Job Description:
Job Title: Security Vulnerability Lead
Location: Hybrid London or Newcastle, UK
DXC’sInsurance Software and BPSbusiness provides a range of software and services to the global insurance market including life, wealth, health, commercial and speciality, property and casualty, and reinsurance. DXC is also a key partner of the London Market, providing digital transformation and outsourcing services.
DXC’s insurance business has 13,000 domain experts serving 2,000 insurance customers operating in over 100 countries worldwide.
Role Overview
This is a dedicated account-level role responsible for leading vulnerability management across both heritage and digital IT estates within the London Markets account. The successful candidate will be tasked with rebuilding the vulnerability management program from the ground up, ensuring robust coverage, effective remediation coordination, and continuous improvement.
Key Responsibilities
Strategic Leadership
1. Refresh and redesign the vulnerability management framework for the account.
2. Define success criteria and establish KPIs for vulnerability management effectiveness.
3. Lead continual improvement initiatives and manage the program roadmap.
Operational Oversight
4. Oversee vulnerability identification, assessment, and reporting across the estate.
5. Ensure vulnerability scanning tools are properly configured, integrated, and provide adequate coverage.
6. Maintain and publish regular reports on vulnerability status, trends, and aged backlog.
Remediation Coordination
7. Collaborate closely with the Remediation Manager to drive timely resolution of vulnerabilities.
8. Address aged vulnerabilities and align remediation efforts with business priorities.
9. Review vulnerabilities accepted as risk and re-evaluate remediation opportunities.
Governance and Compliance
10. Develop and maintain vulnerability management policies, standards, and procedures.
11. Support internal and external audits with documentation and evidence.
12. Ensure alignment with regulatory requirements and industry best practices.
Stakeholder Engagement
13. Act as the central point of contact for vulnerability-related issues.
14. Educate stakeholders on risks, remediation strategies, and tool usage.
15. Provide executive-level summaries and technical reports to leadership.
Key Challenges
16. Establishing a baseline for tool functionality and coverage across legacy and modern platforms.
17. Producing a clear management view of vulnerabilities by component (OS, DB, middleware, etc.).
18. Coordinating across delivery teams and technical owners to ensure accountability and progress.
19. Implementing a vulnerability matrix to track patching schedules, ownership, and compliance.
Educational & Professional Requirements
20. Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
21. Preferred: Master’s degree or relevant certifications (e.g., CISSP, CISM, CRISC, GIAC).
22. Experience in vulnerability management or related security domains.
23. Proven experience managing teams and driving security improvement programs.
Desirable Skills
24. Strong understanding of vulnerability scanning tools (e.g., Qualys, Prisma Cloud, AWS GuardDuty).
25. Familiarity with patch management processes and SLAs.
26. Excellent communication and stakeholder management skills.
27. Analytical mindset with ability to prioritize risks and align with business impact.
What we can offer you:
28. Competitive Compensation & Pension Scheme – Rewarding your expertise while securing your future.
29. Comprehensive Benefits Package – Including DXC Select, Perks at Work, and incentive programs for exclusive savings and rewards.
30. Continuous Learning & Development – Access to upskilling opportunities, career growth resources, and industry-leading training.
31. Lifestyle Perks – Enjoy options like the Salary Sacrifice Car Scheme and more.
At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.