Role:
Senior Cyber Exposure & Vulnerability Manager
Location:
Corporate Offices / Hybrid (UK)
Industry:
Financial Services / Insurance (Regulated Environment)
Type:
Full-Time, Permanent
Senior Cyber Exposure & Vulnerability Manager | Hands-On AI & Exposure Leader
- End-to-end operational ownership of enterprise exposure, vulnerability management, and zero-day response capabilities.
- Drive modern risk-based prioritisation and AI-driven automation across cloud, infrastructure, and application estates.
- Key focus: Strategy execution, cross-CIO collaboration, backlog reduction, and executive-level governance.
About the Opportunity
A leading UK financial services organisation is looking for a high-performing Senior Cyber Exposure & Vulnerability Manager
to own and evolve its end-to-end vulnerability management and response framework.
Reporting directly to the Deputy CISO, you will act as the organizational authority on exposure management. In this hands-on, high-impact role, you will bridge the gap between technical risk and business reality—ensuring vulnerabilities across infrastructure, cloud, and applications are identified, prioritised, remediated, and reported in a disciplined, risk-based manner. Additionally, you will champion the practical application of AI and intelligent automation to modernise triage, threat correlation, and remediation workflows.
Key Accountabilities
- End-to-End Vulnerability Ownership: Own the enterprise lifecycle across infrastructure, cloud, apps, and third-party services—covering scanning, triage, risk prioritisation, mitigation, and verification.
- Hands-On Delivery & Response: Manage vulnerability backlogs, ageing, high/critical remediation activity, scan coverage, and emergency response to zero-day exposures.
- AI, Automation & Innovation: Champion the practical use of AI and data-driven insights to optimise triage, reduce false positives, perform root-cause clustering, and automate reporting.
- Cross-CIO Collaboration: Partner with Engineering, Cloud, Data, and Architecture teams to embed vulnerability response into existing delivery pipelines rather than treating it as a parallel task.
- Governance & Executive Reporting: Define and track KPIs/KRIs (SLAs, exposure trends, backlog health) and deliver concise, actionable reporting for CIO leadership, Audit, and CISO/Board forums.
- Risk & Regulatory Support: Align exposure decisions to organizational risk appetite, manage formal risk acceptances, and drive audit and regulatory remediation actions to closure.
Required Skills & Experience
- Enterprise Exposure Experience: Proven track record running vulnerability management and response within complex, highly regulated environments (Financial Services/Insurance preferred).
- Technical Breadth: Strong hands-on understanding of vulnerability management principles, tooling, and remediation across cloud, hybrid infrastructure, applications, and platforms.
- Risk-Based Prioritisation: Expertise in context-aware risk scoring (combining CVSS, threat intelligence, asset criticality, attack surface, and business impact).
- Forward-Looking Mindset: Genuine interest and practical experience in leveraging AI, machine learning, or automated tooling to streamline cyber operations.
- Influence & Stakeholder Management: Ability to translate complex technical vulnerabilities into clear business risk and drive remediation across engineering teams without relying on formal authority.
To Apply
If you are an energetic, delivery-focused vulnerability leader looking to drive modern, AI-enabled exposure management within a fast-paced environment, please submit your CV for immediate consideration.

