Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Cybersecurity Engineer - Vulnerability & Configuration Management

True Zero Technologies, LLC

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories ("Prosperous and Thriving" ($5MM-$50MM in gross revenue) and "Mid-Atlantic Region" (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025 , a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

This candidate will lead risk-based asset management efforts across vulnerability management, configuration management, and database hardening in support of a federal cybersecurity program. Additionally, this role will coordinate technical activities, guide prioritization based on business and security risk, and provide leadership visibility into remediation progress, operational gaps, and program performance. This position calls for a blend of hands-on technical depth and team leadership, with responsibility for driving process improvement, supporting automation, and helping mature enterprise security practices.

Job Responsibilities

    • Oversee RBAM projects, schedules, milestones, and team execution
    • Facilitate meetings and brief leadership on status, risks, priorities, and progress
    • Lead and coordinate vulnerability management activities across enterprise systems, including vulnerability identification, prioritization, remediation tracking, and validation
    • Oversee remediation efforts by working with system owners, engineers, administrators, database teams, and other stakeholders to ensure timely and risk-informed mitigation
    • Apply knowledge of CVE, CVSS, NVD, and the CISA KEV catalog to support risk-based vulnerability prioritization and remediation sequencing
    • Establish, manage, and enforce configuration baselines across Windows, Linux, network, cloud, containerized, and database environments
    • Incorporate security configuration baselines into configuration management processes, including operating system image hardening, automation, audit, and compliance validation
    • Support configuration management practices aligned with NIST SP 800-128 and other applicable federal guidance
    • Coordinate database hardening activities across relational, NoSQL, and cloud-native database environments
    • Apply DISA STIGs, CIS Benchmarks, and hardening best practices to support secure database configuration and compliance
    • Assess on-premises and cloud-hosted database environments for security posture, hardening compliance, logging, encryption, data masking, and audit readiness.
    • Use scanning and validation tools to verify database hardening compliance and identify configuration gaps
    • Translate audit requirements into actionable technical configurations, remediation tasks, dashboards, reports, and evidence artifacts
    • Develop, modify, and maintain dashboards and reports in Splunk or similar SIEM platforms to support leadership visibility, operational tracking, and program performance.
    • Use enterprise ticketing systems such as ServiceNow to document findings, assign remediation actions, track progress, and support auditability
    • Support automation through scripting, Splunk searches, and repeatable workflows using tools such as Python, PowerShell, Bash, or similar technologies
    • Support DevSecOps and CI/CD pipeline activities by helping integrate vulnerability management, configuration validation, and hardening requirements into development and deployment processes.
    • Coordinate with technical teams to ensure remediation, configuration, and database security activities are properly documented and supported by evidence
    • Provide technical guidance to stakeholders on remediation priorities, configuration risk, database hardening, and cyber hygiene improvement.
    • Support recurring reporting on vulnerability trends, remediation progress, configuration compliance, database hardening status, operational gaps, and risk reduction.
    • Help mature the risk-based asset management program by improving processes, automation, reporting, evidence generation, and stakeholder coordination
    • Direct and support enterprise vulnerability scanning, analysis, remediation prioritization, and reporting
    • Guide the development and enforcement of secure configuration baselines across systems and platforms
    • Coordinate database hardening, patching, scanning, and compliance activities with stakeholders
    • Review cyber hygiene findings and translate results into actionable remediation plans
    • Support evaluation of new technologies and products through security review and software approval processes
    • Develop or enhance dashboards, reporting, and metrics to improve visibility into risk and remediation progress
    • Support process improvement, automation, and operational maturity efforts across the RBAM function
    • Ensure work products, reporting, and technical activities align with DHS, client, and federal cybersecurity expectations
    • Lead and coordinate vulnerability management, configuration management, and database hardening activities
Job Qualifications
  • Bachelor's degree in Information Technology, Information Systems, Computer Science, Computer Engineering, Electrical Engineering, or related technical field; or equivalent additional experience
  • 7+ years of total professional experience
  • 5+ years of technical experience in vulnerability management, configuration management, database hardening, or related security operations
  • Experience leading technical teams or workstreams in dynamic environments
  • Strong experience managing vulnerability remediation efforts across enterprise environments
  • Experience using vulnerability scanning tools such as Tenable/Nessus
  • Strong experience establishing, maintaining, and enforcing configuration baselines
  • Familiarity with remediation practices across Windows, Linux, network devices, containers, and cloud platforms
  • Strong knowledge of CVE, CVSS, NVD, and the CISA KEV catalog
  • Strong knowledge of configuration management principles and secure baseline enforcement
  • Familiarity with DISA STIGs, CIS Benchmarks, and secure hardening practices
  • Experience with enterprise dashboards, reporting, and ticketing workflows
  • Experience with scripting and automation using tools such as Python, PowerShell, Bash, or similar
  • Experience with a wide range of database technologies including:
    • Relational databases: Oracle, PostgreSQL, MySQL, MS SQL
    • NoSQL Databases: MongoDB
    • Cloud-native databases: AmazonRDS, Azure SQL, DynamoDB
  • Familiarity with DevSecOps and CI/CD pipeline concepts
  • Ability to assess and secure on-premises and cloud-hosted database environments
  • Experience with audit logging, encryption, masking, and technical evidence generation for compliance needs
  • Strong written and verbal communication skills
Required Certifications
  • One active certification such as CASP, GSEC, GSLC, CISSP, CEH, CISM, CISA, or comparable
  • One active Agile certification such as PMI-ACP, SAFe Agilist, CSM, or comparable


We're actively searching for talented and expereinced professionals who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:

- Competitive salary, paid twice per month

- Best in class medical coverage

- 100% of medical premiums covered by True Zero

- Company wide new business incentive programs

- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)

- 3 weeks of PTO starting + 11 Paid Holidays Annually

- 401k Program with 100% company match on the first 4%

- Monthly reimbursement of Cell Phone and Home Internet costs

- Paternity/Maternity Leave

- Investment in training and certifications to broaden and deepen your technical skills

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Lead Cybersecurity Engineer - Vulnerability & Configuration Management in United States vacancy
  •  ...Risk-Based Asset Management Leader True Zero...  ...This candidate will lead risk-based asset management...  ...efforts across vulnerability management, configuration management, and...  ...support of a federal cybersecurity program....  ...with system owners, engineers, administrators, database... 
    Suggested
    Remote work

    True Zero Technologies, LLC

    United States
    2 days ago
  • $122.9k - $150k

     ...The PKI Lead Engineer serves as the senior technical...  ...leads the lifecycle management of digital certificates...  ...related incidents, vulnerabilities, and findings, including...  ...'s degree in Cybersecurity, Information Technology...  ...Leverages scripting, configuration management, and PKI... 
    Suggested
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Providence, RI
    2 days ago
  •  ...Lead Cybersecurity Engineer The Lead Cybersecurity Engineer shall have a bachelor...  ...engineering and management experience. This position...  ...sophisticated cyber threats and vulnerabilities or detect when prevention...  ...with the utilization, configuration, and implementation of... 
    Suggested

    CDIT

    Scott Air Force Base, IL
    4 days ago
  • $128.89k - $184.12k

     .... Our capabilities in cybersecurity, network architecture, reverse engineering, software and hardware...  ...Mission Technologies is leading the next evolution of...  ...Vulernatiblity Management Lead to work out of Fairfax...  ...• Leads coordinated vulnerability management operations... 
    Suggested
    Full time
    Contract work
    Work at office
    Local area
    Worldwide

    Huntington Ingalls Industries

    Fairfax, VA
    2 days ago
  • $140k - $165k

     ...our network for a Lead IAM Engineer at a leading energy...  ...implementation, and management of enterprise Identity...  ...gaps and vulnerabilities within the IAM domain...  ...Computer Science, Cybersecurity, Information Systems...  ...tasks, managing system configurations, and enhancing operational... 
    Suggested
    Remote job
    Permanent employment
    Full time
    Temporary work

    Estreetsecurity

    Queens Village, NY
    13 hours ago
  •  ...Our client, a leading organization in the technology and...  ...a Information Security Engineer 4 - Contingent to join their...  ...you will be part of the Cybersecurity - Vulnerability & Patch Management organization supporting...  ...Job? Implement, configure, and manage the Wiz... 

    Experis/Manpower Group

    Charlotte, NC
    4 days ago
  • $82.1k - $172.5k

     ...career in banking at Fifth Third Bank. The Lead Information Security Engineer on the Enterprise Vulnerability Management (EVM) Remediation team will support the...  ...workflows. Hands-on experience implementing cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS... 

    Fifth Third Bank, N.A.

    Ohio
    3 days ago
  •  ...Salesforce Technical Lead Peraton is seeking...  ...governance, incident management, deployment, and operational...  ...stakeholders, cybersecurity teams, infrastructure...  ...requirements. Support vulnerability remediation and...  ..., and authentication configurations. Enforce change management... 
    Permanent employment
    Work at office
    Remote work
    Monday to Friday
    Flexible hours
    Night shift
    1 day per week

    Peraton

    Washington DC
    4 days ago
  • $65 - $70 per hour

     ...Solutions is immediately hiring for a Lead Software Engineer - Identity & Access Management. Position type: Contract (12...  .... Collaborate with cybersecurity and IAM teams to strengthen access...  .... Document processes, configurations, and standards for audit and compliance... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    Innova Solutions

    Charlotte, NC
    8 hours ago
  •  ...Lead Software Engineer We have an opportunity to impact your career and provide an adventure...  ...stack, including build and configuration management, and log/metric aggregation Interface...  ...staff by virtue of 1) sensitive cybersecurity and technology functions they... 

    Chase

    Jersey City, NJ
    1 day ago
  • $100k - $150k

     ...Position: Lead Software Engineer Location: Huntsville, AL Job Id:...  ...agencies seeking innovative Cloud, Cybersecurity, Knowledge Management, and Enterprise solutions. We know...  ...technical documentation and software configuration management. Minimum... 
    Contract work

    Indigo IT

    Huntsville, AL
    13 hours ago
  •  ...A leading federal technology organization is seeking...  ...Lead Coralogix SIEM Engineer for a remote...  ...security operations, log management, and detection engineering...  ...0+ years of hands-on cybersecurity engineering...  ...rules, TCO Optimizer configuration, and log pipeline design... 
    Remote work
    Monday to Friday
    Shift work
    Day shift

    Tandym Group

    United States
    1 day ago
  • $82k - $85k

     ...Support III / Support Lead The Tech...  ...standardized builds, secure configurations, and adherence to...  ...Configuration Manager or equivalent...  ...collaboration with network engineering staff. Work closely with cybersecurity and network teams to perform vulnerability remediation, risk... 
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    Flexible hours

    Cayuse Holdings

    Los Angeles, CA
    1 day ago
  • $105k - $165k

     ...is an industry-leading home, security and...  ...Infrastructure Engineer plays a critical...  ...implementing, and managing the backbone of...  ...the deployment, configuration, and maintenance...  ...development, cybersecurity, enterprise architecture...  ...systems for vulnerabilities and respond... 
    Remote work
    Flexible hours

    Fortune Brands

    United States
    13 hours ago
  •  ...Lead Infrastructure Engineer The Lead Infrastructure Engineer...  ...implementing, and managing the backbone of FBIN...  ...the deployment, configuration, and maintenance of...  ...software development, cybersecurity, enterprise...  ...Monitor systems for vulnerabilities and respond proactively... 

    Fortune Brands

    North Olmsted, OH
    1 day ago
  • $149.1k - $218.9k

     ...1049 - Security Engineer Technical Leader...  ...compliance and risk management solutions that...  ...Technical Lead plays a critical...  ...of experience in cybersecurity, security engineering...  ...assessments, configuration validation, compliance...  ...checks, or vulnerability management workflows... 
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours

    Cisco

    United States
    1 day ago
  •  ...Role: Enterprise Architect or Lead Engineer/Security/Governance/Banking...  ...is required for the vendor Management system. SKILL MATRIX:...  ...development, infrastructure, cloud, cybersecurity, data) as well as extensive...  ...accounts and sensitive configuration files ~ Ability to... 
    Work at office
    Local area

    InterSources

    Fremont, CA
    3 days ago
  •  ...65 CE Sr. Application Engineer The Dynamics 365 CE Sr...  ...engage with clients and manage operations....  ...successful Tyler Identity configuration, identifying process improvement...  ...to generate new sales leads, and provides sales...  ...to join our team! Cybersecurity Intern Tyler Technologies... 
    Contract work
    Temporary work
    Summer work
    Internship
    Work at office
    Local area
    Immediate start

    Tyler Technologies, Inc.

    Plano, TX
    2 days ago
  • $112.8k - $257k

     ...seeking a Program Manager to support a...  ...facing delivery lead for a complex, high...  ..., product, engineering, architecture, integration...  ..., data, cybersecurity, and DevSecOps teams...  ..., including configuration versus code tradeoffs...  ...800‑53, STIGs, vulnerability management, POA&... 
    Local area

    Phase2 Technology

    Arlington, VA
    13 hours ago
  • $205.1k - $307.7k

     ...readiness, and cybersecurity within the QMS are...  ...establish and lead Illumina's standalone...  ...quality engineers with depth in IEC...  ...2304, SaMD risk management, and cybersecurity...  ..., cybersecurity vulnerability tracking, and SOUP...  ..., software configuration management, and... 
    Local area

    Illumina

    San Diego, CA
    1 day ago
  •  ...IT Technical Lead McLean, VA About Vest Vest Financial...  ...rapidly growing investment management firm specializing in Target...  ...software installation conflicts, configuration challenges Partner with...  ...Execution Execute on cybersecurity controls appropriate for an... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Vest

    McLean, VA
    13 hours ago
  • $150k - $224k

     ...Privileged Access Management Technical Lead At Freddie Mac, our mission...  ...ready to lead the charge in cybersecurity? We're on the hunt for a...  ...If you have a passion for engineering, automation, and...  ...~ Familiarity with SEIM configuration and management. ~ Proficient... 
    Full time
    Local area

    Freddie Mac

    McLean, VA
    3 days ago
  • $170.9k - $241.4k

     ...With intelligent agreement management, Docusign unleashes...  ...CLM). What you’ll do As a Lead Security Tools Engineer on the Security Solutions...  ...maintain documentation for tool configurations, integrations, and...  ...experience 12+ years of cybersecurity or IT experience, with 8+... 
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign, Inc.

    Chicago, IL
    13 hours ago
  •  ...quality assurance oversight lead for NA-11’s Program Management Information System (PMIS...  ...and overseeing the configuration process MINIMUM QUALIFICATIONS...  ...knowledge of federal cybersecurity compliance requirements...  ...offers technical, engineering, and programmatic support... 
    For contractors

    Mele Accociates

    Washington DC
    2 days ago
  •  ...Cybersecurity Operations Technical Lead (SOC Engineer/SME) The Cybersecurity Operations Technical Lead (SOC Engineer/SME) serves as the senior technical...  ...detection and analysis, incident response, vulnerability management, threat hunting, SIEM/EDR operations,... 

    cFocus Software

    United States
    4 days ago
  •  ...Software Engineering And Development Technical Lead/Architect Sme Everforth ECS is seeking...  .../CD pipelines, and code management practices with enterprise architectures and cybersecurity mandates. • Conducts...  ...compliance against approved configuration baselines and DevSecOps... 
    Contract work

    ECS Limited

    Falls Church, VA
    20 hours ago
  • $95 - $125 per hour

     ...Job Summary: Our client is seeking a Secure Configuration Management (SCM) Subject-Matter Expert / Technical Lead to join their team! This position is located...  ...groups across broad stakeholder groups, including cybersecurity and IT operations communities Produce... 
    Local area

    KellyMitchell Group

    Bethesda, MD
    2 days ago
  •  ...API Enterprise Engineer We are hiring an API Enterprise...  ...for global API Management & integration...  ...in: Setup and configuration of the Apigee platform...  ...Identifying and deploying cybersecurity measures by continuously performing vulnerability assessment and risk management... 

    Omni Inclusive

    Alpharetta, GA
    4 days ago
  •  ...Lead Information Security Engineer The Lead Information Security Engineer...  ...oversees and manages engineering of information...  ...reliability, configuration, upgrades,...  ...of experience in cybersecurity with a focus on engineering...  ...systems, and vulnerability management applications... 
    Full time
    Work experience placement
    Remote work
    Shift work

    Children's National Health System

    United States
    1 day ago
  •  ...Key Responsibilities: Lead all cybersecurity, compliance, and information...  ...assurance activities. Manage RMF packages, develop and...  ..., RAR, POA&M). Oversee vulnerability scanning, STIG compliance,...  ...cybersecurity expertise to configuration management and project teams... 

    Gbti Solutions

    Quantico, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Cybersecurity Engineer - Vulnerability & Configuration Management. Be the first to apply!