Senior Vulnerability Management Specialist
Application Security | DevSecOps | Snyk | Automation
We are seeking an experienced Senior Vulnerability Management Specialist to design, own, and continuously improve our application vulnerability management programme.
You'll be responsible for driving vulnerability remediation across development and DevOps teams, ensuring security risks are prioritised, tracked, remediated, and reported through a scalable and automated process.
Key Responsibilities
- Own the end-to-end application vulnerability management lifecycle.
- Triage and prioritise vulnerabilities using risk-based methodologies including CVSS, EPSS, exploitability, business criticality, and data sensitivity.
- Manage findings from SAST, DAST and SCA security tooling, with a strong focus on application security.
- Drive remediation activities with engineering, DevOps, and application owner communities.
- Create and manage Jira workflows, tickets, SLAs, escalations, and exception processes.
- Verify remediation through rescanning and reporting.
- Develop automation for vulnerability tracking, ownership assignment, notifications, reporting, and governance.
- Produce management dashboards and security risk reporting.
- Continually improve vulnerability coverage, remediation efficiency, and developer engagement.
Required Experience
- 5+ years' experience in Vulnerability Management, Application Security, DevSecOps, or a related security discipline.
- Strong experience operating enterprise-scale application vulnerability management programmes.
- Experience working with Snyk or equivalent application security platforms.
- Strong understanding of secure software development, CI/CD pipelines, and modern DevSecOps practices.
- Experience working closely with software engineering and DevOps teams to drive remediation.
- Hands-on experience with Jira workflow design and automation.
- Ability to communicate technical risks clearly to both technical and non-technical stakeholders.
Desirable Skills
- GitLab, GitHub, Azure DevOps, or Bitbucket.
- OWASP Top 10, CVE, CVSS, CWE, and EPSS.
- AWS and Infrastructure-as-Code automation (Terraform).
- Experience in regulated environments such as ISO 27001 or NIS2.
Ideal Candidate
A senior security professional with a blend of Application Security, Vulnerability Management, DevSecOps, stakeholder engagement, and automation expertise. You'll be comfortable influencing engineers and application owners, driving remediation without direct authority, and building a scalable, risk-driven security programme that supports modern software delivery