Vulnerability Management Lead
$125k - $175kSteampunk
OverviewWe are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT environment supporting more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads, and network infrastructure.The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and system owners to identify, prioritize, and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes, improving automation and reporting capabilities, and ensuring alignment with federal cybersecurity directives, NIST guidance, and organizational security policies.ContributionsLead the enterprise vulnerability management program across servers, workstations, HPC systems, cloud environments, and network devices supporting more than 30,000 managed assets.Plan, coordinate, and oversee enterprise vulnerability scanning, assessment, prioritization, remediation tracking, validation, and reporting activities.Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Develop and maintain risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Drive enterprise remediation activities in alignment with applicable federal directives, including Binding Operational Directive (BOD) 22-01, and organizational security requirements.Develop and enhance enterprise vulnerability management processes, procedures, templates, and operational standards.Design and implement automation solutions that improve vulnerability data collection, remediation tracking, reporting, and operational efficiency.Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction across the enterprise vulnerability management program.Develop and maintain enterprise dashboards, weekly reporting, and executive visualizations utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Identify tool, process, and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program.Ensure vulnerability management activities align with NIST SP 800-53, organizational policies, and applicable federal cybersecurity directives, including BOD 22-01.Develop and maintain vulnerability management documentation, including standard operating procedures (SOPs), remediation guidance, risk mitigation strategies, process improvement plans, and automation roadmaps.Identify opportunities to improve enterprise vulnerability management through process optimization, workflow improvements, enhanced automation, and data quality initiatives.Support continuous monitoring activities and collaborate with stakeholders to strengthen the organization's overall cybersecurity posture.Stay current on emerging vulnerabilities, threat intelligence, federal cybersecurity directives, and industry best practices.QualificationsAbility to obtain and maintain a U.S. government Security Clearance.Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience).Minimum of 5 years of hands-on experience supporting enterprise vulnerability management, cybersecurity operations, and risk remediation workflows.Experience managing enterprise vulnerability management programs across more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads (AWS, Azure, and Google Cloud Platform), and network devices while driving patching and remediation activities in accordance with BOD 22-01.Experience collaborating with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Experience developing and implementing risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction.Experience developing enterprise dashboards, weekly reporting, and operational metrics utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Experience identifying enterprise tool, process, and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans.Experience developing enterprise vulnerability management processes, standard operating procedures, documentation, and continuous process improvement initiatives.Strong knowledge of federal cybersecurity requirements, including NIST SP 800-53 and applicable federal vulnerability management directives.Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders.PreferredExperience supporting cybersecurity programs within a federal government environment.Experience supporting enterprise continuous monitoring initiatives.One or more of the following certifications:CompTIA Security+CISSPCISMCISACCSPOSCPAbout steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $125,000 to $175,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8025Clearance Requirement: Public Trust
- ...Technical Subject Matter Experts (SETA) in Arlington, VA. The successful candidates will lead project management and risk analysis activities. Responsibilities include vulnerability research and providing expert guidance on security practices. The ideal candidates...Suggested
- ...talent, excited to join that effort. To learn more about our exciting organization, please visit us at We are seeking a Vulnerability Management Lead to join our team and support our client. The ideal candidate is a proactive cybersecurity professional with deep...SuggestedTemporary workFor contractorsWork experience placementWork at officeRemote workFlexible hours2 days per week
- AUGUST SCHELL ENTERPRISES, INC. seeks an IT Vulnerability Management Lead / Senior Security Analyst to guide the vulnerability lifecycle in a primarily on-site Bethesda environment. You will coordinate remediation with IT ops, define scanner architectures, and ensure NIH...Suggested
- Peraton is seeking a Vulnerability Management Analyst to support the FAA under the BNATCS contract, delivering cybersecurity and risk management services to protect NAS systems and critical applications. You will identify, analyze, and remediate vulnerabilities using FAA...SuggestedRemote jobContract work
$100 - $130 per hour
Job Summary: Our client is seeking a Vulnerability Management Team Lead to join their team! This position is located in Bethesda, Maryland. Duties: Lead and mentor the vulnerability management team, coordinating daily tasks, resources, and priorities Develop and execute...SuggestedLocal area- ...SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting... ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination... ...training certificates, access reviews, vulnerability scans) Assist with internal policy...For contractorsRemote work
- ...looking to fill a part-time position for an Experienced Lead eDiscovery Consultant/ Project Manager for a pending contract award at the Farm Credit... ...tasks, including but not limited to change management, vulnerability management, records management, privacy, and security...Contract workPart timeFor contractorsWork at office
- ...urgently hiring a hands-on Cyber Security Lead to lead and execute the company’s... ...security strategy, compliance, and risk management requiring hands-on work. THIS IS A... ...assessors Conduct risk assessments, vulnerability analysis, and risk mitigation activities...Full timeImmediate start
- ...an experienced Cross Domain Solution CDS Program Lead to serve as the technical and programmatic lead for... ...NCDSMO, NIST, and DOD policies and standards Manage RMF A&A lifecycle for CDS environment Manage vulnerability assessment and penetration testing of the CDS...Remote workFlexible hours
- ...Overview SecurePro is seeking experienced Lead and Senior Information System Security... ...Moderate information systems, including Risk Management Framework (RMF) and authorization activities, continuous monitoring, vulnerability management, POA&M execution, security...Contract work
- ...Job Description Position: Cybersecurity Lead Clearance: Secret Location:... ...compliance initiatives for the Project Management Office (PMO) within the Department of Defense... ...Review and validate remediation plans for vulnerability scans/testing across hosts, networks,...Full timeTemporary workWork at officeRemote workFlexible hours
$85k - $170k
OverviewWe are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments... ...develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and...$200k
Cybersecurity & Compliance Lead Position Overview One of our clients is seeking a Cybersecurity... ...& Compliance Lead to oversee CMMC management and security infrastructure operations.... ...security policies Proactively manage vulnerabilities and conduct real-time log monitoring to...Full timeContract workFor contractorsWork experience placementSecond jobLocal area$110k - $130k
...Description Job Description SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure... ...upon contract win. SkyePoint Decisions is seeking a Vulnerability Management Lead to join our team supporting the Department of...Contract workRemote work- ...security, and equity. We are seeking a dynamic and strategic Lead, Supplemental Nutrition Assistance Program (SNAP) to bring their... ...findings, elevating lessons learned, and amplifying the voices of vulnerable older adults and the organizations that serve them. Positions...Work at officeNight shift
- ...responsibilities spanning RMF, FISMA, and DoD cybersecurity compliance, vulnerability analysis, and incident response support. Applicants must hold... ...3 / DCWF certifications. Bachelor’s in CS with 4-7 years in a lead/senior role is required, with strong eMASS experience #J-1880...
- ...an experienced Information Security Systems Officer (ISSO) to lead RMF, ATO, and continuous monitoring for a major federal initiative... ...NIST 800-53 controls, perform risk assessments, and drive DevSecOps with SIEM and vulnerability tools. #J-18808-Ljbffr 3M HEALTHCARE
$112.8k - $257k
...to assess and refine biothreat contingency planning, analyze vulnerabilities, and ensure preparedness against biological hazards in support... ...solutions that integrate into broader CBRN-defense policies. You’ll lead the creation of research-driven deliverables, guide policy...Local area- ...citizenship and an active Top Secret clearance. You will lead auditing efforts in eMASS, manage compliance tasks, and support ATO sustainment while... ...RMF and security directives. Responsibilities include vulnerability assessments, security audits, incident response support...
$140k - $175k
...may oversee staff, support performance management and task delegation, help resolve issues... ...stakeholders while supporting or leading practice, solution, and business development... ...trends, inconsistencies, and potential vulnerabilities Produces clear, well-supported analyses...Work at officeFlexible hours$17 - $27.75 per hour
...Ambassador embodying of Coach values and increasing brand awareness * Leads implementation of Company initiatives and support full... ...Qualifications & Requirements: * 1+ years of equivalent experience in Managing Competitive Retail Space at the Lead Supervisor level * Can...Minimum wageShift work- ...Job Description Job Description IT Vulnerability Management Lead / Senior Security Analyst Location: Bethesda, MD (Onsite 3–5 days per week) Employment Type: Full-time The National Library of Medicine (NLM) is seeking an IT Security Compliance Lead /...Full timeWork experience placementWork at office3 days per week
$114.1k - $268.18k
...opportunities, a world-class training facility, and leading market tools, we help our people... ...Specialist, Cloud Security to join our Managed Services practice. Responsibilities:... ...frameworks Solid experience managing vulnerability management, compliance, exception...Full timeH1bLocal area- ...performance standards, develop and monitor departmental key performance indicators (KPIs). Communicate department performance to senior management.Identify and assign training needs on an individual basis. Provide continuous coaching of the staff so they perform at the...For contractors
$39.79 per hour
DARPA in Arlington, VA is seeking a temporary Mailroom Clerk to manage mail operations at the Defense Advanced Research Projects Agency. The role covers loading/unloading, processing mail, and ensuring adherence to security and postal guidelines. Candidate must hold an...Hourly payTemporary work- ...Job Description Job Description\n Inova Fairfax Medical Campus - Adult Echo Lab is looking for a dedicated Cardiac Sonographer Lead to join the Inova Fairfax Medical Center Echo Lab is an advanced echo imagining center with a strong emphasis on clinical excellence...Full timeRemote workRelocation packageMonday to FridayFlexible hoursDay shift
$138.1k - $157.7k
...Overview Lead Risk Specialist Are you ready to lead from the front line of... ...We are seeking highly motivated Risk Management professionals who blend sharp organizational... ...strategies that identify operational vulnerabilities, drive efficiencies, and focus on automated...Full timePart timeLocal area- ...native infrastructure within AWS environments. Build, deploy, and manage containerized applications using Kubernetes and Red Hat... ...software development practices. Experience with container security, vulnerability management, and compliance frameworks. AWS and/or Red Hat...
$122k - $227k
...cyber domains in the interest of national security. Job Title: Lead , Undersea Business Development Job Code: 43670 Job... ...including working knowledge and experience with the Shipley Capture management process. This position will support the Acoustics and Imaging...For contractorsLocal areaFlexible hours- ...Ground Ramp Lead Do you enjoy working in a fast-paced, safety-obsessed aviation environment? The Ground Ramp Lead oversees daily... ...actions or omissions while at work. Cooperate with their manager/supervisor to allow them to perform or comply with any legal requirements...Full timePart timeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Lead. Be the first to apply!
- vice president program management McLean, VA
- senior director product management McLean, VA
- internship event management company McLean, VA
- vp product management McLean, VA
- director of inventory management McLean, VA
- events management graduate McLean, VA
- director change management McLean, VA
- behavior management McLean, VA
- identity management McLean, VA
- management development program McLean, VA





