Solution Vulnerability Engineer
London, UK
Stephenson Harwood
What we will offer
We will offer you a place where you can be yourself and where there are no limits on what you can achieve. With us, you can take ownership of your career and have honest conversations throughout. You would join an ambitious firm with a clear strategy for profitable growth where you can get early responsibility and early involvement in growing the business. Here you can expect a competitive and fair reward as well as recognition based on all round performance. This forms part of our internal promise to you, The Deal, between the firm and its employees.
You can expect:
- A competitive salary and a host of family friendly policies
- Life assurance, private health and dental care for you and your family
- A range of flexible benefits including gym discount and retail vouchers
- Tech, cycle and electric car schemes
- The opportunity to support the firm's charity through volunteering leave
- A wellbeing strategy that focuses on preventative measures to maintain overall health, and tools and support for when our people experience physical or mental difficulties. The strategy focuses on four pillars: physical, emotional, financial and social aspects.
- Most of our roles are hybrid, meaning that colleagues benefit from working in our office and remotely. We are happy to discuss this and other flexible working arrangements with you as part of the application and interview process.
Team Structure
The IT function is comprised of the following teams: Service Desk, Technical Support and User Experience, Applications, Architecture & Solution Delivery, PMO, IT Security, and IT Change and Adoption.
This role sits in the Architecture & Solution Delivery team, reporting to the Solution Delivery Manager, and has accountability for defining and delivering the IT Modern Workplace project in alignment with the IT and business strategy.
Main Responsibilities
This role will be the bridge between the Solution Delivery and Information Security teams. This role is responsible for identifying, assessing, and mitigating vulnerabilities across our infrastructure, applications, and cloud environments. You’ll play a key role in strengthening our security posture and ensuring compliance with security policies and industry best practices.
- Perform regular vulnerability assessments across endpoints, servers, applications, and cloud resources.
- Analyse scan results, validate findings, and prioritize based on risk, exploitability, and asset criticality.
- Collaborate with IT, DevOps, and application teams to remediate or mitigate identified vulnerabilities.
- Track remediation efforts and verify effectiveness through re-scans and reporting.
- Support audits, compliance checks, and security assessments as needed.
- Implement and support endpoint protection, patching, and backup solutions.
- Continuously improve processes, playbooks, and documentation related to vulnerability management.
- Grow an awareness and understanding of the related systems, architecture and processes across the SH technology estate.
- Ability to work in a flexible way in respect of works required outside of normal working hours.
- Ability to travel to the Firms' offices when required.
Attributes/Skills Required
- 1–2 years of experience in cybersecurity or IT with a focus on vulnerability management.
- Proficiency with tools such as Crowdstrike, Intune or Action1.
- Familiarity with patch management processes in Windows and macOS environments.
- Knowledge of basic networking, firewalls, and cloud security.
- Experience working in Active Directory, Microsoft Entra ID, Microsoft 365, Intune, and other enterprise tools.
- Confident and clear communication (verbal and written) with people at all levels of the business hierarchy.
- Ability to work independently and cross-functionally with multiple teams.
This job description is indicative only and does not represent an exhaustive list of responsibilities. The firm reserves the right to alter or change the responsibilities at any time, in line with the firm's strategy and business needs.
About the Firm
With 8 offices worldwide and with our headquarters based in London, Stephenson Harwood is a law firm where our people are committed to achieving the goals of our clients - listed and private companies, institutions and individuals across the globe. Our mix of expertise and culture results in a combination of deep local insight and the capability to provide a seamless international service.
Our experience encompasses corporate, commercial litigation and arbitration, employment, pensions and private wealth, finance, marine and international trade, and real estate and projects.
We assemble teams of bright thinkers to match our clients' needs and give the right advice from the right person at the right time. Dedicating the highest calibre of legal talent to overcome the most complex issues, we deliver pragmatic, expert advice that is set squarely in the real world.
We understand the power of diversity in delivering that high calibre advice to our clients. We want to attract diverse talent and we particularly encourage applications from underrepresented demographics.
Our Values
Individuality - We encourage creativity and devlop talent.
Commitment - To be the best and deliver the highest standard.
Teamwork - We work together to build close, long-term relationships.
Straight talking - We say what we mean and do what we say.
Our Vision into 2026
To be a successful firm where talented people work together in an entrepreneurial environment, building long term client relationships.
This version is about who we want to be, as well as who we are. It is as much about our values as about our character - the attributes we want to see from all of our people. That's how we unlock our entrepreneurial spirit, advising our clients with top performing teams.
A key part of the 2026 strategy is to focus on five core sectors: energy transition; life sciences and healthcare; private capital and funds; technology; transportation and trade. These have been identified as crucial in the drive for accelerated profitable growth.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Active Directory Audits Cloud Compliance CrowdStrike DevOps Finance Firewalls MacOS Security assessment Strategy Travel Vulnerabilities Vulnerability management Windows
Perks/benefits: Competitive pay Flex hours Health care Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.