Vulnerability Management Lead
$125k - $175kSteampunk.com
Overview We are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT environment supporting more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads, and network infrastructure. The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and system owners to identify, prioritize, and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes, improving automation and reporting capabilities, and ensuring alignment with federal cybersecurity directives, NIST guidance, and organizational security policies. Contributions Lead the enterprise vulnerability management program across servers, workstations, HPC systems, cloud environments, and network devices supporting more than 30,000 managed assets. Plan, coordinate, and oversee enterprise vulnerability scanning, assessment, prioritization, remediation tracking, validation, and reporting activities. Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts. Develop and maintain risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices. Drive enterprise remediation activities in alignment with applicable federal directives, including Binding Operational Directive (BOD) 22-01, and organizational security requirements. Develop and enhance enterprise vulnerability management processes, procedures, templates, and operational standards. Design and implement automation solutions that improve vulnerability data collection, remediation tracking, reporting, and operational efficiency. Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction across the enterprise vulnerability management program. Develop and maintain enterprise dashboards, weekly reporting, and executive visualizations utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations. Identify tool, process, and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program. Ensure vulnerability management activities align with NIST SP 800-53, organizational policies, and applicable federal cybersecurity directives, including BOD 22-01. Develop and maintain vulnerability management documentation, including standard operating procedures (SOPs), remediation guidance, risk mitigation strategies, process improvement plans, and automation roadmaps. Identify opportunities to improve enterprise vulnerability management through process optimization, workflow improvements, enhanced automation, and data quality initiatives. Support continuous monitoring activities and collaborate with stakeholders to strengthen the organization's overall cybersecurity posture. Stay current on emerging vulnerabilities, threat intelligence, federal cybersecurity directives, and industry best practices. Qualifications Ability to obtain and maintain a U.S. government Security Clearance. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience). Minimum of 5 years of hands-on experience supporting enterprise vulnerability management, cybersecurity operations, and risk remediation workflows. Experience managing enterprise vulnerability management programs across more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads (AWS, Azure, and Google Cloud Platform), and network devices while driving patching and remediation activities in accordance with BOD 22-01. Experience collaborating with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts. Experience developing and implementing risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices. Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction. Experience developing enterprise dashboards, weekly reporting, and operational metrics utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations. Experience identifying enterprise tool, process, and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans. Experience developing enterprise vulnerability management processes, standard operating procedures, documentation, and continuous process improvement initiatives. Strong knowledge of federal cybersecurity requirements, including NIST SP 800-53 and applicable federal vulnerability management directives. Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders. Preferred Experience supporting cybersecurity programs within a federal government environment. Experience supporting enterprise continuous monitoring initiatives. One or more of the following certifications: CompTIA Security+ CISSP CISM CISA CCSP OSCP About steampunk Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $125,000 to $175,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk's total compensation package for employees. Learn more about additional Steampunk benefits here. Identity Statement As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology , we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit . We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Refer a Friend ( Need help finding the right job? We can recommend jobs specifically for you!Software Powered by ICIMS ( Job Location US-VA-McLean Posted Date 2 months ago (8/6/2026 9:26 AM) Job ID 8025 Clearance Requirement Public Trust Steampunk.com
- ...Responsibilities Lead technical planning, task prioritization, and schedule management for reverse engineering and vulnerability research assignments. Reverse engineer wireless and embedded communications systems to identify security weaknesses and assess operational...SuggestedFull time
- ...Technical Subject Matter Experts (SETA) in Arlington, VA. The successful candidates will lead project management and risk analysis activities. Responsibilities include vulnerability research and providing expert guidance on security practices. The ideal candidates...Suggested
$154.26k - $231.39k
...Opportunity Two Six Technologies is actively seeking a Lead Vulnerability Researcher to join our Communication Systems team in... ...Lead the technical planning, task prioritization, and schedule management for a group of reverse engineering and vulnerability research...SuggestedFull timeContract workLocal area- ...talent, excited to join that effort. To learn more about our exciting organization, please visit us at We are seeking a Vulnerability Management Lead to join our team and support our client. The ideal candidate is a proactive cybersecurity professional with deep...SuggestedTemporary workFor contractorsWork experience placementWork at officeRemote workFlexible hours2 days per week
$100 - $130 per hour
Job Summary: Our client is seeking a Vulnerability Management Team Lead to join their team! This position is located in Bethesda, Maryland. Duties: Lead and mentor the vulnerability management team, coordinating daily tasks, resources, and priorities Develop and execute...SuggestedLocal area- ...Library of Medicine (NLM) is seeking an IT Security Compliance Lead / Senior Security Analyst to safeguard the agency's IT... ...infrastructure in Bethesda, MD. You will work with the ISSO and lead vulnerability management across on‑prem and cloud environments. Responsibilities...3 days per week
- AUGUST SCHELL ENTERPRISES, INC. seeks an IT Vulnerability Management Lead / Senior Security Analyst to guide the vulnerability lifecycle in a primarily on-site Bethesda environment. You will coordinate remediation with IT ops, define scanner architectures, and ensure NIH...
- Peraton is seeking a Vulnerability Management Analyst to support the FAA under the BNATCS contract, delivering cybersecurity and risk management services to protect NAS systems and critical applications. You will identify, analyze, and remediate vulnerabilities using FAA...Remote jobContract work
- A cybersecurity services company is seeking a full-time Endpoint Vulnerability Management SME to join their team in Bethesda, MD. The ideal candidate will lead vulnerability management initiatives and ensure compliance. Required qualifications include a Bachelor's in a...Full time
- ...SecureITSM SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting... ...and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination... ...training certificates, access reviews, vulnerability scans) Assist with internal policy...For contractorsRemote work
- ...an experienced Cross Domain Solution CDS Program Lead to serve as the technical and programmatic lead for... ...NCDSMO, NIST, and DOD policies and standards Manage RMF A&A lifecycle for CDS environment Manage vulnerability assessment and penetration testing of the CDS...Remote workFlexible hours
- ...Job Description Position: Cybersecurity Lead Clearance: Secret Location:... ...compliance initiatives for the Project Management Office (PMO) within the Department of Defense... ...Review and validate remediation plans for vulnerability scans/testing across hosts, networks,...Full timeTemporary workWork at officeRemote workFlexible hours
- ...Overview SecurePro is seeking experienced Lead and Senior Information System Security... ...Moderate information systems, including Risk Management Framework (RMF) and authorization activities, continuous monitoring, vulnerability management, POA&M execution, security...Contract work
$229.9k - $262.4k
...Overview Senior Lead, Cyber Security (GPN) At Capital One, you will help consult... ...Services, Security & Access Control Management, Container Services, and API Implementation... ...solutions for cyber threats, vulnerabilities, risks, or, events ~7+ years of experience...Full timePart timeH1bLocal area$220k - $250k
...As the Principal Security Team Lead , you are the main senior POC for all security... ...you will assess system security posture, manage compliance activities and monitor, analyze... ...standards, identifying system vulnerabilities, threat vectors, and areas of risk specific...Full timeWork experience placementLocal areaFlexible hours- ...IT Vulnerability Management Lead / Senior Security Analyst Location: Bethesda, MD (Onsite 3–5 days per week) Employment Type: Full-time The National Library of Medicine (NLM) is seeking an IT Security Compliance Lead / Senior Security Analyst to join our...Full timeWork experience placementWork at office3 days per week
$85k - $170k
We are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across... ...develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and...- ...an experienced Information Security Systems Officer (ISSO) to lead RMF, ATO, and continuous monitoring for a major federal initiative... ...NIST 800-53 controls, perform risk assessments, and drive DevSecOps with SIEM and vulnerability tools. #J-18808-Ljbffr 3M HEALTHCARE
- OVERVIEW iTech AG is seeking an IRM Practice Lead - ServiceNow Architect (Integrated Risk Management) to lead the solution architecture for a federal customer... ...linking ServiceNow Security Operations (Vulnerability Response, Configuration Compliance) findings to IRM...Interim roleLocal area
- ...risk-classification criteria for justice-sector personnel and infrastructure. The position requires at least 5 years in threat or vulnerability analysis within law enforcement or intelligence contexts, plus Spanish proficiency and the ability to obtain #J-18808-Ljbffr...Contract work
$112.8k - $257k
...to assess and refine biothreat contingency planning, analyze vulnerabilities, and ensure preparedness against biological hazards in support... ...solutions that integrate into broader CBRN-defense policies. You’ll lead the creation of research-driven deliverables, guide policy...Local area- ...Specialist to support our government customer in Arlington, Virginia. The role is 100% on-site and involves leading RMF and RMF-related activities, vulnerability analysis, and incident response support. Qualified candidates will have a BS in CS or related field, 4-7 years...
$200k
Cybersecurity & Compliance Lead Position Overview One of our clients is seeking a Cybersecurity... ...& Compliance Lead to oversee CMMC management and security infrastructure operations.... ...security policies Proactively manage vulnerabilities and conduct real-time log monitoring to...Full timeContract workFor contractorsWork experience placementSecond jobLocal area- ...Arlington, VA is seeking a Cybersecurity & Compliance Lead responsible for CMMC management and security infrastructure operations. The role requires... ...(firewalls, VPNs, EDR), and manage security policies, vulnerabilities, and real-time log monitoring. #J-18808-Ljbffr BTI...
$140k - $175k
...may oversee staff, support performance management and task delegation, help resolve issues... ...stakeholders while supporting or leading practice, solution, and business development... ...trends, inconsistencies, and potential vulnerabilities Produces clear, well-supported analyses...Work at officeFlexible hours- ...citizenship and an active Top Secret clearance. You will lead auditing efforts in eMASS, manage compliance tasks, and support ATO sustainment while... ...RMF and security directives. Responsibilities include vulnerability assessments, security audits, incident response support...
- ...seeking an experienced Senior Cyber and Risk Management Executive to join our mission-focused... ..., secure AI integration, and leading high performing teams across the Federal... ...security programs Extensive experience with vulnerability analysis and vulnerability management...Live inLocal area
- ...security, and equity. We are seeking a dynamic and strategic Lead, Supplemental Nutrition Assistance Program (SNAP) to bring their... ...findings, elevating lessons learned, and amplifying the voices of vulnerable older adults and the organizations that serve them. Positions...Work at officeNight shift
$120k - $160k
IT State Lead - Security Controls Assessments Sky Solutions is a trusted partner in government... ...in federal security test and evaluations, vulnerability scanning and remediation, Plan of Action and Milestones (POA&M) management, system change management, contingency plan...Full timeContract workLocal areaRemote work- ...responsibilities spanning RMF, FISMA, and DoD cybersecurity compliance, vulnerability analysis, and incident response support. Applicants must hold... ...3 / DCWF certifications. Bachelor’s in CS with 4-7 years in a lead/senior role is required, with strong eMASS experience #J-1880...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Lead. Be the first to apply!
- international management trainee Mc Lean, VA
- director quality management Mc Lean, VA
- threat and vulnerability management engineer Mc Lean, VA
- asset management intern Mc Lean, VA
- director utilization management Mc Lean, VA
- managing attorney Mc Lean, VA
- test data management Mc Lean, VA
- entry level emergency management Mc Lean, VA
- director of managed care Mc Lean, VA
- management team Mc Lean, VA


