Vulnerability Management Modernisation Lead
Role Purpose
BCB is seeking a contractor to lead the establishment of a permanently owned Vulnerability Management capability. This role is the single accountable owner of vulnerability management. The successful candidate will design, stand up and run the business-as-usual (BAU) capability that prevents new technology debt from accumulating, and will define the operating relationship with the MSP and internal teams.
Key Accountabilities and Responsibilities
- Own the vulnerability management discipline end to end: policy, standards, process, cadence, exceptions and risk acceptance recommendations.
- Define and implement the target BAU operating model, including the responsibility split between the Bank and the MSP, and the closed-loop process in which patch deployment is independently verified by scanning.
- Direct the extension of authenticated scanning across the estate (including non-Windows assets and network devices), challenge and track MSP delivery plans and prerequisites, and drive scan coverage and depth to a defensible standard.
- Lead application estate rationalisation: establish the required application set, identify decommissioning candidates, and eliminate unjustified variants (for example, standardising the browser estate on an auto-updating standard).
- Select, scope and implement a third-party patching solution sized to the rationalised estate, and set differentiated patching policies by asset class (automatic updates for high-exposure commodity software; structured, vendor-engaged upgrade cycles for core platforms).
- Provide the technical substance for renegotiation of the MSP contract: patching remit, service levels, cadence, reporting, named owners and milestone dates.
- Define and report the measures of a functioning capability: mean time to remediate by severity, patch deployment rates, scan coverage and authentication depth, and validated closure rates. Contribute to a single consolidated remediation view for board reporting.
- Act as the receiving owner for workstreams completed by the technology debt remediation programme, ensuring each is sustained under BAU process rather than allowed to re-accumulate.
Experience, Skills & Attributes
- Demonstrable experience establishing or running a vulnerability management function, ideally in a regulated financial services environment.
- Deep practical knowledge of vulnerability scanning platforms, including the material difference between authenticated and unauthenticated scanning and the operational prerequisites of each (credentials, PAM integration, scan job configuration).
- Hands-on experience with enterprise patch management tooling for both first-party and third-party software, including tool selection and implementation.
- The technical judgement to distinguish genuine risk from scanner noise, and to apply a differentiated risk calculus across asset classes.
- Experience of estate rationalisation and decommissioning as a remediation strategy — the instinct to ask “what can we switch off?” before “what can we patch?”.
- Track record of holding third-party suppliers to account: defining remits, SLAs, cadences and delivery plans, and challenging dates that lack supporting plans.
- Ability to communicate exposure, progress and trade-offs credibly to senior and board-level audiences, including pre-briefing counterintuitive movements in reported numbers.
Would be an asset to have…
- Experience of core banking platform upgrade and remediation cycles, and of building rolling vendor-engaged upgrade models.
- Familiarity with secure configuration review and penetration testing and integrating their findings into a single remediation backlog.
- Experience operating alongside, and handing off to or from, a formal remediation programme.