The role
This is a strategic, not operational, vulnerability management hire.
The fundamentals - noise reduction, stakeholder relationships, patch cadence - are already in place.
What's needed now is someone to redesign the strategy for an AI-driven threat landscape, where attackers chain together low, medium, high, and critical vulnerabilities into viable attack vectors, fundamentally changing how prioritisation should work.
What you'll do
- Review current tooling, process, and posture
- Design a strategy addressing AI-enabled attack chaining, not just CVE severity triage
- Shape more agile, automated patching approaches - moving beyond monthly cycles toward Real Time patching and auto-remediation
- Engage senior stakeholders (CIO, COO, Infrastructure, business units) to reset ownership of risk vs. delivery
- Build the business case and secure budget sign-off
- Define the programme that takes this from strategy to implementation
About you
- Strong grounding in vulnerability management, but strategy-minded rather than operationally focused
- Understands how AI is reshaping attacker methodology
- Confident engaging and influencing senior stakeholders, with the maturity to land difficult conversations productively
- Able to build a business case from scratch and get it funded
- Comfortable working autonomously in an undefined, evolving brief
- Non-traditional backgrounds welcome - we're more interested in strategic instinct than 20 years of classic vulnerability testing experience