Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Management Lead

$125k - $175k

Steampunk

OverviewWe are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT environment supporting more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads, and network infrastructure.The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and system owners to identify, prioritize, and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes, improving automation and reporting capabilities, and ensuring alignment with federal cybersecurity directives, NIST guidance, and organizational security policies.ContributionsLead the enterprise vulnerability management program across servers, workstations, HPC systems, cloud environments, and network devices supporting more than 30,000 managed assets.Plan, coordinate, and oversee enterprise vulnerability scanning, assessment, prioritization, remediation tracking, validation, and reporting activities.Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Develop and maintain risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Drive enterprise remediation activities in alignment with applicable federal directives, including Binding Operational Directive (BOD) 22-01, and organizational security requirements.Develop and enhance enterprise vulnerability management processes, procedures, templates, and operational standards.Design and implement automation solutions that improve vulnerability data collection, remediation tracking, reporting, and operational efficiency.Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction across the enterprise vulnerability management program.Develop and maintain enterprise dashboards, weekly reporting, and executive visualizations utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Identify tool, process, and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program.Ensure vulnerability management activities align with NIST SP 800-53, organizational policies, and applicable federal cybersecurity directives, including BOD 22-01.Develop and maintain vulnerability management documentation, including standard operating procedures (SOPs), remediation guidance, risk mitigation strategies, process improvement plans, and automation roadmaps.Identify opportunities to improve enterprise vulnerability management through process optimization, workflow improvements, enhanced automation, and data quality initiatives.Support continuous monitoring activities and collaborate with stakeholders to strengthen the organization's overall cybersecurity posture.Stay current on emerging vulnerabilities, threat intelligence, federal cybersecurity directives, and industry best practices.QualificationsAbility to obtain and maintain a U.S. government Security Clearance.Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience).Minimum of 5 years of hands-on experience supporting enterprise vulnerability management, cybersecurity operations, and risk remediation workflows.Experience managing enterprise vulnerability management programs across more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads (AWS, Azure, and Google Cloud Platform), and network devices while driving patching and remediation activities in accordance with BOD 22-01.Experience collaborating with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Experience developing and implementing risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction.Experience developing enterprise dashboards, weekly reporting, and operational metrics utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Experience identifying enterprise tool, process, and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans.Experience developing enterprise vulnerability management processes, standard operating procedures, documentation, and continuous process improvement initiatives.Strong knowledge of federal cybersecurity requirements, including NIST SP 800-53 and applicable federal vulnerability management directives.Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders.PreferredExperience supporting cybersecurity programs within a federal government environment.Experience supporting enterprise continuous monitoring initiatives.One or more of the following certifications:CompTIA Security+CISSPCISMCISACCSPOSCPAbout steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $125,000 to $175,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8025Clearance Requirement: Public Trust

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Lead in McLean, VA vacancy
  •  ...Technical Subject Matter Experts (SETA) in Arlington, VA. The successful candidates will lead project management and risk analysis activities. Responsibilities include vulnerability research and providing expert guidance on security practices. The ideal candidates... 
    Suggested

    Blue Sky Innovators

    Arlington, VA
    1 day ago
  •  ...talent, excited to join that effort. To learn more about our exciting organization, please visit us at We are seeking a Vulnerability Management Lead to join our team and support our client. The ideal candidate is a proactive cybersecurity professional with deep... 
    Suggested
    Temporary work
    For contractors
    Work experience placement
    Work at office
    Remote work
    Flexible hours
    2 days per week

    Unissant

    Herndon, VA
    5 days ago
  • AUGUST SCHELL ENTERPRISES, INC. seeks an IT Vulnerability Management Lead / Senior Security Analyst to guide the vulnerability lifecycle in a primarily on-site Bethesda environment. You will coordinate remediation with IT ops, define scanner architectures, and ensure NIH... 
    Suggested

    AUGUST SCHELL ENTERPRISES, INC.

    Bethesda, MD
    1 day ago
  • Peraton is seeking a Vulnerability Management Analyst to support the FAA under the BNATCS contract, delivering cybersecurity and risk management services to protect NAS systems and critical applications. You will identify, analyze, and remediate vulnerabilities using FAA... 
    Suggested
    Remote job
    Contract work

    Peraton

    Bethesda, MD
    1 day ago
  • $100 - $130 per hour

    Job Summary: Our client is seeking a Vulnerability Management Team Lead to join their team! This position is located in Bethesda, Maryland. Duties: Lead and mentor the vulnerability management team, coordinating daily tasks, resources, and priorities Develop and execute... 
    Suggested
    Local area

    KellyMitchell Group

    Bethesda, MD
    1 day ago
  •  ...SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting...  ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination...  ...training certificates, access reviews, vulnerability scans) Assist with internal policy... 
    For contractors
    Remote work

    Paragone Solutions, Inc.

    McLean, VA
    5 days ago
  •  ...looking to fill a part-time position for an Experienced Lead eDiscovery Consultant/ Project Manager for a pending contract award at the Farm Credit...  ...tasks, including but not limited to change management, vulnerability management, records management, privacy, and security... 
    Contract work
    Part time
    For contractors
    Work at office

    MacMore

    McLean, VA
    20 days ago
  •  ...urgently hiring a hands-on Cyber Security Lead to lead and execute the company’s...  ...security strategy, compliance, and risk management requiring hands-on  work. THIS IS A...  ...assessors Conduct risk assessments, vulnerability analysis, and risk mitigation activities... 
    Full time
    Immediate start

    Atlas Management Services LLC

    Arlington, VA
    8 days ago
  •  ...an experienced Cross Domain Solution CDS Program Lead to serve as the technical and programmatic lead for...  ...NCDSMO, NIST, and DOD policies and standards Manage RMF A&A lifecycle for CDS environment Manage vulnerability assessment and penetration testing of the CDS... 
    Remote work
    Flexible hours

    Sedulous Consulting Services LLC

    Arlington, VA
    5 days ago
  •  ...Overview SecurePro is seeking experienced Lead and Senior Information System Security...  ...Moderate information systems, including Risk Management Framework (RMF) and authorization activities, continuous monitoring, vulnerability management, POA&M execution, security... 
    Contract work

    Securepro Inc

    Arlington, VA
    26 days ago
  •  ...Job Description Position: Cybersecurity Lead Clearance: Secret Location:...  ...compliance initiatives for the Project Management Office (PMO) within the Department of Defense...  ...Review and validate remediation plans for vulnerability scans/testing across hosts, networks,... 
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    ADEPT Force Group Incorporated

    Arlington, VA
    26 days ago
  • $85k - $170k

    OverviewWe are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments...  ...develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and... 

    Steampunk

    McLean, VA
    7 days ago
  • $200k

    Cybersecurity & Compliance Lead Position Overview One of our clients is seeking a Cybersecurity...  ...& Compliance Lead to oversee CMMC management and security infrastructure operations....  ...security policies Proactively manage vulnerabilities and conduct real-time log monitoring to... 
    Full time
    Contract work
    For contractors
    Work experience placement
    Second job
    Local area

    10 BTI Solutions, Inc.

    Arlington, VA
    2 days ago
  • $110k - $130k

     ...Description Job Description SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure...  ...upon contract win. SkyePoint Decisions is seeking a Vulnerability Management Lead to join our team supporting the Department of... 
    Contract work
    Remote work

    SkyePoint Decisions

    Washington DC
    19 days ago
  •  ...security, and equity. We are seeking a dynamic and strategic Lead, Supplemental Nutrition Assistance Program (SNAP) to bring their...  ...findings, elevating lessons learned, and amplifying the voices of vulnerable older adults and the organizations that serve them. Positions... 
    Work at office
    Night shift

    National Council on Aging

    Arlington, VA
    1 day ago
  •  ...responsibilities spanning RMF, FISMA, and DoD cybersecurity compliance, vulnerability analysis, and incident response support. Applicants must hold...  ...3 / DCWF certifications. Bachelor’s in CS with 4-7 years in a lead/senior role is required, with strong eMASS experience #J-1880... 

    International Executive Service Corps

    Arlington, VA
    4 days ago
  •  ...an experienced Information Security Systems Officer (ISSO) to lead RMF, ATO, and continuous monitoring for a major federal initiative...  ...NIST 800-53 controls, perform risk assessments, and drive DevSecOps with SIEM and vulnerability tools. #J-18808-Ljbffr 3M HEALTHCARE

    3M HEALTHCARE

    Arlington, VA
    5 days ago
  • $112.8k - $257k

     ...to assess and refine biothreat contingency planning, analyze vulnerabilities, and ensure preparedness against biological hazards in support...  ...solutions that integrate into broader CBRN-defense policies. You’ll lead the creation of research-driven deliverables, guide policy... 
    Local area

    Booz Allen Hamilton

    Arlington, VA
    2 days ago
  •  ...citizenship and an active Top Secret clearance. You will lead auditing efforts in eMASS, manage compliance tasks, and support ATO sustainment while...  ...RMF and security directives. Responsibilities include vulnerability assessments, security audits, incident response support... 

    Po'okela

    Arlington, VA
    5 days ago
  • $140k - $175k

     ...may oversee staff, support performance management and task delegation, help resolve issues...  ...stakeholders while supporting or leading practice, solution, and business development...  ...trends, inconsistencies, and potential vulnerabilities Produces clear, well-supported analyses... 
    Work at office
    Flexible hours

    BDO USA

    Mc Lean, VA
    3 days ago
  • $17 - $27.75 per hour

     ...Ambassador embodying of Coach values and increasing brand awareness * Leads implementation of Company initiatives and support full...  ...Qualifications & Requirements: * 1+ years of equivalent experience in Managing Competitive Retail Space at the Lead Supervisor level * Can... 
    Minimum wage
    Shift work

    Tapestry

    Arlington, VA
    2 days ago
  •  ...Job Description Job Description IT Vulnerability Management Lead / Senior Security Analyst Location: Bethesda, MD (Onsite 3–5 days per week) Employment Type: Full-time The National Library of Medicine (NLM) is seeking an IT Security Compliance Lead /... 
    Full time
    Work experience placement
    Work at office
    3 days per week

    August Schell

    Bethesda, MD
    3 days ago
  • $114.1k - $268.18k

     ...opportunities, a world-class training facility, and leading market tools, we help our people...  ...Specialist, Cloud Security to join our Managed Services practice. Responsibilities:...  ...frameworks Solid experience managing vulnerability management, compliance, exception... 
    Full time
    H1b
    Local area

    KPMG

    Washington DC
    11 days ago
  •  ...performance standards, develop and monitor departmental key performance indicators (KPIs). Communicate department performance to senior management.Identify and assign training needs on an individual basis. Provide continuous coaching of the staff so they perform at the... 
    For contractors

    MultiPlan

    Mc Lean, VA
    5 days ago
  • $39.79 per hour

    DARPA in Arlington, VA is seeking a temporary Mailroom Clerk to manage mail operations at the Defense Advanced Research Projects Agency. The role covers loading/unloading, processing mail, and ensuring adherence to security and postal guidelines. Candidate must hold an... 
    Hourly pay
    Temporary work

    Melwood

    Arlington, VA
    4 days ago
  •  ...Job Description Job Description\n Inova Fairfax Medical Campus - Adult Echo Lab is looking for a dedicated Cardiac Sonographer Lead to join the Inova Fairfax Medical Center Echo Lab is an advanced echo imagining center with a strong emphasis on clinical excellence... 
    Full time
    Remote work
    Relocation package
    Monday to Friday
    Flexible hours
    Day shift

    Inova

    Falls Church, VA
    19 days ago
  • $138.1k - $157.7k

     ...Overview Lead Risk Specialist Are you ready to lead from the front line of...  ...We are seeking highly motivated Risk Management professionals who blend sharp organizational...  ...strategies that identify operational vulnerabilities, drive efficiencies, and focus on automated... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    more than 2 months ago
  •  ...native infrastructure within AWS environments. Build, deploy, and manage containerized applications using Kubernetes and Red Hat...  ...software development practices. Experience with container security, vulnerability management, and compliance frameworks. AWS and/or Red Hat... 

    Bana Solutions

    Mc Lean, VA
    1 day ago
  • $122k - $227k

     ...cyber domains in the interest of national security. Job Title: Lead , Undersea Business Development Job Code: 43670 Job...  ...including working knowledge and experience with the Shipley Capture management process. This position will support the Acoustics and Imaging... 
    For contractors
    Local area
    Flexible hours

    L3Harris Technologies

    Arlington, VA
    10 hours ago
  •  ...Ground Ramp Lead Do you enjoy working in a fast-paced, safety-obsessed aviation environment? The Ground Ramp Lead oversees daily...  ...actions or omissions while at work. Cooperate with their manager/supervisor to allow them to perform or comply with any legal requirements... 
    Full time
    Part time
    Immediate start

    AGI

    Arlington, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Management Lead. Be the first to apply!