Senior Vulnerability Management Engineer
๐ข London Stock Exchange Group ยท all London Stock Exchange Group jobs
๐ United Kingdom
๐
Posted 2026-07-29 ยท via Himalayas
๐ท Vulnerability-Management,Penetration-Testing,Application-Security,Offensive-Security,Security-Engineering,Vulnerability-Management-Engineer,Principal-Threat-And-Vulnerability-Management-Engineer,Vulnerability-Management-Specialist,Vulnerability-Management-Engineering,Senior-Cybersecurity-Engineer,Senior-Information-Security-Engineer,Security-Engineer
Apply on original site โSenior Vulnerability Management Engineer
Job Description
LSEG is seeking aโฏ Senior Vulnerability Management Engineer to join our internal offensive security team with focus on driving closure of penetration testing findings. This role bridges offensive security and engineering by translating penetration test results into clear, actionable remediation guidance and partnering with application and platform teams to implement secure fixes. The successful candidate has a strong penetration testing or application security background, hands on remediation experience, and the ability to coordinate multiple collaborators to reduce risk at scale. This is a highly technical, delivery focused role with responsibility for both individual findings and systemic improvements.
Key Responsibilities
-
Analyzeand review penetration test reports to understand technical impact, exploitability, and business risk.
-
Develop,documentandmaintainremediation guidance, patterns, andblue-printsfor common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations).
-
Provide consultation to application and platform teams on secure design and remediation approaches, including code-level, configuration-leveland business-level recommendations.
-
Coordinate remediation activities across multiple teams, ensuring, clear ownership, agreed timelines, and risk-based prioritization.
-
Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure.
-
Manage and track the remediation backlog, including SLAs, aging finings, and critical issues when needed.
-
Produce andmaintaindocumentation on remediation processes, workflows, and controls for audit and compliance purposes.
-
Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners.
-
Perform root cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long-term corrective actions.
-
Contribute to continuous improvement of thepentest-to-remediation lifecycle, including automation,standardizationand integration with SDLC/DevSecOpspipelines.
-
Compile technical documents,trackand document remediation metadata
-
Engagement details (who, what, when, where)
- Testing team members and roles
- Tools and methodologies used
- Schedule and timelines
- Target systems and environments
- Constraints, exclusions, and limitations
- Testing activities and event logs
-
Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references.
-
Contribute to the continuous improvement of testing methodologies, tooling, automation.
-
Stay ahead of with emerging threats, vulnerabilities, and offensive security techniques.
-
Participate in R&D initiatives as guided from leadership.
-
Support knowledge sharing and mentoring within the team.
Required Skills & Experience
-
Proven hands-on experience in penetration testing of Web Applications, APIs, ThickClientand Common Infrastructures (Active Directory, Cloud and Cloud-native based environments).
-
Proficiencywith tools such as Burp Suite, common command-line tools, and ability to write custom scripts when needed.
- Experience in automatingpentestingtasks.
-
Solid understanding of application security, network protocols, and operating systems.
-
Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes).
-
Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least on major language stack (e.g. Java/Springboot, .NET, JavaScript/Node, Python)
-
Ability to write clear, technical reports and communicate findings and fixes to both technical and non-technical partners.
-
Experience working in large, com