and do their best work. Continuous professional development and a focus on wellbeing is core to our unit culture. We welcome applications from candidates who share this ethos and are excited by our mission.

The Government Cyber Coordination Centre (GC3) coordinates the cross-Government response to cyber security vulnerabilities, threats, and incidents, and enables cyber defenders across Government to work together and to “defend as one”. The GC3 is a joint initiative sponsored by the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC). This role is based in DSIT, but you should expect to work closely alongside colleagues from both sponsoring organisations, and wider Government and the public sector.

Job description

Please Note - Former DSIT recruitment campaigns are continuing as usual, but candidates should be aware that following the Government’s announcement on the changes to some civil service departments, roles will be subject to the machinery of government moves and will ultimately be in one of the new departments. We will provide more information if you are selected for a role. This work remains of high importance to the civil service, and we thank you for your continued interest.

We are looking for an experienced vulnerability management professional to set the strategic direction for vulnerability management across government and coordinate action to reduce cyber risk through the effective identification, mitigation and remediation of vulnerabilities. This role reports to the Deputy Director for Government Cyber Operations.

Responsibilities

  • set the strategic direction for vulnerability management across government, leading the government’s approach to identifying, triaging, mitigating, and remediating vulnerabilities across departments
  • work closely with the Government Cyber Unit’s accountability team to establish and operate governance, policy, assurance and risk/performance reporting structures for vulnerability management across government
  • understand and report on government’s aggregate exposure to vulnerabilities, and performance remediating or otherwise mitigating vulnerabilities
  • lead the operation of central vulnerability management services, including the Vulnerability Reporting Service (VRS) and Vulnerability Monitoring Service (VMS), ensuring delivery of a quality service that efficiently and effectively reduces risk at-scale, and driving continuous improvement
  • work closely with the Government Cyber Unit’s Services team to build and continually improve central vulnerability management services, providing SME input and direction for the product roadmap
  • work closely with the GC3 Incident Management function to support the cross-government response to critical vulnerabilities, enabling a rapid understanding of risk, clear communications to decision makers, and a coordinated and informed response across government
  • support teams across DSIT and the NCSC working to reduce vulnerabilities at source, both through improving underlying technology and reducing the attack surface
  • advise ministers, senior officials, and IT and cyber security leadership across government on the risk from vulnerabilities, and the operational response to these
  • engage closely with stakeholders and customers across government, including wider DSIT, the NCSC, and departmental IT and cyber security teams
  • line manage lead analysts in the vulnerability management team, and provide coaching and support to staff across the GC3

The post holder may be required to support out of hours on call rotas for responding to cyber and digital resilience incidents, for which remuneration and/or flexible working arrangements will be available.

Person specification

We’re looking for someone with:

  • significant experience leading vulnerability management in a large, complex organisation, and a deep understanding of vulnerabilities and vulnerability management practices
  • strong leadership skills, with the ability to set strategic direction, lead cross-functional teams, and lead delivery in a complex environment
  • strong stakeholder engagement and influencing skills, with the ability to build trusted relationships, manage competing priorities, and achieve consensus
  • the ability to provide clear and highly credible advice to senior decision makers, including translating complex vulnerability information for a non-technical audience
  • the ability to balance strategic objectives, operational risks, and competing stakeholder requirements

Benefits

There are many benefits of working at DSIT, including:

  • flexible hybrid working with flexi-time and the option to work part-time or condensed hours
  • a Civil Service Pension with an average employer contribution of 28.97%
  • 25 days of annual leave, increasing by a day each year up to a maximum of 30 days
  • an extra day off for the King’s birthday
  • an in-year bonus scheme to recognise high performance
  • career progression and coaching, including a training budget for personal development
  • a focus on wellbeing with access to an employee assistance programme
  • job satisfaction from making government services easier to use and more inclusive for people across the UK
  • advances on pay, including for travel season tickets
  • death in service benefits
  • cycle to work scheme and facilities
  • access to an employee discounts scheme
  • 10 learning days per year
  • volunteering opportunities (5 special leave days per year)
  • access to a suite of learning activities through Civil Service learning


Any move to Government Digital Service from another employer will mean you can no longer access childcare vouchers. This includes moves between government departments. You may however be eligible for other government schemes, including Tax Free Childcare. Determine your eligibility at https://www.childcarechoices.gov.uk

Office attendance
The Department operates a discretionary hybrid working policy, which provides for a combination of working hours from your place of work and from your home in the UK. The current expectation for this role is 60% office attendance.
DSIT does not normally offer full home working (i.e. working at home); but we do offer a variety of flexible working options (including occasionally working from home).

Things you need to know

Artificial intelligence

Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use.

Selection process details

The standard selection process for roles at DSIT consists of:

  • a simple application screening process - We only ask for a CV. Your CV will be assessed against the essential criteria - ignificant experience leading vulnerability management in a large, complex organisation, and a deep understanding of vulnerabilities and vulnerability management practices
  • A 20 minute technical phone screen
  • a 60 minute video interview

While we value the use of AI technology to enhance our daily work, we also value the personal touch and urge applicants to write cover letters without the use of AI to emphasise their own unique experiences.

In the Civil Service, we use Success Profiles to evaluate your skills and ability. This gives us the best possible chance of finding the right person for the job, increases performance and improves diversity and inclusivity. We’ll be assessing your technical abilities, skills, experience and behaviours that are relevant to this role.

For this role we’ll be assessing you against the following Civil Service Behaviours:

  • Leadership
  • Delivering at pace
  • Making effective decisions
  • Communicating and influencing

We’ll also be assessing your experience and specialist technical skills against the following skills defined in the Government Cyber Capability Framework for the Vulnerability Management - Principalrole

  • Cyber security operations (Practitioner)
  • Information risk assessment and risk management (Practitioner)
  • Legal and regulatory environment and compliance (Awareness)

Recruitment Timeline

Sift completion: 6th October 2026

Panel interviews: Starting from 13th October 2026

Candidates that do not pass the interview but have demonstrated an acceptable standard may be considered for similar roles at a lower grade.

A reserve list will be held for a period of 12 months, from which further appointments can be made.

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan and the Civil Service D&I Strategy.

Sponsorship

DSIT cannot offer Visa sponsorship to candidates through this campaign. DSIT holds a Visa sponsorship licence but this can only be used for certain roles and this campaign does not qualify.

Security

Please note, this role requires Developed Vetting level of clearance (DV).

DV isrequired when an individual has long term, frequent and uncontrolled access to ‘Top Secret’ (Information that could directly threaten the national security of the UK, cause long-term damage to our economy or lead to widespread loss of life) information.
To gain DV clearance an applicant will normally need to have been a UK resident for a minimum of 10 years. There are several stages to the vetting process which usually takes 6 month +:-

  • SC Level Clearance
  • Completion of a DV supplementary questionnaire
  • Completion of a financial questionnaire
  • A review of the candidate’s personal finances
  • A medical and psychological assessment
  • Interviews with the candidates referees
  • A detailed interview with the candidate

More information on DV clearance is linked here

Nationality Requirements - Further Information for Candidates

1. This post is classed as ‘Reserved’ as per Civil Service Nationality RulesSection 3. In accordance with these rules, ‘only UK nationals may be employed in reserved posts in the Civil Service’1 (Paragraph. 3.1).

UK National Definition

2. The definition of a ‘UK National’ can be found at Paragraphs. 1.4-1.8 of the Civil Service Nationality Rules.

Dual Nationals

3. As per Paragraph. 1.41 of the Civil Service Nationality Rules:

4. ‘Candidates with dual nationality are in principle eligible for employment in the Civil Service provided that they meet the requirements in relation to one of their nationalities [i.e. UK National]. They may not be eligible, however, for employment in certain reserved posts where additional nationality requirements are imposed.’

Additional Restrictions for Reserved Posts

5. As per Paragraphs. 3.10-3.11 of the Civil Service Nationality Rules:

6. ‘…departments and agencies are entitled to impose additional requirements in reserved posts if this is considered necessary. This could include, for example, requirements as to the residency of the applicant or the nationality of one or both parents of the applicant.’

7. If you are a Dual National who possesses UK Nationality and wish to check your eligibility for the post, please contact our recruiting team at the details below. Please be advised that we will not be able to provide a justification for our decision for security reasons.

8. Irish nationals and Commonwealth citizens are also eligible for employment in reserved posts if they were in the Civil Service at 31 May 1996 or before, or were appointed from a recruitment scheme with a closing date for receipt of applications before 1 June 1996. (Paragraph. 3.1)

Please note offers of employment are subject to achieving satisfactory pre-employment and security checks. These include an Occupational Health Assessment and a Disclosure and Barring Service (DBS). As part of this you will need to confirm your identity, employment/education history, nationality and any criminal record (unspent convictions only).



Feedback will only be provided if you attend an interview or assessment.

Security

Successful candidates must undergo a basic (or equivalent) criminal record check.Successful candidates must meet the security requirements before they can be appointed. The level of security needed is developed vetting (opens in a new window).

See our vetting charter (opens in a new window).People working with government assets must complete baseline personnel security standard (opens in new window) checks.

Nationality requirements

Open to UK nationals only.

Working for the Civil Service

The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants.

We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window).The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria.The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.

Diversity and Inclusion

The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see theCivil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).

Apply and further information

This vacancy is part of the Great Place to Work for Veterans (opens in a new window) initiative.Once this job has closed, the job advert will no longer be available. You may want to save a copy for your records.

Contact point for applicants

Job contact :

Recruitment team

Further information

If you feel your application has not been treated in accordance with the Recruitment Principles and you wish to make a complaint, you should contact gds-complaints@dsit.gov.uk in the first instance.

If you are not satisfied with the response you receive you can contact the Civil Service Commission by email: info@csc.gov.uk Or in writing: Civil Service Commission, Room G/8 1 Horse Guards Road, London, SW1A 2HQ.

Salary range

  • £75,105 - £87,305 per year