NHS Logo

Vulnerability Management Engineer

Northumbria Healthcare NHS Foundation Trust
This job is closed to applications
Medical Protection Advertisement

Location
Salary
£47,810 - £54,710 per annum
Profession
Administrative and IT
Grade
Band 7
Deadline
01 Sep 2025
Contract Type
Permanent
Posted Date
22 Aug 2025

Job overview

Northumbria Healthcare is making a significant investment in new technology to transform how we deliver care.  The multi-million pound programme is both challenging in the expectation of delivery as well as ensuring that our services are secure, robust and resilient at all times. An opportunity has arisen for a Vulnerability Management Engineer to join the Digital Services Team at Northumbria Healthcare NHS Foundation Trust.

Working as part of the Information Security Team, you will be responsible for reducing risk to Northumbria's IT systems and data. The post will be based at the Manufacturing and Innovation Hub premises in Seaton Delaval and you will be coordinating mitigation and resolution activities with technical staff, system stakeholders and third parties across Trust sites such as North Tyneside General Hospital, Hexham General Hospital and the Northumbria Specialist Emergency Care Hospital in Cramlington.

Please note we reserve the right to close this vacancy prior to the closing date once the required number of suitable applications have been received.

Main duties of the job

The Vulnerability Management Engineer role involves utilising the Trust's security toolset to facilitate the reduction of risk to Northumbria’s IT systems and data. You will evaluate the practical criticality of vulnerabilities discovered by tooling, penetration tests, CareCERTS, audits, spot checks and assessments. You will lead and coordinate the required mitigation and resolution activities between Trust technical staff, system stakeholders, third parties, and any other parties required, to reduce the risk from all vulnerabilities by means such as patching, upgrades, reconfiguration, containment/isolation, etc.

You must be able to take a pragmatic view of risk and apply a wide knowledge of IT subjects to deliver solutions which balance risk reduction against service disruption.  The role will also manage the Digital Services vulnerability register, arrange Penetration Testing and IT health checks, and take a key role in the Trust’s cyber compliance activities and accreditations.

Experience of leading group work to resolve issues is essential alongside excellent communication skills as you will be regularly liaising with clinical and business services, service delivery teams and 3rd party suppliers. You will be responsible for generating regular vulnerability reports for senior management and will be required present and discuss these. You will have recent and comprehensive experience of working in large-scale, corporate, connected and distributed IT environments.

Detailed job description and main responsibilities

  • Provide leadership and co-ordination for vulnerability management projects
  • Ownership of compliance submissions including Data Security and Protection Toolkit, and DCB 1596 NHS Secure Mail Accreditation
  • Develop viable options for the Trust response to vulnerabilities.
  • Perform recurring and on-demand scanning of Trust systems and cloud environments.
  • Review the Trust’s security toolset to identity vulnerabilities in hardware, software, operating systems, web services, and other Trust information systems.
  • Classify and communicate the risk of identified vulnerabilities and recommend security controls to mitigate them
  • Maintain documentation regarding threat management, including policies and procedures
  • Assist technology teams to develop, implement, and automate security solutions
  • Improve and automate existing vulnerability management systems
  • Research and assess emerging security threats and vulnerabilities
  • Manage the penetration testing of Trust systems for compliance and assurance.
  • Manage the Trusts vulnerabilities register and escalate to risk register as appropriate.
  • Work with Digital Services teams to implement “approved standard builds” across all managed assets and manage the ongoing configuration and release management processes.
Vulnerability Management Engineer at Northumbria Healthcare NHS Foundation Trust | Job Clerk