Vulnerability Management Engineer (Security)
$81k - $120kNtiva, Inc.
Are you looking for limitless career opportunities with a company that values growth, innovation, and teamwork? At Ntiva, we’re more than a Managed Services Provider, we’re a community dedicated to helping each other, our clients, and their businesses thrive both personally and professionally. Ntiva is a culture of people who are passionate about the work…and each other.
Our clients view us as an essential part of their teams, relying on us for strategic guidance, fast solutions to complex challenges, and proactive support. With strategic locations across the U.S. and leadership from our founder, Steven Freidkin, we’re on the front lines of a fast-paced industry, facing cybersecurity threats and rapid technology changes together.
If you thrive in a dynamic, supportive environment and enjoy going above and beyond, we’d love to meet you. Come explore one of our many opportunities and grow with us!
The scope and responsibilities of this position are accurately represented. Title alignment is still being finalized and reflects the closest match to the role. How you’ll make an Impact As a Vulnerability Management Engineer, you serve as the senior technical advisor for high-risk security remediation, planned security infrastructure changes, and limited post containment recovery for GovCon clients. You are responsible for performing risk based technical analysis, sequencing recommendations, and clearly defining change guardrails that protect system stability, compliance posture, and service margins. This role owns engineering judgment and technical recommendations, not just implementation. You are expected to identify unsafe or insufficiently defined work, recommend delays when requirements are not met, and ensure all changes include clear success, validation, and rollback criteria. Location and Work Expectations
FLSA Status: Salaried, Exempt
Work Authorization Criteria
This position requires U.S. citizenship due to federal government contract obligations and access to secured information systems.
Workspace Requirements and Remote Work Policy
Team members must establish a dedicated safe workspace that is free from distractions, hazards, and that is secure from unauthorized access. This includes following Ntiva’s IT User and Security Policies that include but are not limited to password-protecting all equipment, keeping confidential and proprietary documents secure, refraining from using public Wi-Fi, having adequate arrangements in place to avoid significant interruptions from caregiving responsibilities during work hours (except in emergency situations with manager approval). Any remote work away from a team member’s normal expected dedicated safe workspace must be requested by team member, is subject to review by management, and must adhere to Ntiva policies and procedures.
Our Commitment to a Diverse Workforce
At Ntiva, we are committed to creating and maintaining a diverse, inclusive, and welcoming work environment for all employees and job applicants. We firmly believe that a diverse workforce fosters a wider range of perspectives, experiences, and ideas that lead to increased creativity, innovation, and problem-solving capabilities. As an equal opportunity employer, we actively seek to recruit and retain a diverse workforce that reflects the communities we serve. We prohibit discrimination of any kind, including but not limited to race, color, religion, gender, gender identity or expression, sexual orientation, marital status, national origin, age, hair length, protective hairstyles, organ donor status, disability, veteran status, or any other legally protected status and comply with all applicable laws governing nondiscrimination in employment.
Application Deadline: The sooner you apply, the sooner we can get to know you! Submit your resume today! Applications will be accepted until 6/16/26. Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
Our clients view us as an essential part of their teams, relying on us for strategic guidance, fast solutions to complex challenges, and proactive support. With strategic locations across the U.S. and leadership from our founder, Steven Freidkin, we’re on the front lines of a fast-paced industry, facing cybersecurity threats and rapid technology changes together.
If you thrive in a dynamic, supportive environment and enjoy going above and beyond, we’d love to meet you. Come explore one of our many opportunities and grow with us!
The scope and responsibilities of this position are accurately represented. Title alignment is still being finalized and reflects the closest match to the role. How you’ll make an Impact As a Vulnerability Management Engineer, you serve as the senior technical advisor for high-risk security remediation, planned security infrastructure changes, and limited post containment recovery for GovCon clients. You are responsible for performing risk based technical analysis, sequencing recommendations, and clearly defining change guardrails that protect system stability, compliance posture, and service margins. This role owns engineering judgment and technical recommendations, not just implementation. You are expected to identify unsafe or insufficiently defined work, recommend delays when requirements are not met, and ensure all changes include clear success, validation, and rollback criteria. Location and Work Expectations
- This is a hybrid -remote role with approximately 5% on-site work at client sites throughout the US if needed. The specific allocation of remote versus onsite requirements may fluctuate based on business needs.
- This role also includes participation in a rotating on-call schedule.
- Provide senior level technical recommendations and execution guidance for high-risk remediation and availability impacting security changes.
- Analyze and recommend change sequencing, blast radius reduction strategies, rollback feasibility, and validation requirements.
- Require defined success criteria and rollback plans prior to execution; formally recommend delay or redesign when requirements are insufficient.
- Execute approved proactive security remediation requiring advanced engineering judgment or infrastructure changes.
- Perform approved, availability impacting security changes including firewall, firmware, and network security updates.
- Implement configuration hardening and security control changes across servers, endpoints, and network infrastructure.
- Serve as the senior technical lead for post containment recovery, guiding environments back to a validated steady state following MSSP/SOC containment.
- Coordinate technical recovery activities across company stakeholders, and third-party vendors to prevent uncontrolled rebuild work.
- Validate remediation outcomes against defined technical success criteria and confirm verified closure of findings.
- High-impact and high-risk remediation requiring senior engineering analysis and judgment.
- Planned firewall, firmware, and infrastructure security updates on an approved cadence.
- Availability-impacting security changes executed with defined rollback and validation steps.
- Post-containment recovery technical leadership for:
- Business Email Compromise (BEC)
- Malware mitigation/removal (non-ransomware)
- Foreign or impossible login events (nonforensic)
- EDR agent deployment, health monitoring, and lifecycle management across all endpoints and servers
- EDR Policy configuration, tuning, and optimization aligned to GovCon risk profiles
- Implementation, and maintenance of web filtering security policies
- Review and investigation of web filtering security events
- Review and actioning of MDR threat intelligence and recommendations to enhance client environments
- Participation in quarterly client security posture reviews to assess risk trends and control effectiveness
- Review of DLP policies and tuning to reduce false positives while maintaining protection efficacy
- Review and update of Microsoft Sentinel data connectors
- Other duties as assigned
- 5+ years of experience in Security Engineering, Infrastructure Engineering, or Systems Engineering, with ownership of high impact changes.
- Demonstrated authority executing availability impacting security changes using disciplined rollback and validation practices.
- Strong working knowledge of firewalls, network security devices, and firmware lifecycle management.
- Experience with configuration hardening for Windows and Linux servers.
- Solid understanding of identity, endpoint, and network security controls, including the use of compensating controls.
- Experience leading post incident technical recovery following MSSP/SOC containment, including stabilization and determination of steady state.
- Experience supporting GovCon or compliance driven environments (CMMC, DFARS, ITAR, NIST 800171 preferred).
- Ability to partner effectively with internal teams, vendors, and client stakeholders.
- Strong problem-solving skills with emphasis on stability, predictability, scope enforcement, and verified closure.
- Ability to operate under pressure with a tactful, professional demeanor.
- Ability to communicate professionally, in English, both written and orally
- Ability to write business correspondence and process procedures
- Ability to effectively present information and respond to questions from groups of managers, clients, and the general public
- Medical, Dental and Vision coverage for employee and family
- 401k + company-matched contributions 4% match on 5% contribution - no vesting period! (Employee and Company contribute after 90 days)
- Group Term Life and Accidental Death and Dismemberment coverage (company provided)
- Short-Term (voluntary enrollment) and Long-Term Disability coverage (company provided)
- Health Savings Account (HSA) Options / PPO Options
- Employee Assistance Program
- Paid Time Off (PTO) + Volunteer Time Off (VTO) + 8 Paid Holidays + 3 Floating Holidays
- Education Reimbursement Program
- Generous Employee Referral Program - cash bonus for successful referrals!
- Dynamic Recognition and Rewards
- Clear Promotion and Advancement Tracks
- Work with Industry-Leading Talent
FLSA Status: Salaried, Exempt
Work Authorization Criteria
This position requires U.S. citizenship due to federal government contract obligations and access to secured information systems.
Workspace Requirements and Remote Work Policy
Team members must establish a dedicated safe workspace that is free from distractions, hazards, and that is secure from unauthorized access. This includes following Ntiva’s IT User and Security Policies that include but are not limited to password-protecting all equipment, keeping confidential and proprietary documents secure, refraining from using public Wi-Fi, having adequate arrangements in place to avoid significant interruptions from caregiving responsibilities during work hours (except in emergency situations with manager approval). Any remote work away from a team member’s normal expected dedicated safe workspace must be requested by team member, is subject to review by management, and must adhere to Ntiva policies and procedures.
Our Commitment to a Diverse Workforce
At Ntiva, we are committed to creating and maintaining a diverse, inclusive, and welcoming work environment for all employees and job applicants. We firmly believe that a diverse workforce fosters a wider range of perspectives, experiences, and ideas that lead to increased creativity, innovation, and problem-solving capabilities. As an equal opportunity employer, we actively seek to recruit and retain a diverse workforce that reflects the communities we serve. We prohibit discrimination of any kind, including but not limited to race, color, religion, gender, gender identity or expression, sexual orientation, marital status, national origin, age, hair length, protective hairstyles, organ donor status, disability, veteran status, or any other legally protected status and comply with all applicable laws governing nondiscrimination in employment.
Application Deadline: The sooner you apply, the sooner we can get to know you! Submit your resume today! Applications will be accepted until 6/16/26. Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Vulnerability Management Engineer (Security) in McLean, VA vacancy
$60k - $73k
...Vulnerability Management Analyst Are you looking for limitless career opportunities with a company that values growth, innovation, and... ...impact As a Vulnerability Management Analyst, you support Security Engineers by executing approved security remediation tasks,...SuggestedContract workTemporary workRemote workMonday to Friday- ...Staff Security Engineer (IOT/Embedded Security) Tysons, Virginia The Staff Security Engineer... ..., communicate those risks to management, and assist with the mitigation efforts... ...extraction, reverse engineering, and vulnerability discovery Perform security research...SuggestedCasual workWork at officeImmediate startWorldwide
$170.6k - $390k
...to grow your career in information security! The opportunity The Senior... ...Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal role... ...arsenal, along with threat hunting and vulnerability management. Your business...SuggestedSummer holidayRemote workFlexible hours$130k - $216k
...cybersecurity subject matter expert to help clients maximize the value and effectiveness of their existing security tooling and platforms (e.g., SIEM, EDR, vulnerability management). Assess current cybersecurity tools, configurations, and processes to identify gaps,...SuggestedTemporary workFlexible hours$229.9k - $262.4k
...Senior Lead Information Security Consultant (AI) At Capital One... ..., Security & Access Control Management, Container Services, and API... .... Partner closely with engineers, product managers, and other... ...common AI attack vectors, model vulnerabilities, prompt injection, data...SuggestedFull timePart timeH1bLocal areaShift work- ...Senior Security Engineer Most wealth management is fragmented. Range is building AI-powered wealth management that actually works. One platform –... ...offensive security: red teaming, penetration testing, or vulnerability research ~ Experience assessing cloud...
$115.7k - $150.5k
...is looking for an Information Systems Security Manager (ISSM) to lead onsite cybersecurity... .... The ISSM will work closely with engineering and program leadership to ensure that... ...consistency. Direct risk-based assessments, vulnerability management, and incident response...Temporary workFor contractorsWork experience placementCasual workLocal areaRelocation package- ...Information Systems Security Manager (ISSM) Location: McLean, VA Clearance: TS/SCI w/ Poly Position Overview... ...integrity, confidentiality, and availability. Risk Assessment & Vulnerability Management Conduct risk assessments to identify...
- ...Support information system security topics across multiple organizational... ...secure system lifecycle management. Collaborate with... ...Computer Science, Systems Engineering, Mathematics, Information Systems... ...cyber risks, exploits, vulnerabilities, and associated mitigations...For contractors
- ...Federal business and national security objectives. Our headquarters... ..., data exploitation, and engineering services, specializing in large... ...for developing the Project Management plans and other contract... ...business days when requested. Vulnerability & Configuration Management (...Contract workWork at officeRemote work
- ...Job Family: Management Consulting Travel Required: Up to 10% Clearance Required: Ability to Obtain Public Trust... ...cyber delivery teams. Oversee successful implementation of security tools and capabilities related to Zero Trust pillars. Ensure...Temporary workFlexible hours
$269.1k - $307.2k
...Director, Information Security Officer Cybersecurity is essential... ...about security and risk management. You see security as an enabler... ...platforms, threat and vulnerability management, incident management... ...You enjoy leveraging your engineering experience to problem solve...Full timePart timeH1bWork at officeLocal area- ...McLean, VA, US Who is Saliense? Saliense is a growing Management and Technology Consulting Solutions provider based out of Mclean... ...of the full benefits package. Position Title: Senior Cyber-Security Analyst / Navy Validator Location: Onsite in Arlington, VA...For contractorsWork at officeLocal areaImmediate start
- ...MITRE Network Engineer Opportunity Why choose between doing meaningful... ...safer, healthier, and more secure nation and world. Our... ...Network Security Network Management and Orchestration Network... ...posture, identify threats, vulnerabilities, and control gaps, and recommend...Work experience placementRelocation
- ...safer, healthier, and more secure nation and world. Our workplace... ...within MITRE Technology and Engineering specializes in complex... ...Network Security Network Management and Orchestration Network... ...posture, identify threats, vulnerabilities, and control gaps, and recommend...Work experience placementLocal areaRelocation
$104.8k - $192.2k
...planning, pursuing, delivering and managing engagements to assess,... ...cases operate integrated security operations for our clients.... ...discovering the newest security vulnerabilities, attending and speaking at... ...wireless, web application, social engineering and physical penetration...For contractorsWork experience placementSummer holidayWork at officeLocal areaFlexible hours- ...Lead the detection and continuous monitoring of potential security incidents across diverse network environments. Perform deep... ...normal operations. Integrate threat intelligence and vulnerability management data to proactively identify and defend against emerging risks...Full timeShift workNight shiftDay shiftAfternoon shift
- ...client, a pioneer in proactive exposure management and winner of the SC Award for Best CTEM... ...helps organizations see, understand, and secure their hybrid digital environments across... ...team as a Senior Network Security Engineering Consultant and directly impact our clients...Remote work
$107.9k - $195.05k
...seeking an experienced M365 Security and Compliance Administrator... ...professional who can strategically manage and enhance the security and... ...agency context. This senior engineering role sits at the center of... ...engineering responses to vulnerabilities, outages, and operational...Local areaImmediate startNight shiftDay shift- ...Information Systems Security Manager (ISSM) We are looking for a dedicated and results-driven Information Systems Security Manager (ISSM) to lead and oversee the security management of our information systems. In this pivotal role, you will be responsible for ensuring...Temporary workFor contractorsImmediate startFlexible hours
- ...policies and controls, increase transparency and performance management, and comply with Federal laws and regulations. The nature... ...role will support a Government agency within the homeland security enterprise with opportunities to expand your support to other...Temporary workFlexible hours
- ...skilled and motivated Network Engineering Analyst with a TS/SCI... ...integrity, efficiency, and vulnerabilities. Duties & Responsibilities... ...in network monitoring and management tools (e.g., SolarWinds, Wireshark... ..., IDS/IPS, and network security best practices Scripting...
$229.9k - $262.4k
...Overview Senior Manager, Information Security Office (AI) Consultant At Capital One, the AIML... ...background in application security engineering, and be eager to take on challenges... ...Drive continuous improvement through vulnerability assessments, risk remediation, and...Full timePart timeH1bWork at officeLocal area$150k - $224k
...an exciting and challenging opportunity for a Technical Lead of Security Architecture. The focus will be on improving security designs... ...threats while looking for opportunities to optimize, consolidate and manage out tools that no longer meet company needs. Automate...Full timeLocal area$131.3k - $237.35k
...opportunity for an Enterprise Architect/Systems Engineer in our Intel Sector Analysis Solutions... ...talented team is at the forefront in Security Engineering, Computer Network Operations... ...(SIGINT), and Cryptographic Key Management. At Leidos , we offer competitive benefits...Local areaImmediate startFlexible hours$90k - $140k
...you to be a Senior?Information Systems Security Officer (ISSO) on our team?to support a... ...Memos to assist in the effective management of?system risks Conduct an annual assessment... ...and respond to Information Security Vulnerability Management (ISVM)/Patch Management Provide...Local areaFlexible hours- ...Senior Information System Security Officer Join our team at Core... ...and assessments. Conduct vulnerability scanning, compliance checks,... ...with system owners, engineers, and developers to ensure security... ...remediation of security incidents. Manage account recertifications,...
$140k - $160k
...Information Systems Security Officer (ISSO), Mid (MCSES III)... ...Evaluation, Program Mission Support, Engineering & Analysis, and Training.... ...Systems Security Managers (ISSM), Program Security Officers... ...basis to identify potential vulnerabilities, evaluate the effectiveness...Full timeFor contractorsRemote work$115k - $175k
...Information Systems Security Officer (ISSO) - Navy Job Locations US-VA-Tysons... ...with Department of Defense (DoD) Risk Management Framework (RMF) and FedRAMP... ...ongoing security assessments, audits, and vulnerability scans, ensuring compliance with DoD guidelines...Full timeContract workWork at officeLocal area- ...Federal Information System Security Officer (ISSO) Location:... ...and oversight Partner with engineering, cloud infrastructure, and... ...collection, reporting, and risk management tracking Assist in... ...access management, encryption, vulnerability management, and logging/monitoring...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Engineer (Security). Be the first to apply!
Related searches
- cyber security analyst McLean, VA
- information security consultant McLean, VA
- analyst asset management McLean, VA
- asset management intern McLean, VA
- utilization management nurse McLean, VA
- aviation management McLean, VA
- data management associate McLean, VA
- management team McLean, VA
- management development program McLean, VA
- property management specialist McLean, VA



