Talent.com
Coforge
Vulnerability EngineerCoforge • Greater London, ENG, GB
Search for other jobs
Vulnerability Engineer

Vulnerability Engineer

Coforge • Greater London, ENG, GB
1 day ago
Job type
  • Permanent
Job description

Work-mode: Hybrid - 3 days weekly from office

Skills: Vulnerability, Qualys, PowerShell and Microsoft SCCM/MECM

We at Coforge are looking for Vulnerability Engineer in London, UK.

Scope & Description of Required Work

  • Own the technical investigation and remediation of complex endpoint vulnerabilities across the workstation estate.
  • Analyse and prioritise findings from Qualys and other approved security platforms, considering technical impact, business risk and remediation feasibility.
  • Perform structured root cause analysis for vulnerabilities, failed deployments, recurring non-compliance and endpoint health issues.
  • Design, test and deliver sustainable engineering fixes that remove underlying causes and reduce repeated manual remediation.
  • Create, test, peer review and deploy enterprise application packages, security updates and configuration changes through Microsoft SCCM/MECM and related endpoint tooling.
  • Develop and maintain PowerShell automation for detection, remediation, validation, reporting and operational health checks.
  • Troubleshoot SCCM/MECM client health, software distribution, content delivery, deployment status and patch installation failures.
  • Use controlled pilot groups, technical validation and rollback planning to reduce deployment risk.
  • Work with the End User Platform and Security teams to agree remediation strategy, technical ownership and delivery priorities.
  • Recommend improvements to packaging standards, deployment controls, vulnerability workflows, reporting and endpoint engineering processes.
  • Produce clear technical documentation, remediation records, runbooks, knowledge articles and audit evidence.
  • Provide accurate progress, risk and dependency updates for vulnerability, compliance and service reporting.
  • Support remediation across physical workstations, laptops and Citrix virtual desktop environments.
  • Apply ITIL best practice across Incident, Request, Problem and Change management activities.
  • Perform system administration and advanced troubleshooting within Windows, Active Directory, Group Policy and Microsoft 365 environments.
  • Ensure solutions comply with TMHCC security policies, technical standards, controls and agreed service levels.

Out of Scope

  • Activities not explicitly listed in the Scope & Description of Required Work.
  • Changes to production services that have not completed the required TMHCC change control and approval process.
  • Ownership of security policy, risk acceptance decisions or business risk sign-off.
  • Work on unsupported platforms or systems outside the agreed endpoint estate unless separately authorised.

Deliverables & Delivery Milestones

  • Prioritised vulnerability remediation backlog based on approved security data and agreed delivery priorities.
  • Tested and peer-reviewed SCCM/MECM packages, security updates and configuration changes.
  • Production-ready PowerShell detection, remediation and validation scripts.
  • Root cause analysis records for recurring vulnerabilities, failed deployments and endpoint health issues.
  • Pilot, validation and rollback evidence for controlled deployments.
  • Runbooks, knowledge articles, remediation records and audit evidence.
  • Regular progress, risk, dependency and outcome reporting.
  • Delivery milestones and target dates to be agreed during onboarding and maintained through the applicable planning and change processes.

Acceptance Criteria

  • Agreed vulnerability remediation activities are completed in line with approved priorities, change controls and service levels.
  • Delivered packages, scripts and configuration changes pass agreed testing, peer review, pilot and technical validation requirements before production deployment.
  • Remediation includes clear evidence of outcome, validation results and rollback arrangements where applicable.
  • Root causes and recurring failure patterns are documented, with permanent engineering actions or technical debt items recorded where required.
  • Technical documentation, runbooks, knowledge articles, remediation records and audit evidence are complete, accurate and stored in the agreed TMHCC location.
  • Progress, risks, dependencies and blockers are reported accurately through the agreed governance process.
  • Solutions comply with TMHCC security policies, technical standards and operational processes.
  • Deliverables are accepted by the TMHCC Hiring Manager or nominated technical owner.

#J-18808-Ljbffr

Create a job alert for this search

Vulnerability Engineer • Greater London, ENG, GB