Skip to content
site-logo

FEDIP Job Profiles

  • Home
  • About
  • All Job Roles
  • Submit Feedback
  • News
  • FAQs

SFIA Skills: Vulnerability research (VURE)

Tools and techniques (VURE)(Level Six)

Develops techniques and tools to analyse and expose vulnerabilities designing new vulnerability discovery techniques.

Research activities (VURE)(Level Six)

Plans and leads the organisation’s approach for vulnerability research. Identifies new and emerging threats and vulnerabilities.

Reporting (VURE)(Level Six)

Engages with, and influences, relevant stakeholders to communicate results of research and the required response.

Networking and communities (VURE)(Level Six)

Maintains a strong external network. Takes a leading part in external-facing professional activities to facilitate information gathering.

Body of knowledge (VURE)(Level Six)

Takes a leading role in the development of the security vulnerability research body of knowledge. Initiates frequent communications with peers in other organisations and in other countries, presents keynote papers at conferences, writes for high impact journals and major clients.

Tools and techniques (VURE)(Level Five)

Adopts and adapts vulnerability assessment techniques and tools to be used by others.

Research activities (VURE)(Level Five)

Plans and manages vulnerability research activities into new threats, attack vectors, risks and potential solutions.

Reporting (VURE)(Level Five)

Assesses and documents the impacts and threats to the organisation. Creates reports and shares knowledge and insights with others.

Networking and communities (VURE)(Level Five)

Maintains a strong external network within own area of specialism.

Body of knowledge (VURE)(Level Five)

Gathers information on new and emerging threats and vulnerabilities. Contributes research findings on security vulnerabilities, countermeasures, and mitigations to national and international vulnerability databases.

Tools and techniques (VURE) (Level 4)

Specifies requirements for environment, data, resources, techniques and tools to perform vulnerability assessments.

Research activities (VURE) (Level 4)

Designs and executes complex vulnerability research activities into new threats, attack vectors, risks and potential solutions.

Reporting (VURE) (Level 4)

Reviews test results and modifies tests if necessary. Creates reports to communicate methodology, findings and conclusions.

Networking and communities (VURE) (Level 4)

Makes an active contribution to research communities.

Tools and techniques (VURE) (Level 3)

Applies tools, such as disassemblers, debuggers and fuzzers, to the analysis of embedded devices and/or the reverse engineering of hardware or software.

Research activities (VURE) (Level 3)

Applies standard techniques and tools for vulnerability research into new threats, attack vectors, risks and potential solutions.

Reporting (VURE) (Level 3)

Analyses and reports on research activities and results.

Networking and communities (VURE) (Level 3)

Participates in research communities and uses available resources to maintain current knowledge of malware attacks and other cyber security threats.

Job Families

  • IT Operations (47)
    • Application Operations Engineer (6)
    • Infrastructure Engineer (5)
    • Infrastructure Operations Engineer (5)
    • End User Computing Engineer (5)
    • Service Transition Manager (4)
    • IT Service Manager (4)
    • Service Desk Manager (4)
    • Command and Control Centre Manager (4)
    • Business Relationship Manager (3)
    • Change and Release Manager (3)
    • Incident Manager (2)
    • Problem Manager (2)
  • User Centred Design (37)
    • Content Designer (6)
    • Interaction Designer (6)
    • Graphic Designer (6)
    • Service Designer (6)
    • User Researcher (6)
    • Accessibility Specialist (4)
    • Technical Writer (2)
    • Content Strategist (1)
  • Architecture (27)
    • Solutions Architect (5)
    • Technical Architect (5)
    • Enterprise Architect (4)
    • Business Architect (4)
    • Data Architect (3)
    • Security Architect (3)
    • Network Architect (3)
  • Data (25)
    • Data Engineer (5)
    • Data Analyst (5)
    • Analytics Engineer (4)
    • Data Scientist (4)
    • Data Governance Manager (3)
    • Machine Learning Engineer (2)
    • Data Ethicist (2)
  • Software Development (24)
    • Software Developer (9)
    • Development Operations Engineer​​ (9)
    • Frontend ​Developer​ (6)
  • Product and Delivery (21)
    • Business Analyst (6)
    • Product Manager (5)
    • Delivery Manager (4)
    • Digital Portfolio Manager (4)
    • Programme Delivery Manager (1)
    • Service Owner (1)
  • Patient Services (18)
    • Clinical Coder (7)
    • Records and Information Manager​​ (4)
    • Patient Access​ Manager​ (4)
    • Data Quality​ Officer​ (3)
  • Quality Assurance Testing (10)
    • Quality Assurance Testing (QAT) Analyst (4)
    • Test Engineer (4)
    • Test Manager (2)
  • Cyber Security (10)
    • Cyber Security Specialist (Governance Risk and Compliance) (4)
    • Cyber Security Specialist (Operations) (4)
    • Cyber Security Analyst (2)
  • Digital Leadership Roles (9)
    • Chief Technology Officer (1)
    • Chief Information Officer (1)
    • Chief Audit Officer (1)
    • CxIO (1)
    • Chief Information Security Officer (1)
    • Chief Analytics Officer (1)
    • Caldicott Guardian (1)
    • Chief Data Officer (1)
    • Chief Pharmacy Information Officer (1)
  • Knowledge, Library and Information Management (16)
    • Library Manager (11)
      • Digital Systems Librarian (1)
      • Evidence Specialist (1)
      • Patient Information Librarian (1)
      • Primary Care Librarian (1)
      • Apprentice Library Assistant (1)
      • Outreach Librarian (1)
      • Embedded Specialist Librarian (1)
    • Knowledge Manager (4)
    • Information Manager (1)
  • Information Governance (6)
    • Information Governance Officers​ (3)
    • Information Governance Manager​​s (2)
    • Data Protection Officer​​ (1)
  • Digital Education Services (6)
    • Digital Education Specialist (2)
    • Digital Education Manager (2)
    • Digital Education Administration (1)
    • Digital Education Trainer​ (1)
  • Clinical Informatics (3)
    • Clinical Informatician​ (2)
    • Clinical Safety Officer (1)
FEDIP logo

The Federation for Informatics Professionals in Health and Care

Registered in England and Wales No. 10639143

email: info@fedip.org

Copyright © 2026 All Rights Reserved FEDIP | Use of cookies | Legal notices
Registered in England and Wales No. 10639143

website by Sarah Scriven