
Cybersecurity Vulnerability Management Lead
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Lead and enhance the Vulnerability Management capabilities of NSF across enterprise, cloud, containerized, application, and hybrid environments.
• Provide technical guidance to a team of vulnerability analysts.
• Create and maintain a Vulnerability Management roadmap that aligns with evolving threats and organizational priorities.
• Implement and operationalize prioritization using CISA KEV, EPSS, threat intelligence, asset criticality, internet-facing asset identification, attack path analysis, and MITRE ATT&CK mapping.
• Assess emerging technologies for vulnerability validation, attack surface visibility, and exposure management.
• Oversee the discovery, validation, prioritization, remediation coordination, exception handling, verification, and executive reporting processes.
• Manage and optimize Tenable.sc, Tenable.io, and Nessus.
• Enhance scan coverage, credential management, accuracy, and reduction of false positives.
• Integrate findings from AWS Inspector, Security Hub, GuardDuty, Wiz, Prisma Cloud, and Microsoft Defender for Cloud.
• Collaborate with Application Security and DevSecOps teams on AppScan, DAST, SAST, CI/CD integrations, and container image scanning.
• Advance ServiceNow Vulnerability Response and CMDB integrations, including ticketing, SLA tracking, ownership, and escalation workflows.
• Develop automation solutions through APIs, Python, PowerShell, and orchestration capabilities.
• Create executive dashboards and metrics that cover MTTR, SLA adherence, vulnerability aging, exposure trends, scan coverage, and remediation effectiveness.
• Update cybersecurity leadership on emerging risks, remediation progress, and program maturity initiatives.
• Over 8 years of experience in cybersecurity.
• More than 4 years of direct Vulnerability Management experience in a federal or large enterprise setting.
• At least 3 years of experience leading vulnerability analysts, remediation programs, or enterprise VM initiatives.
• Extensive hands-on knowledge of Tenable.sc, Tenable.io, and Nessus.
• Proven experience in implementing or significantly enhancing a Vulnerability Management or Exposure Management capability.
• Familiarity with ServiceNow Vulnerability Response and CMDB integrations.
• Ability to leverage CISA KEV, EPSS, threat intelligence, asset criticality, and attack path analysis.
• Experience supporting AWS, Azure, or hybrid cloud environments.
• Background in collaborating with Security Operations and Incident Response teams to identify and swiftly remediate actively exploited vulnerabilities.
• Experience in briefing technical teams, executives, and federal stakeholders.
• Candidates must meet the pre-employment qualifications set by Cherokee Federal.
• Preferred certifications include CISSP, GCIH, CySA+, Security+, Tenable Certified Professional, AWS Security Specialty, and ServiceNow Vulnerability Response Certification.
• Highly desired experience includes SafeBreach, AttackIQ, Pentera, XM Cyber, Wiz, Prisma Cloud, AppScan, BAS, CCV, EASM, Kubernetes Security, and Detection Engineering.
• Equal opportunity employer.
• Pre-employment qualifications required.
• Opportunity to contribute to a strategic modernization initiative within the NSF Cybersecurity Program.
• A highly visible role with responsibilities in technical leadership.
GardaWorld Federal Services
Foundant Technologies
FRSecure
Synack, Inc.
Get handpicked remote jobs straight to your inbox weekly.