Vulnerability Management Analyst
Inspired Thinking Group (ITG)
| Company | Inspired Thinking Group (ITG) |
| Category | Security |
| Location | Birmingham |
| Remote | On-site (inferred) |
| Employment | Full-time |
| Level | Mid |
| Salary | Not stated by the employer |
| Posted | 24 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (workable) |
Description
We are looking for an enthusiastic and detail-oriented Vulnerability Management Analyst to join our information security and data protection team. This is an ideal opportunity for someone with real-world experience in information security and data protection. It's a great opportunity to get hands-on with the tools and processes that keep all our products secure, and to make a genuinely visible difference to how we manage risk day to day. The Role: The Vulnerability Management Analyst will help us find, prioritise, and fix security vulnerabilities across our global business and all our products. You’ll configure and tune our vulnerability tools, risk assessing detections, and prioritising findings for fix. You’ll cover code vulnerabilities (SAST, DAST, SCA, OSS licencing), Cloud Security Posture Management (CSPM), Internal Vulnerability Scanning (IVS), and penetration testing. You'll also help design and report on our detection and remediation activities. This is a full-time position. Occasional after-hours work may be required for incident response or urgent security tasks. Successful candidates will be enrolled on a fully funded training pathway and will be provided with mentoring support to help them grow and learn. Responsibilities: 1. Configuring and tuning our tools Help configure, tune, and maintain our vulnerability tooling across scanning tools, working with platform and engineering teams to keep coverage accurate Support day-to-day scanning schedules and tooling integrations, including ticketing and CI/CD pipelines Look for opportunities to automate reporting, validation, and other repetitive tasks across the whole vulnerability lifecycle 2. Triage and risk assessment Triage findings from vulnerability sources, confirming genuine issues and filtering out false positives Risk-assess confirmed findings against severity, exploitability, and business context, to prioritise fixes Apply a consistent risk-scoring approach so findings are prioritised effectively, regardless of source Stay on top of current threats and trends (e.g. threat actors, new vulnerabilities etc.) to inform vulnerability management activities 3. Designing secure benchmarks and guidelines Develop and maintain secure configuration benchmarks and hardening guidelines for our software, infrastructure, and tooling Align benchmarks and guidelines to recognised industry frameworks for business Work with the right teams to help implement the secure configurations, providing practical advice, and facilitating deviations within our broader risk management framework 4. Working with Developers and Engineers Act as a primary contact point for Developers and Engineers to help them understand and fix issues Track remediation progress, chase owners on overdue items, escalate where necessary Support teams with practical remediation guidance, drawing on the OWASP Top 10, the Mitre Att&ck Framework, and our secure coding standards 5. Coordinating IVS, web application testing, and penetration testing Organise our externally delivered IVS and Penetration Testing programmes, from scheduling and scoping, through to day-to-day contact with our testing partners Help manage our relationships with testing providers, including engagement administration and reporting 6. SLAs, outcome driven metrics, and reporting Help design and report on remediation SLAs across vulnerability classes, severities, and products Produce regular reporting (monthly, quarterly, and ad-hoc) on SLA performance, open findings, and trends Feed data and insight into our wider security metrics and reporting processes 7. Continuous improvement and team support Suggest ways to improve how we manage vulnerabilities and the tools we use to do it Support the rollout of new scanning tools or process changes across our global product estate Help create and maintain our vulnerability management policies, standards, and procedures Requireme