The Roles · Who defends it

Vulnerability analyst

Written from published sources

The analyst who looks for the weaknesses before an adversary does. The national framework describes the work as assessing systems and networks to identify deviations from acceptable configurations, and measuring how well a defence-in-depth architecture holds against known vulnerabilities. The output is a prioritised account of exposure, which somebody else then has to act on.

What the day looks like

  • Running assessments across an estate whose inventory is a moving target.
  • Separating the findings that matter from the volume that arrives with them, using exposure rather than score alone.
  • Verifying that a reported weakness is reachable in this environment, since context decides severity.
  • Retesting after remediation, which is the step that turns a ticket into a fact.
  • Reporting to the teams who own the systems, in terms that make the fix ownable.

What it answers for

  • Findings that are true, reachable and reproducible.
  • Prioritisation that reflects this organisation rather than a generic score.
  • The record of what was tested, when, and with what coverage.

What it is measured on

  • Coverage of the estate, and the age of the last assessment.
  • Time to remediate, which belongs to other teams and lands on this report.
  • Findings verified as closed rather than marked as closed.

Who it receives from

Asset management
The inventory, at whatever accuracy the organisation maintains.
Threat intelligence
Which weaknesses are being used, which changes what matters first.
Vendors
Advisories, fixed releases and the details that make a finding actionable.

Who it serves

The teams who own the systems
A short, ordered list they can act on.
Security leadership
Exposure expressed as a trend rather than a snapshot.
Audit and compliance
Evidence that assessment happens and that findings close.

Who else has a stake

  • Every team whose maintenance window a remediation will occupy.
  • The organisation's insurers and regulators.
  • Customers relying on the systems being assessed.

What it takes

  • Breadth across operating systems, networks and applications, since the estate contains all of them.
  • The judgement to rank by reachable exposure rather than by the number a scanner printed.
  • Diplomacy, because the deliverable is a list of other people's outstanding work.
  • Persistence through the retest, which is where the value is realised.

What the job turns on

The report is easy to produce and the remediation belongs to somebody else, which makes influence the actual skill. An analyst who arrives with two hundred findings ordered by scanner severity hands over a document; one who arrives with the six that are reachable from the internet, with the fixed version named and the window suggested, hands over a plan. The second gets fixed, and the difference is entirely in the preparation.

The published sources

Where it leads

Roles that lead here

The work itself

The Practice covers how this work is done — triage, escalation, evidence, handover — across the whole corpus.

Read The Practice