Skip to content
site-logo

FEDIP Job Profiles

  • Home
  • About
  • All Job Roles
  • Submit Feedback
  • News
  • FAQs

SFIA Skills: Vulnerability assessment (VUAS)

Vulnerability identification and analysis (VUAS) (Level 4)

Assesses the potential vulnerabilities identified against established vulnerability databases.

Vulnerability assessment (VUAS) (Level 4)

Conducts automated and manual vulnerability assessments and business impact analyses. Creates test cases using in-depth technical analysis of risks and typical vulnerabilities. Assesses effectiveness of security controls for infrastructure and application components, and recommends remedial action.

Tools and techniques (VUAS) (Level 4)

Contributes to the selection and deployment of vulnerability assessment tools and techniques.

Risk mitigation (VUAS) (Level 4)

Delivers risk treatment plans using one or more recognised control sets.

Risk assessment (VUAS) (Level 4)

Produces a risk assessment table to determine the likelihood and impact to an information or technology asset if a vulnerability is exposed to a threat source, assigning a likelihood and impact to determine risk level. Documents the business impact of a vulnerability being breached.

Critical information and technology assets (VUAS) (Level 4)

Allocates an impact level to critical information and technology assets should their confidentiality, integrity or availability be breached. Collates and analyses catalogues of information and technology assets for vulnerability assessment.

Communication and awareness (VUAS) (Level 4)

Promotes security awareness and communicates information on security risks and potential business impact to senior business managers and others.

Assessment documentation (VUAS) (Level 4)

Documents a full vulnerability assessment and business impact analysis conducted on medium complexity information systems.

Vulnerability identification and analysis (VUAS) (Level 5)

Takes a comprehensive approach to seeking vulnerabilities across the full spectrum of organisation policies, processes, and defences in order to improve organisational readiness, improve training for defensive practitioners, and inspect current performance levels.

Vulnerability assessment (VUAS) (Level 5)

Plans and manages automated and manual vulnerability assessment activities within the organisation. Assesses effectiveness of security controls for infrastructure and application components and recommends remedial action.

Tools and techniques (VUAS) (Level 5)

Reviews, evaluates, and selects vulnerability tools and techniques.

Risk mitigation (VUAS) (Level 5)

Identifies control owners and holds them accountable for the implementation of policies to reduce the risk of controls allocated to them using a recognised methodology.

Risk assessment (VUAS) (Level 5)

Uses complex quantitative risk analysis methods such as exposure factor, single loss expectancy, annualised rate of occurrence or annualised loss expectancy, to conduct security risk assessments, business impact analysis and accreditation on complex information systems.

Critical information and technology assets (VUAS) (Level 5)

Determines a quantifiable value to the impairment of an identified critical information or technology asset.

Communication and awareness (VUAS) (Level 5)

Communicates to the organisation’s leadership information on security risks to critical information and technology assets, and the impact on the business should vulnerabilities be breached.

Assessment documentation (VUAS) (Level 5)

Documents a full vulnerability assessment and business impact analysis conducted on complex information systems.

Vulnerability identification and analysis (VUAS) (Level 3)

Determines the potential vulnerabilities that might breach a critical information asset.

Vulnerability assessment (VUAS) (Level 3)

Conducts automated and manual vulnerability assessments under direction. Undertakes moderate-complexity vulnerability assessments using more sophisticated techniques and tools.

Risk assessment (VUAS) (Level 3)

Assesses the likelihood of attack on critical information and technology asset vulnerabilities from a threat source. Assesses the business impact and determines a value to the potential loss should a vulnerability be breached.

Critical information and technology assets(VUAS) (Level 3)

Assigns asset information security requirements and catalogues identified critical information and technology assets for vulnerability assessment.

Communication and awareness (VUAS) (Level 3)

Promotes security awareness and communicates information on known security risks and issues to business managers and others.

Assessment documentation (VUAS) (Level 3)

Documents vulnerability assessments. Evaluates and documents results, escalating and communicating issues where appropriate.

Vulnerability identification and analysis (VUAS) (Level 2)

Identifies basic vulnerabilities that might breach a critical information or technology asset.

Vulnerability assessment (VUAS) (Level 2)

Undertakes routine vulnerability assessments using automated and semi-automated tools, escalating issues where appropriate. Participates, under supervision, in more complex assessments.

Critical information and technology assets (VUAS) (Level 2)

Identifies and documents critical information and technology assets within the organisation, including the asset type and asset location.

Communication and awareness (VUAS) (Level 2)

Promotes awareness of security risks and issues to colleagues and others.

Assessment documentation (VUAS) (Level 2)

Documents the scope and results of basic vulnerability assessments, or contributes to the documentation of more complex assessments.

Job Families

  • IT Operations (47)
    • Application Operations Engineer (6)
    • End User Computing Engineer (5)
    • Infrastructure Operations Engineer (5)
    • Infrastructure Engineer (5)
    • Service Transition Manager (4)
    • Service Desk Manager (4)
    • IT Service Manager (4)
    • Command and Control Centre Manager (4)
    • Change and Release Manager (3)
    • Business Relationship Manager (3)
    • Incident Manager (2)
    • Problem Manager (2)
  • User Centred Design (37)
    • User Researcher (6)
    • Service Designer (6)
    • Interaction Designer (6)
    • Graphic Designer (6)
    • Content Designer (6)
    • Accessibility Specialist (4)
    • Technical Writer (2)
    • Content Strategist (1)
  • Architecture (27)
    • Solutions Architect (5)
    • Technical Architect (5)
    • Business Architect (4)
    • Enterprise Architect (4)
    • Network Architect (3)
    • Data Architect (3)
    • Security Architect (3)
  • Data (25)
    • Data Engineer (5)
    • Data Analyst (5)
    • Analytics Engineer (4)
    • Data Scientist (4)
    • Data Governance Manager (3)
    • Machine Learning Engineer (2)
    • Data Ethicist (2)
  • Software Development (24)
    • Software Developer (9)
    • Development Operations Engineer​​ (9)
    • Frontend ​Developer​ (6)
  • Product and Delivery (21)
    • Business Analyst (6)
    • Product Manager (5)
    • Delivery Manager (4)
    • Digital Portfolio Manager (4)
    • Service Owner (1)
    • Programme Delivery Manager (1)
  • Patient Services (18)
    • Clinical Coder (7)
    • Records and Information Manager​​ (4)
    • Patient Access​ Manager​ (4)
    • Data Quality​ Officer​ (3)
  • Quality Assurance Testing (10)
    • Quality Assurance Testing (QAT) Analyst (4)
    • Test Engineer (4)
    • Test Manager (2)
  • Cyber Security (10)
    • Cyber Security Specialist (Governance Risk and Compliance) (4)
    • Cyber Security Specialist (Operations) (4)
    • Cyber Security Analyst (2)
  • Digital Leadership Roles (9)
    • Chief Technology Officer (1)
    • Chief Information Officer (1)
    • Chief Audit Officer (1)
    • CxIO (1)
    • Chief Information Security Officer (1)
    • Chief Analytics Officer (1)
    • Caldicott Guardian (1)
    • Chief Data Officer (1)
    • Chief Pharmacy Information Officer (1)
  • Knowledge, Library and Information Management (8)
    • Knowledge Manager (5)
    • Library Manager (2)
    • Information Manager (1)
  • Digital Education Services (6)
    • Digital Education Specialist (2)
    • Digital Education Manager (2)
    • Digital Education Administration (1)
    • Digital Education Trainer​ (1)
  • Information Governance (6)
    • Information Governance Officers​ (3)
    • Information Governance Manager​​s (2)
    • Data Protection Officer​​ (1)
  • Clinical Informatics (3)
    • Clinical Informatician​ (2)
    • Clinical Safety Officer (1)
FEDIP logo

The Federation for Informatics Professionals in Health and Care

Registered in England and Wales No. 10639143

email: info@fedip.org

Copyright © 2026 All Rights Reserved FEDIP | Use of cookies | Legal notices
Registered in England and Wales No. 10639143

website by Sarah Scriven