Threat & Vulnerability Manager (FTC)
- Vulnerability Management
- Penetration Testing
- CISSP
- Python
- Perl
- PowerShell
- Threat Intelligence
- Agile
- AI
- GDPR
We have a new opportunity for an experienced Threat and Vulnerability Manager to join our Technology team here at Penguin on a 7-month fixed-term contract to cover a period of parental leave. This role is offered with hybrid working from our office in Embassy Gardens, London.
As Threat and Vulnerability Manager, you'll take ownership of our threat and vulnerability management capabilities, leading the identification, assessment and remediation of vulnerabilities across the business. Alongside this, you'll play a hands-on part in our wider security operations: supporting the security controls that protect our technical environment, monitoring internal and external cyber threats, and responding quickly to information security incidents.
Supporting the Head of Security Operations, you'll help maintain and continually improve our cyber security attack surface, driving prompt and effective remediation and working with stakeholders across the business to strengthen our overall security posture.
This is an important role in reducing our exposure to cyber security threats and helping to protect the resilience of our systems and services.
About the team
The Technology team provides expertise and effective solutions to Penguin Random House. We integrate flexibility and agility which supports our consistent way of working. We set ourselves up for success by holding ourselves accountable and welcoming change. Each member of the Technology team brings skill and initiative to their role; we take personal ownership within a one team culture, working collaboratively to meet expectations from our stakeholders who trust us to deliver.
Key responsibilities:
Threat and vulnerability management
Responsible for ensuring that vulnerability detection and remediation controls and platforms are properly configured and operating effectively.
Responsible for promptly assessing new or emerging vulnerabilities and leading internal efforts to resolve or mitigate as appropriate to the severity level, including guidance and recommendations on emergency patching based on appropriate threat assessments.
As a subject matter expert, has product ownership for enterprise VM tooling in collaboration with our infrastructure and security architects.
Coordinating vulnerability scanning and penetration testing, and managing the technical remediation of their findings.
Plays a leadership role in the team to proactively challenge and drive incremental and continuous improvements in end-to-end vulnerability management processes, i.e. scopes, prioritises and leads service improvement initiatives for vulnerability management platforms and management processes.
Provide leadership and direction to the PRH community on all aspects of vulnerability management and mitigation across user endpoints, servers, networks and applications.
Continually improving PRH's security posture through collaborative and successful vulnerability remediation efforts with internal and external teams responsible for infrastructure and applications.
Producing ad hoc, weekly and monthly metrics and KPIs evidencing vulnerability analysis, and reduction or mitigation of vulnerability risk.
Chairing Patching and Vulnerability Management forums.
Responsible for assurance of all BAU vulnerability management processes managed by PRH Security Operations or by our nominated MSSPs.
Will drive technical integrations between VM platforms to leverage automation and threat/vulnerability intelligence.
Security operations
Monitoring internal and external cyber threats and ensuring our technical controls stay aligned to them.
Supporting the operation of key security controls, including endpoint protection (anti-virus, encryption, mobile device management and network access control), DDoS protection, web security and email security (including phishing simulation).
Supporting security incident and event management, including log reviews, identifying critical events and creating alerts.
Rapid response, detection, isolation and remediation of information security incidents, and reporting to management on incidents and incident prevention activities.
Conducting periodic reviews of security technology for adherence to policy, such as firewall policy, email allow-list and anti-virus exception reviews, and ensuring audit trails and system logs are reviewed in line with policy and audit requirements.
Supporting the delivery of ongoing security initiatives and projects.
What you'll bring
Essential criteria:
Demonstrable experience of using VM tooling at an enterprise level and supporting or leading enterprise VM programmes.
Previous experience of patch management processes.
Ability to demonstrate broad and deep vulnerability knowledge and experience across various domains including Infrastructure, Cloud, Applications and Networks.
A good understanding of threats and threat vectors, and hands-on experience of information security incident handling.
Ability to build and maintain collaborative relationships with various stakeholder groups, and to be an advocate for informed, risk-based vulnerability management.
Good understanding of Web Application Security frameworks, common vulnerabilities and associated remediations.
Excellent verbal and written communication skills, with the ability to explain the business impact of security risks, tools and policies to technical teams, management and business colleagues.
Ability to work under pressure, with proven problem-solving and decision-making experience.
Desirable criteria:
Technical accreditations such as CISSP, SANS or other relevant security credentials.
Ability to use scripting languages such as Python, Perl, PowerShell etc.
Working knowledge of Open-Source Threat Intelligence capabilities.
Experience of working with teams in an Agile environment.
Application instructions
Please apply with your CV by 23:59 on Wednesday 7th October 2026. Applications will be reviewed on a rolling basis and the advert may close at any time. We would encourage you to apply as soon as possible.
AI
Here at Penguin, we believe in the power of authenticity and human creativity. When you apply for a position, we want to encourage you to showcase your unique voice. Throughout our recruitment process, please share your own thoughts, experiences, and skills. This helps us get a true sense of who you are and what you might bring to our team.
We celebrate creativity and diverse perspectives, so please be yourself! While we recognise AI tools can be helpful, we recommend using them thoughtfully to ensure your responses reflect you.
Disability Confident
As a Disability Confident Committed organisation, we offer interviews to candidates with a disability who meet the essential criteria for the role, and opt-in on their application form. The essential criteria for this role are listed as part of the 'What you'll bring' section.
There may be times when the volume of applications means we cannot take all eligible candidates to interview. We encourage you to tell us about any reasonable adjustments you may need by emailing PRHCareersUK@penguinrandomhouse.co.uk(opens in new window). Remember, you only need to share what you are comfortable with, for us to support your request.
Salary
The salary for this opportunity is £60,000-£65,000 depending on how your skills and experience align to the role, plus a generous bonus scheme and benefits.
Hybrid working
While our offices across the UK are places to connect, collaborate and celebrate with colleagues, we recognise that flexibility around where you work is just as important.
For this role we expect that you will work from our head office in Embassy Gardens, London a minimum of 2 days per week (Tuesday & Thursday) with additional days for team meetings, townhalls etc. as required. There may also be occasional travel to our warehouse site in Frating, Colchester.
Disclosure requirements pertaining to the collection of your personal data:
Responsible for processing the information provided in your application is the company specified in the job advertisement, with its registered office as indicated. The company processes your data for the purpose of establishing an employment relationship on the basis of Art. 6 (1) b GDPR / Section 26 (1) sentence 1 BDSG.
The retention period for your data is determined by the statutory time limits applicable in the respective country, beginning upon completion of the recruitment process. You can find thesehere.
You can contact the company’s Data Protection Officer at the above-mentioned postal address.
Further information on data protection and your rights can be foundhere.
Recruiting-Platform powered by SmartRecruiters.
Threat & Vulnerability Manager (FTC) · Bertelsmann-Jobs