Vulnerability Management Team Lead
Cherokee Federal
Vulnerability Management Team Lead
Cherokee-Federal Systems, LLC is seeking an experienced cybersecurity professional to lead a risk-driven vulnerability management program across hybrid on-prem and cloud environments. The ideal candidate will possess deep expertise in infrastructure and security tools, apply critical thinking to identify security gaps, and develop and implement security protocols and risk management improvements. The qualified individual will own discovery, triage, remediation, and reporting of the agency's security posture and lead a small team of cybersecurity analysts to drive measurable reductions in vulnerabilities with Tenable for infrastructure, AppScan for applications, and ServiceNow for workflow and governance. Align operations to FISMA, FedRAMP, and CMMC. Drive measurable reduction in exploitability and clean audit outcomes.
Location: Alexandria, VA (Remote)
Key Responsibilities
- Lead end-to-end vulnerability operations: scanning, validation, prioritization, remediation, exceptions, and verification across on-prem, IaaS/PaaS, and SaaS.
- Operate and optimize Tenable (Nessus/Tenable.sc or Tenable.io) for servers, endpoints, network devices, containers, and cloud assets; maintain credentialed scans, schedules, and coverage for both vulnerabilities and configuration audits.
- Manage AppScan for web and API testing; integrate findings into SDLC and DevSecOps workflows; guide developers with reproducible issues and fix recommendations.
- Continue integration of Tenable, Explore/Implement integration of AppScan with ServiceNow Vulnerability Response:
- Autocreate tickets, enrich with asset data from CMDB, assign ownership by CI/service, and track to closure.
- Maintain risk-based SLAs by asset criticality and threat intel; monitor SLA adherence and escalate aging risk.
- Establish cloud-specific controls:
- Use CSP native scanners and posture tools (e.g., AWS Inspector, Azure Defender/Microsoft Defender for Cloud, GCP Security Command Center) and correlate with Tenable.
- Enforce secure configurations with CIS Benchmarks and cloud guardrails; remediate misconfigurations via IaC changes.
- Prioritize with CVSS, CISA KEV, exploit maturity, and exposure context (internet-facing, privileged paths, high-value assets).
- Govern exceptions: risk acceptance with compensating controls, time-bound approvals, and periodic review.
- Produce executive and compliance reporting: exposure trends, SLA performance, time-to-remediate, patch coverage, POA&Ms, and audit artifacts aligned to FISMA/NIST RMF, FedRAMP, and CMMC.
- Partner with SOC/IR to correlate actively exploited vulnerabilities; enable rapid containment for high-risk findings.
- Coordinate patching windows and change management; champion continuous hardening for Windows/Linux, network, databases, and cloud services.
- Mentor analysts; mature automation, data quality, and process discipline; lead tabletop exercises for patching/vuln scenarios.
Required Qualifications
- 6+ years in cybersecurity with 3+ years leading vulnerability management in hybrid on-prem/cloud environments.
- Hands-on expertise with Tenable (Nessus/Tenable.sc or Tenable.io), AppScan, and ServiceNow Vulnerability Response/CMDB integration.
- Strong grasp of CVE/CVSS, CISA KEV, exploit kits, and modern attack paths; able to translate technical risk to business impact.
- Familiarity with DAST, SAST, CI/CD and Cloud Assessments.
- Proven remediation leadership across Windows/Linux, network devices, containers, and cloud workloads (AWS/Azure/GCP).
- Experience aligning programs to FISMA (NIST View phone number on click.appcast.io RMF), FedRAMP baselines, and CMMC practices.
- Metrics and reporting proficiency: exposure reduction, SLA compliance, MTTR for vulnerabilities, patch cadence, and POA&M management.
- Clear, direct communicator comfortable with executive briefings and cross-functional coordination.
Preferred Qualifications
- Certifications: Security+, CySA +, CISSP, CEH, GCSA, GCPN; Tenable or ServiceNow VR certifications; AppSec certs (GWAPT) a plus.
- Experience integrating Tenable with ServiceNow VR, CMDB, and change management; familiarity with Jira for developer workflows.
- Knowledge of CIS Benchmarks, NIST 80053, 80040 (patch), 80063, FedRAMP PMO guidance, and cloud security patterns.
- Scripting/automation (Python, PowerShell) for data normalization, ticket enrichment, API integrations, and reporting.
Key Competencies
- Accountability and speed under pressure.
- Analytical rigor and validation discipline.
- Operational excellence and automation mindset.
- Crisp communication for technical and executive audiences.
- Collaborative leadership across security, IT ops, cloud, and development.
What Success Looks Like
- Faster time-to-remediate against risk-based SLAs; measurable reduction of critical/high exposure across on-prem and cloud.
- Accurate asset inventory, clean CMDB linkage, and high scan coverage with low false positives.
- Audit-ready evidence with strong POA&M management and clear control effectiveness.
- Executive visibility into vulnerability risk, trends, and remediation velocity.
$100 - $130 per hour
...Job Summary Our client is seeking a Vulnerability Management Team Lead to join their team. This position is located in Bethesda, Maryland. Responsibilities Lead and mentor the vulnerability management team, coordinating daily tasks, resources, and priorities Develop and...SuggestedHourly payLocal area- ...Gritter Francona is looking for a Vulnerability Assessment Team Lead to support a potential project with the Department of Homeland Security. The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection...SuggestedTemporary work
- ...SOC Vulnerability Management Team Lead - Senior ECS is seeking a SOC Vulnerability Management Team Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this Task 3 role, the selected candidate...SuggestedContract work
- ...Vulnerability Management Team Lead Bethesda, MD Require employee(s) performing vulnerability management functions possess demonstrable credentials to reflect knowledge, skills, and experience: Coordinating teams, utilizing vulnerability scanning tools, and developing...Suggested
- KellyMitchell Group is seeking a Vulnerability Management Team Lead in Bethesda, Maryland. In this role, you will lead a team to develop and execute a comprehensive vulnerability management program, overseeing daily operations and coordinating with various stakeholders...Suggested
- ...SOC Vulnerability Management AESS Lead - Senior ECS is seeking a SOC Vulnerability Management AESS Lead - Senior to support the Army National Guard... ...owners, endpoint administrators, and other cybersecurity teams to strengthen defensive cyberspace operations and...Contract work
$70 - $75 per hour
...Akraya, Inc. is seeking an experienced Vulnerability Management professional based in San Jose, CA. The... ...will manage vulnerability backlogs and lead security efforts during incidents while... ...collaborating with engineering product teams. This role requires effective communication...Hourly payRemote work- ...Job Description Qualifications Key Responsibilities 1. Vulnerability Inventory & Baseline Establishment Review existing... ...compensation, opportunities for professional growth, and a supportive team culture. All your information will be kept confidential...Remote work
- ...Full-Time/Part-Time Full-Time Description RiVidium is seeking a Vulnerability Management Lead to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core...Full timeContract workPart time
- ...Everforth ECS is seeking a Product Manager SME to work in the National Capital Region... ...analysts. • This role directs enterprise vulnerability assessment operations using the Assured... ..., network engineers, and cybersecurity teams using ServiceNow, Jira, and SharePoint to...Contract work
$141.3k - $211.9k
...future-you'll create it. As a Technology Risk: Vulnerability Management & Application Security Domain Lead, you will be responsible for overseeing the end-to-... ...pivotal role collaborates closely with the respective teams, with a particular emphasis on application security...Full timeTemporary workWork experience placementWork at officeLocal areaRelocation$100k - $300k
.... Cogent was founded by a seasoned team of former engineering and product leaders... ...and machine learning talent from leading companies such as Abnormal Security, Coinbase... ...security engineering ~ Expertise in vulnerability management across the attack surface ~ Fluency...Remote work$170.9k - $241.4k
...A leading e-signature and contract lifecycle management company in Chicago seeks a Technical Leader for their Cloud & Infrastructure Security team. This highly strategic role involves defining security programs, driving vulnerability management, and influencing various...Contract work- ...Job Title: Vulnerability Management & Remediation Lead Location: Remote (Anywhere in the US; Texas-based preferred) Job Type: Contract (3 Months / 560 Hours) Duration: 05/26/26 - 08/31/26 Interview Mode: Video Role Overview: This role...Contract workRemote work
- ...SOC Vulnerability Management ACAS Lead - Senior ECS is seeking a SOC Vulnerability Management ACAS Lead - Senior to support the Army National Guard... ...works closely with SOC, compliance, RMF, and engineering teams to identify risk, prioritize remediation, and strengthen...Contract work
$78.75 - $113.75 per hour
...TS SCI W/ CI Poly Cleared Vulnerability/GRC Lead Our client, a leader in the HCM space is in need... ...security, compliance, and risk management initiatives. The Lead will be responsible... ...with internal engineering and security teams to support secure product development...Hourly payContract work- ...A cybersecurity solutions provider is seeking a Vulnerability Assessment (VA) Team Lead to oversee security assessments and penetration testing. The ideal candidate will have a Bachelor's Degree and at least 5 years of experience in vulnerability assessments, leadership...
- ...MUST HAVE STATE CLIENT EXPEIRENCE Job ID : 70126090 Role: Vulnerability Management & Remediation Coordination Lead Location: 100% Remote, Work Location With-in the United States. Contract role Job description: Vulnerability...Contract workRemote work
- ...Enterprise Vulnerability Management Lead SME Everforth ECS is seeking an Enterprise Vulnerability Management Lead SME to work in the National... ...with system owners, platform engineers, and cybersecurity teams. • Maintains authoritative vulnerability records and remediation...
- ...candidate will engage in critical cybersecurity projects involving vulnerability research, software development, and advanced systems analysis.... ..., along with an active Top Secret Clearance. Join our dynamic team and contribute to national security efforts. #J-18808-Ljbffr...
- Leidos has a career opportunity for an ISSO Vulnerability Management in Bethesda, Maryland. The role involves managing the vulnerability management process and analyzing scan results to ensure cybersecurity compliance. Candidates must have an active DoD Secret clearance...
- A major cruise line company in Miami is seeking a Senior Vulnerability Management Analyst to enhance its cybersecurity posture. The successful... ...skills, and the ability to work collaboratively with diverse teams. This position involves generating KPIs, conducting...Work at office
- LexisNexis Risk Solutions is looking for a Security & Risk Management Program Manager in Horsham, PA to lead the vulnerability management program. You will manage cross-functional risk initiatives, enhance security practices, and ensure audit readiness. The ideal candidate...
- ...society, while generating value for our customers, investors, and society. Come Join an Inclusive Team This role will design and maintain cybersecurity vulnerability management tools. This will include operational, analytic, and forensic tools, as well as their supporting...Work experience placementWork at officeLocal areaRemote workHome office2 days per week
- A leading cruise company in Miami is hiring a Senior Vulnerability Management Analyst. This role requires assessing vulnerabilities across IT infrastructure and requires... ...ideal candidate will collaborate with various teams and generate critical reports to enhance security...Work at office
- A leading defense technology company is seeking a Senior Manager for Enterprise Vulnerability Management in Fort Worth, TX. This role requires a strategic leader to develop and execute... ...experience in information security, team management, and vulnerability tools. Benefits...Flexible hours
- Osaic is seeking a Senior Vulnerability Management Analyst to lead and mature vulnerability programs across SDLC, external attack surface, and internal... ...lifecycle management, coordinating closely with various teams including Engineering and IT. The ideal candidate will...
- A leading chemical company in Houston is looking for a Cybersecurity professional to design and maintain vulnerability management tools. The candidate will perform threat analysis, risk assessments, and maintain security measures. A Bachelor’s degree in Cybersecurity is...Remote jobFlexible hours
- Bank of America is seeking a skilled Cloud Security Vulnerability Management Program Specialist in Chicago, Illinois, focused on ensuring secure... ...include identifying vulnerabilities and working with teams to support the security posture of enterprise cloud environments...
$116.26k - $151.13k
...Service Corporation is looking for a dedicated cybersecurity professional to lead the Vulnerability Dispositioning team in Columbus, Ohio. You will be responsible for overseeing vulnerability management, working closely with business units to develop actionable remediation...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Team Lead. Be the first to apply!
- training team manager United States
- training team lead United States
- marketing team manager United States
- healthcare team leader United States
- clinical team leader United States
- application team lead United States
- remote team lead United States
- group strategy director United States
- team supervisor United States
- team coordinator United States

