Vulnerability Analyst

Cyber Security training courses
London
5 days ago
Create job alert

Location(s): UK, Europe & Africa: UK: London || UK, Europe & Africa: UK: Leeds


BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.


Job Title: Vulnerability Analyst


Requisition ID: 122575


Location: London—We offer a range of hybrid and flexible working arrangements—please speak to your recruiter about the options for this particular role.


Grade: GG10


Referral Bonus: £5,000


SOC Vulnerability Analyst


Role description

To undertake the day‑to‑day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure cloud platforms, with many systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to.


These roles require a minimum of SC clearance. Due to timelines for the start of operations, it will not be possible to sponsor new clearances so candidates must have existing clearances.


Responsibilities

  • Own and manage the Vulnerability Assessment platforms, configuring the toolset for appropriate analysis schedule (with assistance from the SOC Engineering team for underlying hosting/operational support), triage and management of output vulnerability data from both internal scanning and external attack surface management.
  • Gather and maintain a set of VA requirements that define the threats that will be monitored and tracked.
  • Undertake Vulnerability Management, managing the priorities related to the data from Vulnerability Assessment as well as collation and management of wider vulnerability exposure (zero days, environmental (business, operation etc) threats, architectural and legacy threats, etc) to advocate for responsible short and long‑term mitigations that may include patching, IT change and SIEM detection content requirements.
  • Ensure the business is responsive to changing threat profiles and be the voice of operational vulnerability risk mitigation in the prioritisation of SOC resource effort, including reporting/dashboarding as necessary.

Requirements

  • Working in a SOC team developing vulnerability insight for technical and non‑technical audiences.
  • Experience of Microsoft Defender Vulnerability Management and Microsoft Defender External Attack Surface Management highly beneficial.
  • Conducting threat assessments and defining threat intelligence requirements beneficial.
  • Good knowledge of Windows and Linux operating systems and use of the command line.
  • Good knowledge of core networking concepts and technologies e.g. TCP/IP.
  • Some knowledge of malware behaviour and techniques employed by attackers to evade security controls.
  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing).
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Team player and adept at working in multi‑disciplinary and diverse teams.
  • Proven analytical skills capable of solving new and complex technical problems.
  • Excellent written and verbal communication skills with the ability to communicate the impact and importance of detailed technical information to non‑technical and senior audiences.
  • Leading and managing small teams of highly skilled technical people.
  • Managing and building relationships with customer and internal stakeholders.
  • Self‑motivated and motivates others keeping morale and performance high.

Why BAE Systems

This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity, rewards integrity and merit, and where you'll be empowered to fulfil your potential. We welcome candidates from all backgrounds and particularly from sections of the community who are currently underrepresented within our industry, including women, ethnic minorities, people with disabilities and LGBTQ+ individuals.


We also want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.


PLEASE NOTE: You're expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development. We know there may be individual circumstances that impact this, so please discuss this with your line manager or HR Business Partner (HRBP). If you don't feel you can talk to your line manager, you can contact your HRBP.


Should you be invited for interview, you will be giving consent for the Recruitment team to contact you and your line manager regarding your application for this opportunity.


This vacancy is eligible for the UK Employee Referral Scheme. Amount: £5,000.


Life at BAE Systems Digital Intelligence

We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day.


By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well‑being.


Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds – the best and brightest minds – can work together to achieve excellence and realise individual and organisational potential.


Division overview: Government

At BAE Systems Digital Intelligence, we pride ourselves in being a leader in the cyber defence industry, and Government contracts are an area we have many decades of experience in. Government and key infrastructure networks are critical targets to defend as the effects of these networks being breached can be devastating.


As a member of the Government business unit, you will defend the connected world and ensure the protection of nations. We all have a role to play in defending our clients, and this is yours.



#J-18808-Ljbffr

Related Jobs

View all jobs

Vulnerability Analyst

Security Analyst - Dublin

Cyber Assurance Officer

Information Security Analyst - Law Firm

Business Analyst - Operational resilience - Banking

IT Information Security Analyst - Compliance

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

How to Write a Cyber Security Job Ad That Attracts the Right People

Cyber security is now a board-level priority for organisations across the UK. From financial services and healthcare to critical infrastructure, SaaS platforms and the public sector, demand for skilled cyber security professionals continues to grow. Yet despite this demand, many employers struggle to attract the right candidates. Cyber security job adverts often generate large volumes of applications, but few are a genuine match. Meanwhile, experienced security engineers, analysts and architects quietly ignore adverts that feel vague, unrealistic or disconnected from real security work. In most cases, the problem is not a lack of talent — it is the quality of the job advert. Cyber security professionals are trained to assess risk, spot weaknesses and question assumptions. A poorly written job ad signals organisational immaturity and weak security culture. A well-written one signals seriousness, competence and trust. This guide explains how to write a cyber security job ad that attracts the right people, improves applicant quality and positions your organisation as a credible security employer.

Maths for Cyber Security Jobs: The Only Topics You Actually Need (& How to Learn Them)

If you are applying for cyber security jobs in the UK it can feel like “real security people” must be brilliant at maths. The reality is simpler: most roles do not need degree-level pure maths. What they do need is confidence with a small set of practical topics that show up repeatedly in day-to-day work across SOC, incident response, cloud security, AppSec, threat detection, IAM & security engineering. This guide strips the maths down to what actually helps you get hired. It includes a 6-week learning plan plus portfolio projects you can publish to prove the skills. You will focus on: Number systems & bitwise thinking (binary, hex, bytes, XOR) Modular arithmetic basics (enough to understand how modern crypto “works”) Probability & statistics for detection, triage & risk Discrete maths for logic, sets, graphs & complexity Security maths habits: estimation, false positive control & evidence-led reporting You will not waste time on heavy theory that rarely appears in junior or mid-level cyber security roles.

Neurodiversity in Cyber Security Careers: Turning Different Thinking into a Superpower

Cyber security is all about thinking like an attacker, spotting unusual patterns, protecting systems & responding calmly when everything looks like it’s on fire. It’s a discipline built on curiosity, persistence & noticing things other people miss. That’s exactly why it can be such a good fit for many neurodivergent people. If you live with ADHD, autism or dyslexia, you may have been told your brain is “too distracted”, “too literal” or “too disorganised” for a security role. In reality, the traits that can make traditional office work tough often line up beautifully with cyber security work – from hyperfocus in incident response to meticulous analysis in threat hunting. This guide is written for cyber security job seekers in the UK. We’ll look at: What neurodiversity means in a cyber context How ADHD, autism & dyslexia strengths map to different security roles Practical workplace adjustments you can ask for under UK law How to talk about neurodivergence during applications & interviews By the end, you’ll have a clearer sense of where you might thrive in cyber security – & how to turn “different thinking” into a genuine superpower.