Vulnerability Management Lead
$125k - $175kSteampunk
OverviewWe are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT environment supporting more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads, and network infrastructure.The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and system owners to identify, prioritize, and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes, improving automation and reporting capabilities, and ensuring alignment with federal cybersecurity directives, NIST guidance, and organizational security policies.ContributionsResponsibilities include:Lead the enterprise vulnerability management program across servers, workstations, HPC systems, cloud environments, and network devices supporting more than 30,000 managed assets.Plan, coordinate, and oversee enterprise vulnerability scanning, assessment, prioritization, remediation tracking, validation, and reporting activities.Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Develop and maintain risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Drive enterprise remediation activities in alignment with applicable federal directives, including Binding Operational Directive (BOD) 22-01, and organizational security requirements.Develop and enhance enterprise vulnerability management processes, procedures, templates, and operational standards.Design and implement automation solutions that improve vulnerability data collection, remediation tracking, reporting, and operational efficiency.Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction across the enterprise vulnerability management program.Develop and maintain enterprise dashboards, weekly reporting, and executive visualizations utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Identify tool, process, and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program.Ensure vulnerability management activities align with NIST SP 800-53, organizational policies, and applicable federal cybersecurity directives, including BOD 22-01.Develop and maintain vulnerability management documentation, including standard operating procedures (SOPs), remediation guidance, risk mitigation strategies, process improvement plans, and automation roadmaps.Identify opportunities to improve enterprise vulnerability management through process optimization, workflow improvements, enhanced automation, and data quality initiatives.Support continuous monitoring activities and collaborate with stakeholders to strengthen the organization's overall cybersecurity posture.Stay current on emerging vulnerabilities, threat intelligence, federal cybersecurity directives, and industry best practices.QualificationsRequiredAbility to obtain and maintain a U.S. government Security Clearance.Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience).Minimum of 5 years of hands-on experience supporting enterprise vulnerability management, cybersecurity operations, and risk remediation workflows.Experience managing enterprise vulnerability management programs across more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads (AWS, Azure, and Google Cloud Platform), and network devices while driving patching and remediation activities in accordance with BOD 22-01.Experience collaborating with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Experience developing and implementing risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction.Experience developing enterprise dashboards, weekly reporting, and operational metrics utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Experience identifying enterprise tool, process, and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans.Experience developing enterprise vulnerability management processes, standard operating procedures, documentation, and continuous process improvement initiatives.Strong knowledge of federal cybersecurity requirements, including NIST SP 800-53 and applicable federal vulnerability management directives.Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders.PreferredExperience supporting cybersecurity programs within a federal government environment.Experience supporting enterprise continuous monitoring initiatives.One or more of the following certifications:CompTIA Security+CISSPCISMCISACCSPOSCPAbout steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $125,000 to $175,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers – and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8025Clearance Requirement: Public Trust
- ...Technical Subject Matter Experts (SETA) in Arlington, VA. The successful candidates will lead project management and risk analysis activities. Responsibilities include vulnerability research and providing expert guidance on security practices. The ideal candidates...Suggested
$150k - $180k
GovCIO is currently hiring for a Vulnerability Management Team Lead to provide support to a Federal government contract. The Vulnerability Team Lead will be leading critical support for the Information Security’s vulnerability management program (VM) as part of the Office...SuggestedContract workWork experience placementCurrently hiringWork at officeRemote work- Peraton is seeking a Vulnerability Management Analyst to support the FAA under the BNATCS contract, delivering cybersecurity and risk management services to protect NAS systems and critical applications. You will identify, analyze, and remediate vulnerabilities using FAA...SuggestedRemote jobContract work
- A cybersecurity services company is seeking a full-time Endpoint Vulnerability Management SME to join their team in Bethesda, MD. The ideal candidate will lead vulnerability management initiatives and ensure compliance. Required qualifications include a Bachelor's in a...SuggestedFull time
- ...at least 3 years of Cybersecurity experience, strong knowledge of Risk Management Framework (RMF), and requisite certifications such as Security+. Responsibilities include conducting vulnerability tests and managing the security of Information Systems. OTS values diversity...SuggestedContract work
$141.2k - $278.3k
Position Summary Google AI Lead Architect/AI & Engineering:Join our AI & Engineering... ...and BigQuery vector; implement context management, retrieval strategies, and... ...AI/ML systems by addressing potential vulnerabilities such as data privacy concerns, model poisoning...Local areaVisa sponsorshipFlexible hours- ...SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting... ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination... ...training certificates, access reviews, vulnerability scans) Assist with internal policy...For contractorsRemote work
- Peraton is seeking a Senior Risk and Vulnerability Analyst to support a 24x7 Security Operations Center, identifying, analyzing, and prioritizing vulnerabilities across enterprise, cloud, and application environments. The role requires coordinating remediation efforts,...
$114.1k - $268.18k
...opportunities, a world-class training facility, and leading market tools, we help our people... ...Specialist, Cloud Security to join our Managed Services practice.Responsibilities:... ...operating frameworksSolid experience managing vulnerability management, compliance, exception...H1bLocal area$135k - $225k
...seeking an experienced Sitecore Architect to lead the design, implementation, and... ...based digital platforms, including content management/operations, asset management,... ...managing and triaging website security vulnerabilities. Have a strong understanding of CMS governance...Full timeRemote workFlexible hours- ...Duties and Responsibilities - Lead a small team of advanced and mid-level... ...proactively identifying novel threats and vulnerabilities. - Executive communication: excellent... ...decision-makers. - Project and case management: proven ability to independently manage...Full timeWeekend work
- ...standards and procedures through security governance, risk management and continuous monitoring programs. Assess security impacts... ...applications in order to identify potential security weaknesses and vulnerabilities, recommends improvements, develops and implements...Contract workLocal area
$112.8k - $257k
...to assess and refine biothreat contingency planning, analyze vulnerabilities, and ensure preparedness against biological hazards in support... ...solutions that integrate into broader CBRN-defense policies. You’ll lead the creation of research-driven deliverables, guide policy...Local area- ...an experienced Information Security Systems Officer (ISSO) to lead RMF, ATO, and continuous monitoring for a major federal initiative... ...NIST 800-53 controls, perform risk assessments, and drive DevSecOps with SIEM and vulnerability tools. #J-18808-Ljbffr 3M HEALTHCARE
$136k - $184k
...None Job Family: Cyber and IT Risk Management Skills: Job Qualifications: Cyber Incident... ...: Cyber Incident Response Team (CIRT) Lead Location: Full-time onsite, Falls... ...remediation. Direct proactive identification of vulnerabilities and recommend mitigations to reduce...Full timeContract workTemporary workWork experience placementImmediate startRemote workWorldwideFlexible hoursShift work- ...seeking an experienced Cyber Security professional to join their Offensive Security Purple Team. The role involves identifying vulnerabilities, threat hunting, and collaborating with various stakeholders to enhance cyber defense. The ideal candidate will have a strong background...
- ...skills Support the development and validation of security and vulnerability tests against applications Requirements Bachelor's degree... ...testing progress across multiple releases Experience with test management tools like Jira or ALM Experience testing low code and BPM...Full time
- ...Market, Inc. in Arlington, Virginia is looking for an Assistant Meat Manager who enjoys sharing knowledge about meat and seafood while assisting customers with their choices. In this role, you will lead a team to provide excellent service in one of the busiest...Flexible hours
$93.5k - $144.89k
Certifiedarchivists in Arlington, VA, is looking for an Archival Supervisor to lead the Charlie Clark Center for Local History. This full-time position involves strategy implementation, mentorship of staff, and development of archival collections. The ideal candidate will...Full timeLocal area- ...playground with over 50 life-sized mini-games and a full-service bar and restaurant. The FOH Supervisor will lead front-of-house staff, ensure guest satisfaction, manage shifts, cash handling, and uphold service standards across our venues. Based in the Tysons, VA area, the...Shift work
- Amazon Security's Business Assurance Center seeks an Incident Response Coordination Supervisor to lead a 24/7 GSOC team and ensure timely incident management across global security operations. Role requires a Bachelor's degree, 3+ years of operations personnel management...Shift workWeekend workAfternoon shift
- ...Ambassador embodying of Coach values and increasing brand awareness. Leads implementation of Company initiatives and support full... ...Qualifications & Requirements: 1+ years of equivalent experience in Managing Competitive Retail Space at the Lead Supervisor level. Can bend...Minimum wageShift work
$125k - $175k
OverviewSteampunk is seeking an ISSO Portfolio Manager / Team Lead to support a federal customer. This role is perfect for someone who blends... ..., audit readiness, data calls, and risk reporting.Track vulnerabilities, guide remediation, and keep all systems “green” on the...Contract work1 day per week$180k - $250k
...in our Federal Operating Group and will lead client delivery, business development, and... ...on water, infrastructure, and emergency management. The successful candidate will bring... ...utility and infrastructure operationsConduct vulnerability assessments and translate findings into...Contract workWork experience placementLocal areaRemote workWorldwide- ...of our Water Business Group, you’ll help shape how communities manage water for generations to come. From delivering safe drinking water... ...in people’s lives. This isn’t just a job, it's a chance to lead change, drive progress, and leave a lasting legacy.Each and every...Contract workWork at officeLocal areaRemote work
- ...generation facilities, your contributions will help define the future of the built environment. This isn’t just a job, it’s a chance to lead innovation, engineer impact, and build a legacy of excellence.Each and every role throughout our organization makes a difference in...Contract workWork at office
- ...Advanced Security Product Services, MDR) and leading Security Platforms (market leading OEM’... ...Architects. Work with Account Managers and Sales Directors to proactively establish... ...managers and management. Experience in vulnerability analysis procedures and deliverables....Full time
- DescriptionSAIC is seeking a Policy and Proposal Lead to support multiple customers within the Department of Navy (DON), including... ...stakeholders, including DUSN(I&S), NCIS, and the DON SBIR/STTR Program Management Office (PMO) to lead the development of the Navy’s SBIR/STTR...Work at officeRemote work
$140k - $150k
...DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office /... ...with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems... ...proceduresComfortable interacting with executive management to communicate risk and support...Work at officeRemote work$140k - $175k
...team, this individual may oversee staff, support performance management and task delegation, help resolve issues, and contribute to client... ..., leadership, and client stakeholders while supporting or leading practice, solution, and business development initiatives.Job Duties...Work at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Lead. Be the first to apply!
- weight management McLean, VA
- learning management system specialist McLean, VA
- product management intern McLean, VA
- change management project manager McLean, VA
- internship event management company McLean, VA
- director revenue management McLean, VA
- asset management McLean, VA
- endpoint management McLean, VA
- focus workforce management McLean, VA
- entry level management training McLean, VA


