Vulnerability Management Modernisation Lead at Bermuda Commercial Bank, UK Remote, £Contractor Rate

Contract Description

Vulnerability Management Modernisation Lead

Location

United Kingdom (Remote)


Department

Technology


Employment Type

Contractor

Role Purpose
BCB is seeking a contractor to lead the establishment of a permanently owned Vulnerability Management capability. This role is the single accountable owner of vulnerability management. The successful candidate will design, stand up and run the business-as-usual (BAU) capability that prevents new technology debt from accumulating, and will define the operating relationship with the MSP and internal teams.

 

Key Accountabilities and Responsibilities

  • Own the vulnerability management discipline end to end: policy, standards, process, cadence, exceptions and risk acceptance recommendations.
  • Define and implement the target BAU operating model, including the responsibility split between the Bank and the MSP, and the closed-loop process in which patch deployment is independently verified by scanning.
  • Direct the extension of authenticated scanning across the estate (including non-Windows assets and network devices), challenge and track MSP delivery plans and prerequisites, and drive scan coverage and depth to a defensible standard.
  • Lead application estate rationalisation: establish the required application set, identify decommissioning candidates, and eliminate unjustified variants (for example, standardising the browser estate on an auto-updating standard).
  • Select, scope and implement a third-party patching solution sized to the rationalised estate, and set differentiated patching policies by asset class (automatic updates for high-exposure commodity software; structured, vendor-engaged upgrade cycles for core platforms).
  • Provide the technical substance for renegotiation of the MSP contract: patching remit, service levels, cadence, reporting, named owners and milestone dates.
  • Define and report the measures of a functioning capability: mean time to remediate by severity, patch deployment rates, scan coverage and authentication depth, and validated closure rates. Contribute to a single consolidated remediation view for board reporting.
  • Act as the receiving owner for workstreams completed by the technology debt remediation programme, ensuring each is sustained under BAU process rather than allowed to re-accumulate.

 

Experience, Skills & Attributes

  • Demonstrable experience establishing or running a vulnerability management function, ideally in a regulated financial services environment.
  • Deep practical knowledge of vulnerability scanning platforms, including the material difference between authenticated and unauthenticated scanning and the operational prerequisites of each (credentials, PAM integration, scan job configuration).
  • Hands-on experience with enterprise patch management tooling for both first-party and third-party software, including tool selection and implementation.
  • The technical judgement to distinguish genuine risk from scanner noise, and to apply a differentiated risk calculus across asset classes.
  • Experience of estate rationalisation and decommissioning as a remediation strategy — the instinct to ask “what can we switch off?” before “what can we patch?”.
  • Track record of holding third-party suppliers to account: defining remits, SLAs, cadences and delivery plans, and challenging dates that lack supporting plans.
  • Ability to communicate exposure, progress and trade-offs credibly to senior and board-level audiences, including pre-briefing counterintuitive movements in reported numbers.

 

Would be an asset to have…

  • Experience of core banking platform upgrade and remediation cycles, and of building rolling vendor-engaged upgrade models.
  • Familiarity with secure configuration review and penetration testing and integrating their findings into a single remediation backlog.
  • Experience operating alongside, and handing off to or from, a formal remediation programme.