We're Recruiting:Operational Security Lead & Cyber Vulnerability Manager
Location: Hybrid - 1 x week in Marlow
Department: Information Security
Monday-Friday
Are you an experienced cyber security professional with a passion for security operations, incident response and vulnerability management?
We're looking for anOperational Security Lead & Cyber Vulnerability Manager to play a critical role in protecting Kensington's technology estate, leading our operational cyber security capability and driving continual improvements to our security posture.
This is an excellent opportunity to join a growing Information Security function, working closely with senior stakeholders across the business to ensure cyber risks are effectively identified, managed and mitigated.
About the RoleReporting to the Chief Information Security Officer, you'll lead the day-to-day operational cyber security function, overseeing security operations, cyber incident management, infrastructure and cloud vulnerability management, and third-party security oversight.
You'll be responsible for ensuring security risks are managed appropriately, coordinating incident response activities, driving remediation programmes and helping strengthen Kensington's overall cyber resilience.
This role combines hands-on security expertise with leadership, governance and stakeholder engagement, making it ideal for someone who enjoys operating at both a strategic and operational level.
Key Responsibilities- Lead the operational cyber security capability across the organisation.
- Manage cyber incidents and coordinate effective response and recovery activities.
- Oversee infrastructure and cloud vulnerability management programmes.
- Drive continuous reduction in cyber risk exposure.
- Lead security monitoring, threat intelligence and threat management activities.
- Manage third-party security incidents and supplier security risks.
- Support compliance testing and security assurance activities.
- Oversee security governance, service requests and operational controls.
- Lead phishing simulations and security awareness initiatives.
- Support firewall, network and security configuration reviews.
What We're Looking ForYou'll have a strong background in cyber security operations and be comfortable operating within a fast-paced, highly regulated environment.
Essential Experience- Cyber Security Operations and Cyber Defence.
- Vulnerability Management and remediation.
- Security Incident Response and Major Incident Management.
- Security Monitoring and SIEM platforms.
- Threat Intelligence.
- Cloud Security, ideally Azure.
- Data Loss Prevention (DLP).
- Network Security.
- Security Governance and Risk Management.
- Working within regulated environments.
Technical KnowledgeYou'll ideally have experience with:
- Vulnerability scanning and reporting tools.
- Security testing methodologies.
- Network architecture and infrastructure technologies.
- Security compliance frameworks, including NIST.
- Threat actor tactics and attack techniques.
- Security assurance and compliance reviews.
- Infrastructure and cloud security controls.
Skills & BehavioursWe're looking for someone who can:
- Make informed decisions during security incidents and risk events.
- Prioritise effectively in high-pressure environments.
- Build strong relationships across technical and non-technical teams.
- Communicate complex cyber security concepts clearly to senior stakeholders.
- Influence, challenge and drive positive security outcomes.
- Lead teams and support the development of others.
- Maintain a strong governance and control mindset.
QualificationsEssential- Degree qualified or equivalent experience in Cyber Security, Information Security, Computer Science or a related discipline.
Desirable- CISSP
- CISM
- Vulnerability Management certifications
- Incident Response certifications
Why Join Kensington?At Kensington, you'll have the opportunity to influence and develop our cyber security capability while working with modern technologies and security frameworks. You'll play a key role in protecting the organisation, shaping security strategy and helping us build a resilient and secure operating environment.