About this role
Job title: Vulnerability Management Analyst
Posting Date: 23-Sep-2026 Requisition ID: 3588 States/Provinces/Cities: Belfast, Buenos Aires, Manila Location Type: Hybrid Business Unit: Business Professionals Function: Technology Full Time or Part Time: Full Time
Description & Requirements The Vulnerability Management Analyst is responsible for analyzing, categorizing, and prioritizing identified security vulnerabilities across the firm's technology infrastructure. Acting as a trusted partner to technology teams, the role will drive vulnerability remediation efforts, provide risk-based guidance, and track remediation progress to help reduce the firm's overall cyber risk exposure
Main responsibilities
- To operate and serve as a subject matter expert in the firm’s vulnerability management program. Perform regular vulnerability scans and across applications and infrastructure. Validate and prioritise remediation of vulnerabilities from the firm’s security tooling. Monitor security advisories, threat intelligence services and vendor notifications for vulnerability remediation.
Skills and experience:
- Expert experience of working with enterprise vulnerability management platforms.
- Working experience with threat intelligence, attack surface mgmt. and exposure mgmt. platforms.
- Expert understanding of vulnerability scoring, including CWE, CVSS and MITRE ATT&CK.
- Foundational knowledge of windows, Linux and networking.
- Ability to assess security risks and prioritise remediation works at enterprise scale.
- Experience in the creation and development of Vulnerability dashboards, reports and executive level metrics.
- Ability to validate the presence of identified vulnerabilities with accuracy and reduce false positive detections.
- Experience of managing vulnerability exceptions, risk acceptance in a large, structured enterprise environment.
- Highly desired experience of working within an enterprise SOC.
- Ongoing commitment to understanding of the threat landscape and common adversary motivations/practices. Ability to quickly adapt practices to evolving circumstances.
- Ability to perform autonomous vulnerability threat research and analysis
- Strong written and oral communication skills. Ability to convey complex concepts to non-technical constituents. Proficiency in oral and written English.
- Capable of providing assistance with the preparation of internal training materials and documentation.
- Ability to be productive and maintain focus to meet firm SLAs on vulnerability remediation.
- Understands Vulnerability Management in the context of risk management and organizational priorities.
Qualifications
-
Possess a Computer Science Bachelor’s Degree or substantial equivalent experience
-
CISSP desired
-
GIAC Vulnerability assessment (GMON/GVCA)
-
Microsoft security certification (SC-900, SC-200)
-
Security+
-
Certified Ethical hacker
-
Reports to: Security Engineering Manager & Vulnerability Management architect
-
Position Type: Centre Services
-
Development Framework: Specialist
-
About us
-
Baker McKenzie empowers clients to compete in the global economy. We provide comprehensive and practical legal advice that cuts through complexity with clear, actionable guidance. Our people represent diverse cultures and jurisdictions, combining local know-how with international expertise to ensure your business thrives across borders.
-
Additional Information
-
Baker McKenzie is an Equal Opportunity Employer. We are committed to promoting diversity and inclusion for all. Our unique international culture is reflected in the drawing together of a worldwide family of individuals from diverse cultures and backgrounds in all of our offices. We encourage the best people - regardless of race, religion or belief if any, gender, gender identity, disability, sexual orientation or age - to fulfill their professional aspirations with us. We are committed to ensuring an inclusive and accessible experience for all candidates.