Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Management Lead

$125k - $175k

Steampunk

OverviewWe are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT environment supporting more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads, and network infrastructure.The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and system owners to identify, prioritize, and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes, improving automation and reporting capabilities, and ensuring alignment with federal cybersecurity directives, NIST guidance, and organizational security policies.ContributionsResponsibilities include:Lead the enterprise vulnerability management program across servers, workstations, HPC systems, cloud environments, and network devices supporting more than 30,000 managed assets.Plan, coordinate, and oversee enterprise vulnerability scanning, assessment, prioritization, remediation tracking, validation, and reporting activities.Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Develop and maintain risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Drive enterprise remediation activities in alignment with applicable federal directives, including Binding Operational Directive (BOD) 22-01, and organizational security requirements.Develop and enhance enterprise vulnerability management processes, procedures, templates, and operational standards.Design and implement automation solutions that improve vulnerability data collection, remediation tracking, reporting, and operational efficiency.Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction across the enterprise vulnerability management program.Develop and maintain enterprise dashboards, weekly reporting, and executive visualizations utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Identify tool, process, and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program.Ensure vulnerability management activities align with NIST SP 800-53, organizational policies, and applicable federal cybersecurity directives, including BOD 22-01.Develop and maintain vulnerability management documentation, including standard operating procedures (SOPs), remediation guidance, risk mitigation strategies, process improvement plans, and automation roadmaps.Identify opportunities to improve enterprise vulnerability management through process optimization, workflow improvements, enhanced automation, and data quality initiatives.Support continuous monitoring activities and collaborate with stakeholders to strengthen the organization's overall cybersecurity posture.Stay current on emerging vulnerabilities, threat intelligence, federal cybersecurity directives, and industry best practices.QualificationsRequiredAbility to obtain and maintain a U.S. government Security Clearance.Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience).Minimum of 5 years of hands-on experience supporting enterprise vulnerability management, cybersecurity operations, and risk remediation workflows.Experience managing enterprise vulnerability management programs across more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads (AWS, Azure, and Google Cloud Platform), and network devices while driving patching and remediation activities in accordance with BOD 22-01.Experience collaborating with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.Experience developing and implementing risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction.Experience developing enterprise dashboards, weekly reporting, and operational metrics utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.Experience identifying enterprise tool, process, and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans.Experience developing enterprise vulnerability management processes, standard operating procedures, documentation, and continuous process improvement initiatives.Strong knowledge of federal cybersecurity requirements, including NIST SP 800-53 and applicable federal vulnerability management directives.Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders.PreferredExperience supporting cybersecurity programs within a federal government environment.Experience supporting enterprise continuous monitoring initiatives.One or more of the following certifications:CompTIA Security+CISSPCISMCISACCSPOSCPAbout steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $125,000 to $175,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers – and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8025Clearance Requirement: Public Trust

Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Lead in McLean, VA vacancy
  •  ...Technical Subject Matter Experts (SETA) in Arlington, VA. The successful candidates will lead project management and risk analysis activities. Responsibilities include vulnerability research and providing expert guidance on security practices. The ideal candidates... 
    Suggested

    Blue Sky Innovators Inc

    Arlington, VA
    1 day ago
  • $150k - $180k

    GovCIO is currently hiring for a Vulnerability Management Team Lead to provide support to a Federal government contract. The Vulnerability Team Lead will be leading critical support for the Information Security’s vulnerability management program (VM) as part of the Office... 
    Suggested
    Contract work
    Work experience placement
    Currently hiring
    Work at office
    Remote work

    Govcio

    Bethesda, MD
    1 day ago
  • Peraton is seeking a Vulnerability Management Analyst to support the FAA under the BNATCS contract, delivering cybersecurity and risk management services to protect NAS systems and critical applications. You will identify, analyze, and remediate vulnerabilities using FAA... 
    Suggested
    Remote job
    Contract work

    Peraton

    Bethesda, MD
    1 day ago
  • A cybersecurity services company is seeking a full-time Endpoint Vulnerability Management SME to join their team in Bethesda, MD. The ideal candidate will lead vulnerability management initiatives and ensure compliance. Required qualifications include a Bachelor's in a... 
    Suggested
    Full time

    Maveris

    Bethesda, MD
    1 day ago
  •  ...at least 3 years of Cybersecurity experience, strong knowledge of Risk Management Framework (RMF), and requisite certifications such as Security+. Responsibilities include conducting vulnerability tests and managing the security of Information Systems. OTS values diversity... 
    Suggested
    Contract work

    Oneida Technical Solutions LLC

    Fort Belvoir, VA
    3 days ago
  • $141.2k - $278.3k

    Position Summary Google AI Lead Architect/AI & Engineering:Join our AI & Engineering...  ...and BigQuery vector; implement context management, retrieval strategies, and...  ...AI/ML systems by addressing potential vulnerabilities such as data privacy concerns, model poisoning... 
    Local area
    Visa sponsorship
    Flexible hours

    Deloitte

    McLean, VA
    11 hours ago
  •  ...SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting...  ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination...  ...training certificates, access reviews, vulnerability scans) Assist with internal policy... 
    For contractors
    Remote work

    Paragone Solutions, Inc.

    McLean, VA
    5 days ago
  • Peraton is seeking a Senior Risk and Vulnerability Analyst to support a 24x7 Security Operations Center, identifying, analyzing, and prioritizing vulnerabilities across enterprise, cloud, and application environments. The role requires coordinating remediation efforts,... 

    Peraton

    Washington DC
    5 days ago
  • $114.1k - $268.18k

     ...opportunities, a world-class training facility, and leading market tools, we help our people...  ...Specialist, Cloud Security to join our Managed Services practice.Responsibilities:...  ...operating frameworksSolid experience managing vulnerability management, compliance, exception... 
    H1b
    Local area

    KPMG

    McLean, VA
    7 hours ago
  • $135k - $225k

     ...seeking an experienced Sitecore Architect to lead the design, implementation, and...  ...based digital platforms, including content management/operations, asset management,...  ...managing and triaging website security vulnerabilities. Have a strong understanding of CMS governance... 
    Full time
    Remote work
    Flexible hours

    Guidehouse

    McLean, VA
    11 hours ago
  •  ...Duties and Responsibilities - Lead a small team of advanced and mid-level...  ...proactively identifying novel threats and vulnerabilities. - Executive communication: excellent...  ...decision-makers. - Project and case management: proven ability to independently manage... 
    Full time
    Weekend work

    search-tactics

    Arlington, VA
    1 day ago
  •  ...standards and procedures through security governance, risk management and continuous monitoring programs. Assess security impacts...  ...applications in order to identify potential security weaknesses and vulnerabilities, recommends improvements, develops and implements... 
    Contract work
    Local area

    iTech AG

    Arlington, VA
    2 days ago
  • $112.8k - $257k

     ...to assess and refine biothreat contingency planning, analyze vulnerabilities, and ensure preparedness against biological hazards in support...  ...solutions that integrate into broader CBRN-defense policies. You’ll lead the creation of research-driven deliverables, guide policy... 
    Local area

    Booz Allen Hamilton

    Arlington, VA
    2 days ago
  •  ...an experienced Information Security Systems Officer (ISSO) to lead RMF, ATO, and continuous monitoring for a major federal initiative...  ...NIST 800-53 controls, perform risk assessments, and drive DevSecOps with SIEM and vulnerability tools. #J-18808-Ljbffr 3M HEALTHCARE

    3M HEALTHCARE

    Arlington, VA
    11 hours ago
  • $136k - $184k

     ...None Job Family: Cyber and IT Risk Management Skills: Job Qualifications: Cyber Incident...  ...: Cyber Incident Response Team (CIRT) Lead Location: Full-time onsite, Falls...  ...remediation. Direct proactive identification of vulnerabilities and recommend mitigations to reduce... 
    Full time
    Contract work
    Temporary work
    Work experience placement
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    Shift work

    General Dynamics Information Technology

    Falls Church, VA
    4 days ago
  •  ...seeking an experienced Cyber Security professional to join their Offensive Security Purple Team. The role involves identifying vulnerabilities, threat hunting, and collaborating with various stakeholders to enhance cyber defense. The ideal candidate will have a strong background... 

    Capital One National Association

    Mc Lean, VA
    1 day ago
  •  ...skills Support the development and validation of security and vulnerability tests against applications Requirements Bachelor's degree...  ...testing progress across multiple releases Experience with test management tools like Jira or ALM Experience testing low code and BPM... 
    Full time

    Astor & Sanders

    Mc Lean, VA
    3 days ago
  •  ...Market, Inc. in Arlington, Virginia is looking for an Assistant Meat Manager who enjoys sharing knowledge about meat and seafood while assisting customers with their choices. In this role, you will lead a team to provide excellent service in one of the busiest... 
    Flexible hours

    Sprouts Farmers Market, Inc.

    Arlington, VA
    5 days ago
  • $93.5k - $144.89k

    Certifiedarchivists in Arlington, VA, is looking for an Archival Supervisor to lead the Charlie Clark Center for Local History. This full-time position involves strategy implementation, mentorship of staff, and development of archival collections. The ideal candidate will... 
    Full time
    Local area

    Certifiedarchivists

    Arlington, VA
    2 days ago
  •  ...playground with over 50 life-sized mini-games and a full-service bar and restaurant. The FOH Supervisor will lead front-of-house staff, ensure guest satisfaction, manage shifts, cash handling, and uphold service standards across our venues. Based in the Tysons, VA area, the... 
    Shift work

    Level99 Entertainment

    Mc Lean, VA
    3 days ago
  • Amazon Security's Business Assurance Center seeks an Incident Response Coordination Supervisor to lead a 24/7 GSOC team and ensure timely incident management across global security operations. Role requires a Bachelor's degree, 3+ years of operations personnel management... 
    Shift work
    Weekend work
    Afternoon shift

    Socket.dev

    Arlington, VA
    2 days ago
  •  ...Ambassador embodying of Coach values and increasing brand awareness. Leads implementation of Company initiatives and support full...  ...Qualifications & Requirements: 1+ years of equivalent experience in Managing Competitive Retail Space at the Lead Supervisor level. Can bend... 
    Minimum wage
    Shift work

    Tapestry

    Mc Lean, VA
    3 days ago
  • $125k - $175k

    OverviewSteampunk is seeking an ISSO Portfolio Manager / Team Lead to support a federal customer. This role is perfect for someone who blends...  ..., audit readiness, data calls, and risk reporting.Track vulnerabilities, guide remediation, and keep all systems “green” on the... 
    Contract work
    1 day per week

    Steampunk

    McLean, VA
    3 days ago
  • $180k - $250k

     ...in our Federal Operating Group and will lead client delivery, business development, and...  ...on water, infrastructure, and emergency management. The successful candidate will bring...  ...utility and infrastructure operationsConduct vulnerability assessments and translate findings into... 
    Contract work
    Work experience placement
    Local area
    Remote work
    Worldwide

    Nathan Associates

    Arlington, VA
    4 days ago
  •  ...of our Water Business Group, you’ll help shape how communities manage water for generations to come. From delivering safe drinking water...  ...in people’s lives. This isn’t just a job, it's a chance to lead change, drive progress, and leave a lasting legacy.Each and every... 
    Contract work
    Work at office
    Local area
    Remote work

    HDR

    Vienna, VA
    3 days ago
  •  ...generation facilities, your contributions will help define the future of the built environment. This isn’t just a job, it’s a chance to lead innovation, engineer impact, and build a legacy of excellence.Each and every role throughout our organization makes a difference in... 
    Contract work
    Work at office

    HDR

    Arlington, VA
    3 days ago
  •  ...Advanced Security Product Services, MDR) and leading Security Platforms (market leading OEM’...  ...Architects. Work with Account Managers and Sales Directors to proactively establish...  ...managers and management. Experience in vulnerability analysis procedures and deliverables.... 
    Full time

    Presidio

    Reston, VA
    11 hours ago
  • DescriptionSAIC is seeking a Policy and Proposal Lead to support multiple customers within the Department of Navy (DON), including...  ...stakeholders, including DUSN(I&S), NCIS, and the DON SBIR/STTR Program Management Office (PMO) to lead the development of the Navy’s SBIR/STTR... 
    Work at office
    Remote work

    Science Applications International Corporation

    Arlington, VA
    3 days ago
  • $140k - $150k

     ...DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office /...  ...with SIEM platforms, vulnerability scanners, malware analyzers, IDS/IPS systems...  ...proceduresComfortable interacting with executive management to communicate risk and support... 
    Work at office
    Remote work

    ECS Federal

    Washington DC
    3 days ago
  • $140k - $175k

     ...team, this individual may oversee staff, support performance management and task delegation, help resolve issues, and contribute to client...  ..., leadership, and client stakeholders while supporting or leading practice, solution, and business development initiatives.Job Duties... 
    Work at office
    Flexible hours

    BDO International

    McLean, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Management Lead. Be the first to apply!