
Cybersecurity Vulnerability Management Lead
Posted Aug 12

Posted Aug 12
This is a fully remote position, open to applicants in United States.
• Spearhead and enhance NSF's Vulnerability Management capabilities across enterprise, cloud, containerized, application, and hybrid settings.
• Provide technical direction to a team of vulnerability analysts.
• Create and uphold a Vulnerability Management roadmap that aligns with shifting threats and organizational priorities.
• Implement and operationalize vulnerability prioritization utilizing CISA KEV, EPSS, threat intelligence, asset criticality, identification of internet-facing assets, attack path analysis, and MITRE ATT&CK mapping.
• Assess and suggest emerging technologies for vulnerability validation, attack surface visibility, and exposure management.
• Oversee discovery, validation, prioritization, remediation coordination, exception handling, verification, and executive reporting.
• Manage and optimize Tenable.sc, Tenable.io, and Nessus.
• Enhance scan coverage, credential management, accuracy, and reduce false positives.
• Integrate results from AWS Inspector, Security Hub, GuardDuty, Wiz, Prisma Cloud, and Microsoft Defender for Cloud.
• Collaborate with Application Security and DevSecOps teams on AppScan, DAST, SAST, CI/CD integrations, and container image scanning.
• Advance ServiceNow Vulnerability Response capabilities, including CMDB enrichment, automated ticket creation, SLA tracking, ownership assignment, and escalation workflows.
• Develop automation using APIs, Python, PowerShell, and orchestration capabilities.
• Create executive dashboards and metrics that cover MTTR, SLA adherence, vulnerability aging, exposure trends, scan coverage, and remediation effectiveness.
• Update cybersecurity leadership on emerging risks, remediation progress, and program maturity initiatives.
• Over 8 years of experience in cybersecurity.
• At least 4 years of direct experience in Vulnerability Management within a federal or large enterprise context.
• More than 3 years of experience leading vulnerability analysts, remediation programs, or enterprise VM initiatives.
• Extensive hands-on expertise with Tenable.sc, Tenable.io, and Nessus.
• Proven track record in implementing or significantly enhancing a Vulnerability Management or Exposure Management capability.
• Familiarity with ServiceNow Vulnerability Response and CMDB integrations.
• Knowledge of CISA KEV, EPSS, threat intelligence, asset criticality, and attack path analysis.
• Experience supporting AWS, Azure, or hybrid cloud environments.
• Ability to work with Security Operations and Incident Response teams to quickly identify and remediate actively exploited vulnerabilities.
• Experience in briefing technical teams, executives, and federal stakeholders.
• Highly desirable skills: SafeBreach, AttackIQ, Pentera, XM Cyber, Wiz, Prisma Cloud, AppScan, BAS, CCV, EASM, Kubernetes Security, and Detection Engineering.
• Preferred certifications include CISSP, GCIH, CySA+, Security+, Tenable Certified Professional, AWS Security Specialty, and ServiceNow Vulnerability Response Certification.
• Must successfully pass pre-employment qualifications set by Cherokee Federal.
• Equal opportunity employer.
• Pre-employment qualifications are required.
• Potential access to government buildings or military installations as part of job requirements.
Agile Defense
Stripe
Guild Mortgage
Cambiar Education
Get handpicked remote jobs straight to your inbox weekly.