IT Vulnerability Management Lead / Senior Security Analyst
Full-time
August Schell
IT Vulnerability Management Lead / Senior Security Analyst Location: Bethesda, MD (Onsite 3–5 days per week)
Employment Type: Full-time The National Library of Medicine (NLM) is seeking an IT Security Compliance Lead / Senior Security Analyst to join our security compliance team. In this role, you will work closely with the NLM Information Systems Security Officer (ISSO) and play a critical part in safeguarding NLM’s IT infrastructure. You will be part of a broader IT program that provides end-to-end support—including help desk, systems, network, incident response and security services—ensuring the availability, integrity, and confidentiality of mission-critical systems. This position is based at our client’s office in Bethesda, MD and requires onsite presence 3 to 5 days per week . Responsibilities:
Employment Type: Full-time The National Library of Medicine (NLM) is seeking an IT Security Compliance Lead / Senior Security Analyst to join our security compliance team. In this role, you will work closely with the NLM Information Systems Security Officer (ISSO) and play a critical part in safeguarding NLM’s IT infrastructure. You will be part of a broader IT program that provides end-to-end support—including help desk, systems, network, incident response and security services—ensuring the availability, integrity, and confidentiality of mission-critical systems. This position is based at our client’s office in Bethesda, MD and requires onsite presence 3 to 5 days per week . Responsibilities:
- Lead the agency’s vulnerability management lifecycle using Tenable.sc, Tenable.io, Nessus Manager, and Nessus scanners (on-prem and cloud)
- Analyze, prioritize, and track remediation of vulnerabilities in coordination with IT operations and system owners in a hybrid environment
- Maintain scan schedules, asset groups, scan policies dashboards, repositories, and reports tailored to agency infrastructure and communicate risk posture and remediation progress to relevant infrastructure and application teams to remediate vulnerabilities
- Define the scanner and security center architecture, refine data flows, tune scanning configurations, synchronizations to minimize false positives and ensure the best coverage
- Develop and maintain documentation for system setup, operation, vulnerability management processes, exceptions, and remediation tracking
- Support implementation of security projects that require compliance with relevant government policies or standards
- Be the SME (subject matter expert) for vulnerability management tools and processes updating processes and monitoring to meet NIH mandates
- Ensure systems and practices comply with FISMA and FedRAMP related Security Assessment and Authorization (SA&A) and compliance for NLM IT programs
- Assist NLM in coordination, implementation, communication, and enforcement of the NIH IT security policies
- Support NLM’s incident response workflow and coordinate with NIH teams
- Expert knowledge of IT security vulnerabilities and risk assessments with a proven ability to translate complex technical risks into clear, actionable business impacts for executives and technical teams
- Strong knowledge of vulnerability management lifecycle, patch management processes, and risk scoring (e.g., CVSS2) models in federal workspace
- Familiarity with securing cloud platforms (AWS and GCP) and hybrid environments
- Understanding of Windows, Linux/Unix, and network devices security hardening
- Ability to work with program staff, executives, security application vendors and technology staff to achieve IT security goals and objectives
- Direct and manage enterprise-class Vulnerability Management (VM) platforms (e.g., Tenable/Nessus) to ensure comprehensive asset discovery, repository management accurate scanning, and robust reporting.
- Excellent working experience in applying FISMA, and FedRAMP processes and policies, maintaining Assessment and Authorization documentation for large federal IT systems
- Skilled at bridging gaps between program staff, executives, technology teams, and external security vendors to successfully achieve organizational security objectives with a demonstrated ability to align technical, security, and business stakeholders across the organization
- 5–7 years of progressive experience in IT security, with specialized focus of at least 3 years in vulnerability management and platforms
- Bachelor’s degree in computer science, cybersecurity, information technology, or related technical field (or equivalent practical experience)
- Certifications: CISSP (or ability to obtain within 6 months)
- Experience with scripting and automation (e.g., Python, PowerShell) to automate scanning tasks, reporting, and API integrations; administration and operation of security scanning and vulnerability management platforms such as Nessus
- Deep expertise with SIEM platforms and integration of vulnerability data into enterprise monitoring
- Understanding of the Secure Software Development Life Cycle
- Master’s degree or additional security or cloud certifications (e.g., CISM)
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the IT Vulnerability Management Lead / Senior Security Analyst in Bethesda, MD vacancy
$108k - $140k
...Aspicio, you can join a leading consulting firm... ..., data analytics, management, and strategy... ...and our homeland security and Government clients... ...team.The Senior Information Security Compliance Analyst (Federal Programs)... ...areas of potential vulnerability in systems and infrastructure...SeniorContract workLive inWork at officeRemote workFlexible hours- ...cloud engineering, data management, cybersecurity and emerging... .... We build the right IT solution for government clients... ....com/careers . The Senior Information Security Analyst will perform the core... ...software/hardware updates, vulnerability remediation, and secure configurations...SeniorFull timeStart working todayFlexible hours
- DescriptionSAIC is looking for a Senior Information Systems Security Analyst to join our team... ...a team responsible for IT Security Risk and Compliance... ...Officer (ISSPO) in managing and documenting the ongoing... ..., such as OWASP Top 10 vulnerabilities.Knowledge of cloud...SeniorWork at office2 days per week
- AUGUST SCHELL ENTERPRISES, INC. seeks an IT Vulnerability Management Lead / Senior Security Analyst to guide the vulnerability lifecycle in a primarily on-site Bethesda environment. You will coordinate remediation with IT ops, define scanner architectures, and ensure NIH...Senior
- Peraton is seeking a Vulnerability Management Analyst to support the FAA under the BNATCS contract, delivering cybersecurity and risk management services to protect NAS systems and critical applications. You will identify, analyze, and remediate vulnerabilities using FAA...SeniorRemote jobContract work
- ...Seeking a Senior Security Test & Evaluation Analyst with strong experience in security testing, vulnerability assessment, ethical hacking, and AI-enabled security testing. The ideal candidate will combine traditional security assessment expertise with hands-on experience...SeniorTemporary work
$98.84k - $148.26k
...Washington residents secure health insurance... ...potential.\n SUMMARY\n The Senior Application Security Analyst plays a key role in... ...Security Lead, this role serves as... ...DevOps, architects, IT, and external partners... ...modeling, and vulnerability management, while supporting risk...SeniorContract workWork at officeImmediate startRemote workMonday to FridayShift work- Security Administration and Operations This team is tasked with providing... ...and security configuration management to the enterprise. Security... ...to Risk management and IT Security Audit teams... ...understanding of malware, threats, vulnerabilities, and the complete affect these...Remote jobWeekend workAfternoon shift
$85k - $202k
The Information Security Analyst will support the design, implementation, and management of cybersecurity controls and processes for... ...conduct security risk and vulnerability assessments, evaluate and test... ...SecurityX/CASP+ certification (for Senior role) We are actively...Full timeContract workTemporary workWork at officeVisa sponsorshipWork visa- ...DescriptionProSidian is a Management and Operations... ...solutions based on industry leading practices. ProSidian... ...Compliance, Business Process, IT Effectiveness, Energy... ...’s Mortgage Backed Securities (MBS) programs help to... ...demand. Financial analysts provide this information...SeniorFull timeFor contractorsBank staffInternshipWork at office
$84k - $140k
...level Data Scientist with a strong background in data management, visualization, and reporting related to security assistance accounts and interagency coordination.... ...value.ResponsibilitiesServes as the principal analyst and integrator for data management, visualization,...Contract work- ...DescriptionProSidian is a Management And Operations... ...solutions based on industry-leading practices. ProSidian... ...| Business Process | IT Effectiveness | Engineering... ...Seeks a Information Security Analyst (FISMA/NIST) | Human... ...Region and listed under a Senior Consultant Labor...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- Blu Omega LLC is seeking a Senior System Security Analyst to support NIH Cybersecurity Operations within a fully remote environment. The role focuses... ...risk assessments, incident detection, and collaboration with IT and security teams to embed best practices across cloud and...SeniorRemote job
- ...Technology & Processes, LLC is seeking a Senior Cybersecurity Analyst to drive RMF lifecycle execution... ...in Washington, DC. You will lead Security Authorization Package coordination... ...decisions. In this role you will manage vulnerability scans, control assessments, continuous...Senior
- ...Compensation: $50.88/HR on W2 Security Clearance: Ability to... ...) Responsibilities Lead enterprise anti-virus... ...corrective actions. Manage and optimize enterprise... ...issues, providing senior-level support. Coordinate... ...Security Operations Analyst (preferred). System...SeniorContract workLocal area
- ...commercial and federal sectors ranging from Asset Management to IT Services. CDO employees demonstrate integrity, embrace... ...in the delivery of superior customer service. Senior Security Governance and Policy Analyst The Senior Security Governance and Policy...SeniorFull timeTemporary workFlexible hoursNight shift
$145k - $192.5k
...grow, and make an impact. Join us!The Sr. Cloud Security Analyst is responsible for designing, implementing, and managing security controls across multi-cloud... ...currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and...SeniorFull timeWork at officeFlexible hoursDay shift- ...Job Description Who is Saliense? Saliense is a growing Management and Technology Consulting Solutions provider based out of Mclean... ...Saliense has a new opportunity for an Information Security Analyst to support the U.S. Marshals in Arlington, VA. This...Immediate start2 days per week
- Information Security Analyst Saliense is a growing Management and Technology Consulting Solutions provider based out of Mclean, VA. We work to solve our client's toughest challenges within the Defense, Civilian, Financial, and Healthcare industries. Our diverse employees...Local area2 days per week
$229.9k - $262.4k
...Overview Senior Lead, Information Security Office Consultant At Capital One, you... ...Information Security and Risk Management. You are pragmatic and... ...including upper management, IT leaders, and technology... ...Security, Threat Modeling, or Vulnerability Management ~5+ years of...SeniorFull timePart timeH1bWork at officeLocal areaShift work- DescriptionPersonnel Security Analyst / Adjudicator - SeniorThe Senior Security Analyst is a subject matter expert who independently applies ICD... .... Requiring rare guidance from Senior Case Managers, the Senior Analyst leads by example in production, data integrity, and...Senior
$107.9k - $195.05k
The C5ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber... ...threat detection, incident response, and vulnerability management across cloud and on-premises... ...for an experienced Endpoint Security Analyst to support a highly visible, strategic...Full timeImmediate start$104k - $166k
Responsibilities The Vulnerability Management Analyst will support the Federal Aviation... ...ensuring compliance with federal security requirements, and... ...cybersecurity operations, or IT security. Cybersecurity, IT... ...the galaxy. As the world’s leading mission capability integrator...SeniorContract workLocal areaRemote workShift work- ...skills strengthen national security, cybersecurity, health,... ...at our core, we lead federally funded research... ...Insights: Work closely with IT and OT engineers,... ...briefings, graphics) for senior leaders.Basic QualificationsTypically... ....Familiarity with vulnerability...InternshipLocal area
$140k
DescriptionInformation Security Analyst III - Q Clearance RequiredSummary:We are seeking an... ...Authorization (SA&A), NIST security frameworks, vulnerability management, incident response, cloud security,... ...ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong...$131.3k - $237.35k
...Leidos is looking to add a Senior System Administrator Team Lead. Our mission is to develop... ...the existing systems are secure and performing as intended... ...Primary Responsibilities:Manage tasks and sub-task assignments... ...'s mission-critical IT systems and managing the team...SeniorFull timeWork at office$245k
DescriptionSenior IT Architect (Team Lead) - Q Clearance RequiredSummary:We are seeking a Senior IT Architect (Team Lead) to serve as a... ...requirements, technical standards, security requirements, quality... ...customers, technical teams, management, and other stakeholders to evaluate...Senior- ...Job Description Job Description IT Cloud Security Analyst Location: Bethesda, MD (Onsite 3–5 days per week) Employment Type... ...implementation including Identity Access, Privileged access, Vulnerability management, Configuration compliance, encryption, and centralized...Full timeWork experience placement3 days per week
- ...Network Security Analyst We are looking for a detail-oriented and proactive Network Security Analyst to join our cybersecurity team... ...organization's network infrastructure against potential threats and vulnerabilities. You will be responsible for identifying security risks,...Temporary workFor contractorsImmediate startFlexible hours
- Deployed Global Solutions, LLC is seeking a Proposal Manager in Alexandria, VA to lead the full lifecycle of federal proposals. The role focuses on technical... ...communication, organizational skills, and experience in IT, construction, or manufacturing proposals. #J-18808-...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Vulnerability Management Lead / Senior Security Analyst. Be the first to apply!
Related searches
- business analyst law firm Bethesda, MD
- public sector business analyst Bethesda, MD
- records management analyst Bethesda, MD
- salesforce business analyst - remote Bethesda, MD
- management analyst Bethesda, MD
- senior business analyst contract Bethesda, MD
- fiserv business analyst Bethesda, MD
- configuration management analyst Bethesda, MD
- business analyst healthcare Bethesda, MD
- business development analyst Bethesda, MD


