Full-Time

Vulnerability Management Manager

ION Group

ION Group

5,001-10,000 employees

Provides automated software platforms for trading

No salary listed

London, UK

In Person

Category
Engineering Management (1)
Required Skills
Computer Networking
Vulnerability Analysis
Linux/Unix
Requirements
  • Degree/diploma/certifications in a technology-related field and/or relevant working experience
  • Highly desired certifications include Security+, CCSP, CEH, GCIH, GMON, CASP or CISSP
  • 10 years’ experience in Vulnerability Management within large organizations with at least 5 years in a senior leadership role
  • Excellent track record of building and leading a Vulnerability Management program on a global scale with knowledge on vulnerability assessments, remediation and mitigation activities
  • Technical Security/Engineering/Compliance background with a track record of building and running global teams
  • Previous track record of build risk management framework and applying to an existing vulnerability management program
  • Strong technical expertise in implementing a Prioritization formula to vulnerabilities and misconfigurations and translating these into risks
  • Excellent knowledge of Vulnerability Management frameworks such as NIST/SANS
  • A team player with the ability to work independently and unsupervised
  • Ability to own delegated tasks and see them through to completion
  • Ability to manage time and prioritize work to maximize productivity
  • Excellent reporting and presentation skills are essential for this role
  • Excellent communication skills (both written and verbal)
  • Exceptional attention to detail and quality
  • Excellent problem-solving techniques and trouble analysis skills
  • Experience in design and publishing Security Standards & Policies
  • Experienced in leading Purple Teaming
  • Experienced in running global Bug Bounty/VDP programs
  • Experienced in leading Pen Testing, from scope, schedule, findings, remediation and risk registration and running the Pen Test program for Group Security as well as all other Verticals
  • The candidate should have a good knowledge of Vulnerability Management concepts, controls, and best practices for all Operating systems & asset types, (e.g. workstations, endpoints, mobile, servers either Windows/Linux, cloud instances, etc.)
  • Vulnerability Management tools (Tenable/Rapid7/Qualys)
  • Cloud Security compliance (IaaS, PaaS, SaaS) and misconfigurations
  • Multi-platform endpoints, infrastructure and XaaS vulnerability management deployments
  • General IT networking concepts, protocols, standards and network security concepts, controls, and best practices
  • Forensic investigation techniques
  • Prior experience deploying, configuring, managing, and/or operating security technologies is preferred, such as endpoint security (e.g. AV/EPP/EDR), SIEM, DLP, SWG, CASB, UEBA, IDS, IPS, firewalls, IAM/PIM/PAM, Vulnerability Management, MDM, etc.
  • Excellent track record of Senior Leadership and Board level interaction, reporting and communications
  • Experience in InfoSec program management, project support and large-scale change
  • Proven knowledge of compliance, regulatory practices and experience managing audits
Responsibilities
  • This role may require work-out of hours in support of 24x7 globally coordinated operation
  • The primary responsibilities of this role are to:
  • Personnel Management
  • Ensure team members have clear objectives/development plans
  • Align Teams’ objectives to OKRs
  • Be the escalation point for security Tooling issues and critical security breaches
  • Responsible for team development, upskilling & mentoring
  • Protect and defend:
  • Manage Vulnerability Management tooling to ensure coverage/availability/efficacy
  • Drive improvements and feature enhancement to ensure ROI
  • Operate and maintain:
  • Configure, tune, maintain & operate key vulnerability management controls
  • Management reporting – real-time metrics and scheduled reports
  • Drive process/procedure changes accordingly
  • Ensure quality of ticketing & runbook maintenance
  • Cultivate and maintain strong vendor relationships
  • Have an attitude of continuous improvement
  • Participate in CAB, Tool review or Architecture Review Boards (ARBs)
  • As a member of the ION IT Security Team, it is expected that the person in this role will:
  • Execute ongoing, operational business-as-usual (BAU) tasks to meet management-defined KPIs and SLAs, and deliver security projects in line with management-defined priorities and deadlines
  • Stay current with the latest security news, threats, intelligence, tactics, techniques, and vulnerabilities. Research and analyze new threats and vulnerabilities to determine exposure.
  • Assist and/or lead efforts to isolate, contain, respond to, and recover from security incidents
  • Identify, review, prioritize, plan, coordinate, and follow-up on the remediation of vulnerabilities
  • Define, document, and follow approved processes for all the responsibilities included in this job description. Create and maintain documentation for systems, including design and operation
  • Review vulnerability management systems, configurations, and processes to ensure and report on compliance with ION policy, client requirements, audit controls, regulations, and industry best practices. Provide best practice security recommendations to IT and other teams within ION, based on review results
Desired Qualifications
  • Certifications listed as highly desired: Security+, CCSP, CEH, GCIH, GMON, CASP, or CISSP
  • Experience in Purple Teaming
  • Running global Bug Bounty/VDP programs
  • Leading Pen Testing from scope to remediation and risk registration for Group Security and other Verticals
  • Knowledge of Vulnerability Management tools such as Tenable, Rapid7, Qualys
  • Cloud Security compliance (IaaS, PaaS, SaaS) and misconfigurations
  • Forensic investigation techniques
  • Experience in leading and/or participating in Pen Testing and vulnerability management related audits and regulatory compliance coordination

ION Group delivers software platforms and APIs that automate trading, processing, and risk management for institutional clients in global financial markets. Its products connect to multiple trading venues and exchanges, enabling efficient, accurate transactions and streamlined operations. The company earns revenue from software licensing, subscriptions, and professional services, including customization and support. ION differentiates itself by expanding through acquisitions to stay agile and by offering integrated automation across trading, processing, and risk management, backed by a broad connectivity footprint. The goal is to help clients achieve greater efficiency and reduce operational risk in their financial workflows.

Company Size

5,001-10,000

Company Stage

Growth Equity (Venture Capital)

Total Funding

$438.5M

Headquarters

London, United Kingdom

Founded

1998

Simplify Jobs

Simplify's Take

What believers are saying

  • XTP for Event Contracts launched with Wedbush in December 2025 ahead of Super Bowl.
  • Treasury VoP capabilities live in Germany since April 2026, serving 1,100 global clients.
  • €1.35 billion Prelios acquisition in July 2024 expands into asset management services.

What critics are saying

  • SEC or CFTC bans retail prediction markets within 6-18 months, killing XTP revenue.
  • Wedbush operational failure within 12-24 months eliminates ION's sole FCM partner.
  • VoP logic failures trigger EU customer fines and ION liability within 12-18 months.

What makes ION Group unique

  • ION's Multi-Market Interface automates trading across derivatives, forex, and fixed income markets.
  • XTP platform enables 24x7 event contract processing with real-time settlement for prediction markets.
  • Proprietary ownership of Acuris and Dealogic provides exclusive financial data advantages.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health, dental, and vision insurance

AD&D and disability insurance

Flexible spending account

Health savings account

Life insurance

Mental health care

401K plan

Performance bonus

Supplemental workers' compensation

Family medical leave & parental leave

PTO, paid holidays, sick days, bereavement leave, and volunteer time off

Commuter checks

Company social events

Employee assistance program

Free lunch

mobile phone discount

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
ION Group
Oct 17th, 2025
ION wins Market Surveillance Solution of the Year at FOW Asia Pacific Awards 2025

ION wins Market Surveillance Solution of the Year at FOW Asia Pacific Awards 2025. 17 October 2025 LONDON - 17 October 2025: ION, a global leader in trading and workflow automation software, high-value analytics and insights, and strategic consulting to financial institutions, central banks, governments, and corporates, announces that LookOut has been named "Market Surveillance Solution of the Year" at the FOW Asia Pacific Awards 2025. The awards, hosted by Futures & Options World (FOW), recognize excellence and achievements in the Asian derivatives industry. LookOut is a global, multi-compliance solution for trade surveillance, record keeping, and regulatory reporting. The solution enables brokers, investment banks, asset managers, and trading venues to meet regulatory requirements across different asset classes. The product's broad coverage - including market manipulation, insider trading, best execution and trading obligation monitoring, market-making, and market integrity surveillance - earned it the top honors. LookOut features over 50 built-in detection algorithms and complies with global and regional trade surveillance regulations across EMEA, North America, and APAC. Over the past few years, ION has made strategic investments in artificial intelligence and machine learning, resulting in the development of a Machine Learning Toolkit (MLT). LookOut used the toolkit to build a Machine Learning for Alarm Classification (MLAC) module, streamlining alert triage and case management, and significantly reducing the time compliance teams spend on analysis. Mirko Marcadella, Head of Product for Risk & Market Surveillance Solutions in Markets, ION, said: "We are honored that our LookOut solution has been recognized as the Market Surveillance Solution of the Year. This award reflects our commitment to delivering best-in-class technology that empowers our clients, in Asia, as well as globally, to navigate complex regulatory challenges. Over the past few years, we've significantly expanded our investment in AI and machine learning. Combined with native integration across other ION solutions, these innovations have strengthened our market presence and helped our clients streamline surveillance operations, reduce response times, and improve overall efficiency."

The Herald-Advocate
Jul 7th, 2025
ION wins "Best Sell-Side OMS" at Capital Markets Technology Awards APAC 2025

LONDON, July 7, 2025 /PRNewswire/ - ION, a global leader in trading and workflow automation software, high-value analytics and insights, and strategic consulting to financial institutions, central banks, governments, and corporates, announces that its Fidessa platform has won "Best Sell-Side OMS" at Capital Markets Technology Awards APAC 2025.

PR Newswire
May 23rd, 2025
ION wins "Best algo trading solution" at WatersTechnology Asia Awards 2025

LONDON, May 23, 2025 /PRNewswire/ - ION, a global leader in trading and workflow automation software, high-value analytics and insights, and strategic consulting to financial institutions, central banks, governments, and corporates, announces that its Fidessa Algorithms has won "Best algo trading solution" at the WatersTechnology Asia Awards 2025.

PR Newswire
May 22nd, 2025
Ion Commodities Named Ctrm Software House Of The Year At Energy Risk Awards 2025

LONDON, May 22, 2025 /PRNewswire/ -- ION Commodities, the leading global provider of energy and commodity trading and risk management (ETRM/CTRM) solutions, has been named CTRM Software House of the Year at the prestigious Energy Risk Awards 2025.Each year, Risk.net – the world's leading source of in-depth news and analysis—hosts the Energy Risk Awards to recognize excellence in the commodity markets. The awards distinguish companies across global commodity markets for their innovation and leadership.This recognition highlights ION Commodities' continued commitment to delivering innovative, scalable, and future-ready solutions that empower organizations to navigate an increasingly volatile and complex trading environment. It underscores ION's role as a trusted partner in driving digital transformation and operational resilience across global commodity markets.In recent years, ION has significantly invested in its CTRM portfolio—continuing to expand its functionality for traditional fossil fuel-based commodities while also advancing capabilities to support the energy transition. This dual focus enables businesses to navigate both long-term market shifts and near-term disruptions, while meeting growing regulatory and sustainability demands.With investments in AI, real-time analytics, cloud-native architecture, and integration across traditional and renewable fuels, biogas, carbon, and power markets, ION supports a diverse range of energy and commodity businesses in transforming and streamlining new and existing operations. Many companies have turned to ION to modernize their global trading operations, integrate renewables, and optimize supply chains. From SaaS solutions like Aspect to enterprise-scale C/ETRMs like Openlink, TriplePoint, RightAngle, and Allegro, ION's technology enables real-time risk mitigation, cross-market visibility, and long-term scalability."This recognition underscores ION's role in supporting businesses navigating the complex realities of today's global commodity markets," said Sunil Biswas, Chief Executive Officer of ION Corporates

PR Newswire
May 16th, 2025
Creditflux Announces 2025 Clo Manager Awards Winners

The Creditflux awards are the only credit fund and CLO industry awards solely determined by data and metrics, showcasing the market's best performers. LONDON, May 16, 2025 /PRNewswire/ -- Creditflux, a Debtwire service and part of ION Analytics, and the leading source for CLO and credit trading news, data, and analysis globally, hosted its 17th annual CLO Manager Awards at the Nobu Hotel in London on 15 May 2025. The global collateralized loan obligation (CLO) community came together to recognize the best-performing CLOs, managers, and funds across the USD 1.4tn global CLO market. This year, over 90 CLO managers and CLO fund managers submitted performance data for the awards. The category winners were announced live during the Creditflux Manager Awards Dinner, attended by 350 guests