Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Management Lead, Top Secret

Gdit

Public Trust: None
Requisition Type: Regular
Your Impact

Own your opportunity to serve as a critical component of our nation’s safety and security. Make an impact by using your expertise to protect our country from threats.

Job Description

Position Summary

The Vulnerability Management Lead oversees teams that delivers comprehensive, standards‑aligned security assessments and validation services across cloud, operational technology OT, industrial control systems (ICS), and enterprise environments identifying vulnerabilities, evaluating control effectiveness, and measuring readiness to strengthen the cybersecurity posture of government and commercial information systems. The successful lead directs tailored test plans (e.g., vulnerability assessments, penetration testing, SOC evaluations, phishing exercises), ensures actionable findings, and prioritized mitigation guidance.

Key Responsibilities

Assessment & Security Validation Leadership

  • Oversee teams conducting comprehensive site‑based and remote assessments supporting, vulnerability management, compliance validation, and ad‑hoc inspection needs.

  • Ensure detailed assessments of technical and non‑technical controls across cloud, bare‑metal, and OT/ICS systems are aligned to NIST frameworks, Federal guidance, and Cyber Performance Goals.

  • Direct tailored test plans.

  • Oversee assessments of performance using red‑, blue‑, and purple‑team methodologies.

  • Manage automated system and web‑application scanning, phishing assessments, and development of customized plugin policies.

  • Enforce clear operational oversight practices—weekly status reports, daily assessment updates, formal kickoffs, and structured out‑briefs.

Remediation Orchestration & Risk Reduction

  • Oversee end‑to‑end management of assessment findings—advising system owners on corrective actions and ensuring vulnerabilities are prioritized, fixed, mitigated, or appropriately risk‑accepted (where/when applicable).
  • Direct delivery of automated remediation tracking, trend analysis, and documented mitigation strategies.
  • Ensure machine‑readable assessment outputs are produced and that CISA‑standard tools, techniques, and procedures.
  • Integrate artificial intelligence/machine learning (AI/ML)‑enabled vulnerability discovery and enrichment tools.
  • Leverage ML‑driven risk scoring models to support prioritization of remediation actions, incorporating threat intelligence, exploitability indicators, adversary behaviors, and mission impact.
  • Implement AI‑assisted analytics to evaluate remediation trends, predict control failures, and provide early warning indicators.
  • Employ automated reasoning and natural language processing (NLP) technologies.
  • Oversee integration of AI‑powered attack simulation, red‑team automation, and adversary emulation platforms.
  • Direct the use of AI‑based anomaly detection and behavior modeling.
  • Ensure assessment and remediation workflows are compatible with AI‑enabled orchestration platforms, allowing real‑time synchronization of findings, automated task assignment, and predictive remediation timelines.
  • Guide adoption of ML‑assisted configuration baselining and drift detection capabilities that alert teams to deviations from secure architectures and federal benchmarks.
  • Promote responsible and compliant use of AI/ML in vulnerability management.

Threat Emulation & Simulation Operations

  • Oversee teams that emulate and simulate real‑world threat actors in live and synthetic environments.
  • Ensure the creation and operation of realistic, secure, and rapidly reconfigurable emulated network environments for representative cyber‑range experimentation.
  • Direct reproduction of adversary behaviors (intelligence‑derived TTPs, open‑source reporting, government-provided data) in test/evaluation environments to improve detection and prevention.
  • Oversee red‑ and blue‑team exercises on emulated networks using realistic tools, malware, and tradecraft.
  • Ensure adversary behavioral characteristics from emulation activities are collected and transformed into improved analytics, detection logic, and defensive process enhancements.
  • Employ ML‑based behavior modeling engines to create adaptive threat actors.
  • Use AI‑assisted cyber range orchestration tools to configure, deploy, and reset complex emulated environments, enabling faster test cycles.
  • Implement AI/ML analytics to evaluate telemetry captured from emulation and simulation events, identifying defensive blind spots, response gaps, and control weaknesses.
  • Leverage machine learning to generate synthetic malware variants, exploit chains, and network behaviors that stress test signature‑based and behavior‑based detection mechanisms.
  • Direct the use of autonomous or semi‑autonomous red‑team augmentation tools.
  • Incorporate AI‑powered anomaly detection systems into blue‑team exercises to evaluate how effectively defensive tools and analysts.
  • Ensure adversary emulation telemetry is transformed into machine‑readable threat intelligence artifacts (e.g., STIX, ATT&CK‑mapped behavioral profiles).

Governance, Reporting & Continuous Improvement

  • Maintain continuous communication with system owners and stakeholders.
  • Recommend innovative processes and technologies that modernize assessment efficiency and accuracy, enabling scalable methodologies.
  • Drive analytic rigor by producing custom testing artifacts and enhancing tooling/processes used across engagements.
  • Implement AI‑enabled reporting workflows that automatically transform machine‑readable assessment data into tailored dashboards, executive summaries, and audit‑ready artifacts aligned with federal and CISA reporting standards.
  • Employ natural language processing (NLP) tools to analyze assessment narratives, finding trends, common control failures, and opportunities for standardization or process optimization.
  • Suggest the integration of AI‑assisted governance tools that predict remediation timelines, estimate risk reduction outcomes, and support decision‑making for prioritizing enterprise‑level mitigation actions.
  • Use machine learning to continuously evaluate the effectiveness of assessment methodologies and control validation processes, recommending evidence‑based improvements to increase precision and reduce manual effort.
  • Propose the adoption of generative AI tools to prototype new testing artifacts, emulate threat conditions, and accelerate the development of reusable templates that enhance efficiency across teams.
  • Ensure responsible, transparent, and auditable use of AI/ML technologies within governance and reporting workflows, aligned with federal AI risk management practices and agency‑specific policies.

Required Qualifications

  • Experience overseeing vulnerability management programs and security assessments (cloud, enterprise, OT) for large‑scale federal environments, including penetration testing and SOC evaluation.
  • Demonstrated ability to manage remediation workflows, automated tracking, and risk acceptance processes aligned to federal frameworks (e.g., FISMA, NIST) and CISA standards.
  • Familiarity with red/blue/purple‑team practices, phishing assessment design, and PoC exploit development to validate controls and detection logic.
  • Strong communication and reporting skills (status reports, kickoffs, out‑briefs) with a focus on measurable mission impact.
  • 10 years of overall cybersecurity experience with 5 years of management of cybersecurity teams
  • Experience integrating AI/ML‑enabled tools into vulnerability discovery, risk scoring, and remediation workflows, including automated analysis pipelines and machine‑readable assessment outputs.
  • Demonstrated ability to evaluate and operationalize AI‑assisted threat emulation, automated adversary simulation systems, or model‑driven red‑team augmentation capabilities.
  • Familiarity with AI/ML analytics used for detection logic improvement, control effectiveness measurement, and identification of systemic weaknesses across large‑scale enterprise or cloud environments.
  • Hands‑on experience using or overseeing AI‑powered reporting and governance workflows, such as automated dashboarding, NLP‑based narrative generation, or predictive remediation analytics.
  • Knowledge of federal AI governance and risk management principles (e.g., NIST AI RMF, agency‑specific AI policies) and the ability to ensure responsible, auditable, and compliant use of AI within cybersecurity operations.
  • Practical understanding of ML‑driven behavioral analysis, anomaly detection, and adversary behavior modeling tools employed in SOC evaluation, emulation exercises, or continuous monitoring programs.
  • Experience managing teams that utilize cyber range automation platforms or AI‑enabled orchestration tools to configure, deploy, and validate secure test environments rapidly and consistently.
  • Ability to assess and validate output from AI/ML systems.

Desired Qualifications

  • Experience with threat emulation/simulation environments and cyber‑range operations that replicate adversary target spaces.

  • Background turning adversary behavior insights into analytics and detection logic enhancements.

  • Relevant certifications (e.g., CISSP, OSCP, GPEN, GICSP) and familiarity with CISA Cyber Performance Goals and NIST control baselines.

GDIT IS YOUR PLACE

  • 401K : With company match.
  • Health & Wellness : Comprehensive health and wellness packages.
  • Career Growth : Internal mobility team dedicated to helping you own your career.
  • Professional Development : Growth opportunities including paid education and certifications.
  • Innovative Tech : Access to cutting-edge technology to stay ahead of the mission.
  • Work-Life Balance : Rest and recharge with paid vacation and holidays.

Work Requirements

Years of Experience

10 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

Travel Required

Less than 10%

Citizenship

U.S. Citizenship Required

Vacancy posted 15 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Lead, Top Secret in Herndon, VA vacancy
  • $170k - $230k

     ...Must Currently Possess: Top Secret/SCI Clearance Level Must...  ...Family: Cyber and IT Risk Management Job Qualifications: Skills...  ...Team Leadership, Threat and Vulnerability Management, Vulnerability...  ...The Vulnerability Management Lead oversees teams that delivers... 
    Suggested
    Full time
    Temporary work
    Part time
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Herndon, VA
    15 days ago
  • Northrop Grumman is seeking a Business Development Manager to join their Dulles, VA team. The role involves creating customer engagement...  ...possess 7+ years of experience in business development and a Top Secret clearance. The position offers competitive pay, comprehensive... 
    Suggested

    Northrop Grumman

    Dulles, VA
    3 days ago
  • $170k - $230k

     ...Must Currently Possess: Top Secret Clearance Level Must Be Able...  ...: Cyber and IT Risk Management Job Qualifications: Skills...  ...The NextGen Command Center Lead is responsible for...  ...such as Threat Hunt, CTI, and Vulnerability Management. Key Responsibilities... 
    Suggested
    Full time
    Contract work
    Temporary work
    Part time
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    Shift work

    GDIT

    Herndon, VA
    15 days ago
  • Northrop Grumman is seeking a Business Development Manager in McLean, VA, to create and execute customer engagement strategies in the...  ...customer requirements. The role requires a current active Top Secret security clearance. Competitive salary and benefits offered, including... 
    Suggested
    Relocation package

    Northrop Grumman

    Mc Lean, VA
    4 days ago
  • $170k - $230k

     ...Clearance Level Must Currently Possess: Top Secret Clearance Level Must Be Able to...  ...None Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Cyber...  ...Job Description: The Threat Hunt Lead is responsible for overseeing all cyber... 
    Suggested
    Full time
    Contract work
    Temporary work
    Part time
    Local area
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    Shift work

    GDIT

    Herndon, VA
    23 days ago
  • $170k - $230k

     ...Clearance Level Must Currently Possess: Top Secret Clearance Level Must Be Able to...  ...None Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Remediation...  ...The Remediation and Mitigation (R&M) Lead oversees teams that plan, manage, and... 
    Full time
    Temporary work
    Part time
    Local area
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Herndon, VA
    15 days ago
  •  ...Product Manager Sme Everforth ECS is seeking a product manager sme to work in the...  ...battlefield. The wdp extends to unclassified, secret, and top secret environments, and supports...  .... This role directs enterprise vulnerability assessment operations using the assured... 
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  • $97.75k - $132.25k

     ...Must Currently Possess: Top Secret Clearance Level Must Be...  ...Tracking, Cyber Risks, IT Asset Management (ITAM), System Security...  ...Security Directorate (CSD) is leading one of the most comprehensive...  ..., zero trust modernization, vulnerability assessment, and enterprise-... 
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Ashburn, VA
    3 days ago
  •  ...seeking an experienced ISSO Lead with expertise in applying the Risk Management Framework (RMF) and NIST 80...  ...at conducting deep-dive vulnerability analyses and engineering remediation...  ...must be a U.S. Citizen. Secret security clearance required, Top Secret clearance is... 
    Contract work
    Temporary work
    Local area
    Remote work
    Flexible hours

    TSTC

    Reston, VA
    4 days ago
  • $112k - $179k

     ...NOC Shift Lead Job Locations US-VA-Herndon Requisition...  ...Position Category Project Management Clearance Top Secret/SCI Responsibilities We are...  ...to advise leadership on systemic vulnerabilities and service degradation patterns.... 
    Contract work
    Shift work
    Night shift

    Peraton

    Herndon, VA
    23 hours ago
  • $80k - $128k

     ...Detection & Case Management Lead Job Locations US-VA-Herndon Requisition ID...  ...Threat Analysis Clearance Top Secret/SCI Responsibilities We are seeking...  ...threat intelligence, CDAP/CHAP/vulnerability findings into prioritized, testable detection... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    4 days ago
  • $75.2k - $158.1k

     ...Job Title: Vulnerability Management Lead Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Continental US The Opportunity... 
    Full time
    Contract work
    Work experience placement
    Flexible hours

    CACI International

    Chantilly, Loudoun County, VA
    4 days ago
  •  ...SOC Vulnerability Management AESS Lead - Senior ECS is seeking a SOC Vulnerability Management AESS Lead - Senior to support the Army National Guard...  ...U.S. Citizenship is required Security Clearance: Secret Eligible Required Certifications: DCWF Work Role 541-Vulnerability... 
    Contract work

    ECS

    Fairfax, VA
    3 days ago
  •  ...SOC Vulnerability Management ACAS Lead - Senior ECS is seeking a SOC Vulnerability Management ACAS Lead - Senior to support the Army National Guard...  ...U.S. Citizenship is required Security Clearance: Secret Eligible Required Certifications: DCWF Work Role 541-Vulnerability... 
    Contract work

    ECS

    Fairfax, VA
    3 days ago
  •  ...SOC Vulnerability Management Team Lead - Senior ECS is seeking a SOC Vulnerability Management Team Lead - Senior to support the Army National Guard...  ...U.S. Citizenship is required Security Clearance: Secret Eligible Required Certifications: DCWF Work Role 541-Vulnerability... 
    Contract work

    ECS

    Fairfax, VA
    3 days ago
  • $78.75 - $113.75 per hour

     ...TS SCI W/ CI Poly Cleared Vulnerability/GRC Lead Our client, a leader in the HCM space is in need of a GRC/Vulnerability Lead for a 1 year...  ...schedule out of Reston VA, support security, compliance, and risk management initiatives. The Lead will be responsible for supporting... 
    Hourly pay
    Contract work

    ClearBridge Technology Group

    Reston, VA
    13 hours ago
  • $104k - $166k

     ...Cybersecurity Lead Job Locations US-VA-Herndon Requisition...  ...Information Technology Clearance Top Secret/SCI Responsibilities We are...  ..., and secure configuration management. Oversee vulnerability management, threat/hunt analysis, incident... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    4 days ago
  • $130k - $160k

     ...The Vulnerability Assessment Team Lead manages enterprise vulnerability identification and remediation efforts to reduce risk across CBP systems. If...  ...certification ~ Strong knowledge of RMF and FISMA ~ Secret clearance $130,000 - $160,000 a year We... 

    UltraViolet Cyber

    Ashburn, VA
    1 day ago
  •  ...seeking an experienced ISSO Lead with expertise in applying the Risk Management Framework (RMF) and NIST 80...  ...at conducting deep-dive vulnerability analyses and engineering remediation...  ...must be a U.S. Citizen. Secret security clearance required, Top Secret clearance is... 
    Contract work
    Temporary work
    Local area
    Remote work
    Flexible hours

    TSTC

    Reston, VA
    more than 2 months ago
  • $86k - $138k

     ...Knowledge Transfer (KT) Lead Job Locations US-VA-Herndon Requisition...  ...Knowledge Mgmt Clearance Top Secret/SCI Responsibilities We are seeking...  ...Key Responsibilities Develop and manage KT strategy and transition plans covering... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    4 days ago
  •  ...dynamic and experienced executive with keen business acumen to lead business development for the Department of Justice account....  ...experience. Must be U.S. Citizen eligible to obtain and maintain a Top-Secret clearance. Minimum of 10 years' Business Development... 
    Work at office

    Science Applications International Corporation

    Reston, VA
    1 day ago
  • $89.22k - $151.68k

     ...Description ENVIRONMENTAL POLICY AND STRATEGY LEAD ICF is seeking an experienced...  ...team provides comprehensive environmental management support to the Missile Defense Agency (MDA...  ...dispersed locations worldwide. SECRET Clearance Required This position is based... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Worldwide
    Monday to Thursday

    ICF

    Fairfax, VA
    2 days ago
  •  ...Devsecops/Supply Chain Lead Sme Everforth ECS is seeking...  ...WDP extends to Unclassified, Secret, and Top Secret environments, and supports...  ...acceptance thresholds for vulnerability assessments executed within...  ..., supply chain risk management, or cybersecurity engineering... 
    Contract work

    ECS

    Fairfax, VA
    4 days ago
  •  ...Gritter Francona is looking for a Vulnerability Assessment Team Lead to support a potential project with the Department of Homeland Security. The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection... 
    Temporary work

    Gritter Francona

    Ashburn, VA
    2 days ago
  • $120k - $200k

     ...Government Partnership Lead Scout Space is building a new way to see and operate in...  ...driven Government Partnership Lead with a Top Secret/SCI clearance to drive strategic engagement...  ...Responsibilities Cultivate and manage trusted relationships with key stakeholders... 
    Permanent employment
    Contract work
    Remote work
    Relocation

    SCOUT

    Reston, VA
    1 day ago
  • $86k - $138k

     ...Risk Management Framework (RMF) Lead Job Locations US-VA-Herndon Requisition ID 2026-165279 Position Category Cyber Security Clearance Top Secret/SCI Responsibilities We are seeking a highly skilled and innovative... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    1 day ago
  • $104k - $166k

     ...SOC Shift Lead Job Locations US-VA-Herndon Requisition ID 202...  ...Cyber Security Clearance Top Secret/SCI Responsibilities We are seeking...  ...assigned shifts: coordinate analyst workload, manage escalations, and direct incident response... 
    Contract work
    Shift work
    Night shift

    Peraton

    Herndon, VA
    1 day ago
  •  ...security, compliance, and risk management of network infrastructure,...  ...from unauthorized access, vulnerabilities, and advanced threats. Direct...  ...remediation strategies. Lead incident response efforts,...  ...protocols Must have an active Secret clearance CERTIFICATIONS... 
    Full time
    Contract work
    Temporary work
    Local area
    Remote work
    Monday to Friday
    Weekend work
    Day shift
    Afternoon shift

    TekSynap

    Reston, VA
    10 days ago
  •  ...T&E Gate Lead/Evaluation Science Lead Sme Everforth ECS is...  ...WDP extends to Unclassified, Secret, and Top Secret environments, and...  ...scanning pipelines for security vulnerabilities, integration bottlenecks,...  ...to enforce gate policies and manage remediation workflows across... 
    Contract work

    ECS

    Fairfax, VA
    3 days ago
  • $112k - $179k

     ...CDES Lead/Cross Domain SME Job Locations US-VA-Herndon Requisition...  ...Information Technology Clearance Top Secret/SCI Responsibilities We are...  ...Control Assessors. Oversee configuration management, continuous monitoring, incident response... 
    Contract work
    Shift work

    Peraton

    Herndon, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Management Lead, Top Secret. Be the first to apply!