Cybersecurity Vulnerability Management Lead

Posted Aug 12

This is a fully remote position, open to applicants in United States.

📋 Description

• Spearhead and enhance NSF's Vulnerability Management capabilities across enterprise, cloud, containerized, application, and hybrid settings.

• Provide technical direction to a team of vulnerability analysts.

• Create and uphold a Vulnerability Management roadmap that aligns with shifting threats and organizational priorities.

• Implement and operationalize vulnerability prioritization utilizing CISA KEV, EPSS, threat intelligence, asset criticality, identification of internet-facing assets, attack path analysis, and MITRE ATT&CK mapping.

• Assess and suggest emerging technologies for vulnerability validation, attack surface visibility, and exposure management.

• Oversee discovery, validation, prioritization, remediation coordination, exception handling, verification, and executive reporting.

• Manage and optimize Tenable.sc, Tenable.io, and Nessus.

• Enhance scan coverage, credential management, accuracy, and reduce false positives.

• Integrate results from AWS Inspector, Security Hub, GuardDuty, Wiz, Prisma Cloud, and Microsoft Defender for Cloud.

• Collaborate with Application Security and DevSecOps teams on AppScan, DAST, SAST, CI/CD integrations, and container image scanning.

• Advance ServiceNow Vulnerability Response capabilities, including CMDB enrichment, automated ticket creation, SLA tracking, ownership assignment, and escalation workflows.

• Develop automation using APIs, Python, PowerShell, and orchestration capabilities.

• Create executive dashboards and metrics that cover MTTR, SLA adherence, vulnerability aging, exposure trends, scan coverage, and remediation effectiveness.

• Update cybersecurity leadership on emerging risks, remediation progress, and program maturity initiatives.


⛳️ Requirements

• Over 8 years of experience in cybersecurity.

• At least 4 years of direct experience in Vulnerability Management within a federal or large enterprise context.

• More than 3 years of experience leading vulnerability analysts, remediation programs, or enterprise VM initiatives.

• Extensive hands-on expertise with Tenable.sc, Tenable.io, and Nessus.

• Proven track record in implementing or significantly enhancing a Vulnerability Management or Exposure Management capability.

• Familiarity with ServiceNow Vulnerability Response and CMDB integrations.

• Knowledge of CISA KEV, EPSS, threat intelligence, asset criticality, and attack path analysis.

• Experience supporting AWS, Azure, or hybrid cloud environments.

• Ability to work with Security Operations and Incident Response teams to quickly identify and remediate actively exploited vulnerabilities.

• Experience in briefing technical teams, executives, and federal stakeholders.

• Highly desirable skills: SafeBreach, AttackIQ, Pentera, XM Cyber, Wiz, Prisma Cloud, AppScan, BAS, CCV, EASM, Kubernetes Security, and Detection Engineering.

• Preferred certifications include CISSP, GCIH, CySA+, Security+, Tenable Certified Professional, AWS Security Specialty, and ServiceNow Vulnerability Response Certification.

• Must successfully pass pre-employment qualifications set by Cherokee Federal.


🏝️ Benefits

• Equal opportunity employer.

• Pre-employment qualifications are required.

• Potential access to government buildings or military installations as part of job requirements.

People also viewed

Agile Defense7 hours ago

Senior Security Architect

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer$150k – $155k/year
ApplyView job
Stripe8 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Guild Mortgage9 hours ago

Third-Party Security Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$94.9k – $136.1k/year
ApplyView job
Cambiar Education12 hours ago

Director, IT – Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$140k – $170k/year
ApplyView job
Docker, Inc12 hours ago

Senior Security Engineer – Offensive Security

GB flagUnited Kingdom, +4 more countriesFull-timeCybersecurity / Security Engineer€118.9k – €169.8k/year
ApplyView job
OpenZeppelin12 hours ago

Head of Information Security

Anywhere in the WorldFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers