Cybersecurity Vulnerability Management Lead

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Cybersecurity Vulnerability Management Lead modernizing the NSF Cybersecurity Program for Cherokee Federal. Leading exposure management, prioritization, automation, and enterprise risk reduction.

Responsibilities:

  • Lead and mature NSF's Vulnerability Management capability across enterprise, cloud, containerized, application, and hybrid environments
  • Provide technical leadership to a team of vulnerability analysts
  • Develop and maintain a Vulnerability Management roadmap aligned with evolving threats and organizational priorities
  • Introduce and operationalize prioritization using CISA KEV, EPSS, threat intelligence, asset criticality, internet-facing asset identification, attack path analysis, and MITRE ATT&CK mapping
  • Evaluate emerging technologies for vulnerability validation, attack surface visibility, and exposure management
  • Own discovery, validation, prioritization, remediation coordination, exception handling, verification, and executive reporting
  • Operate and optimize Tenable.sc, Tenable.io, and Nessus
  • Improve scan coverage, credential management, accuracy, and false-positive reduction
  • Integrate AWS Inspector, Security Hub, GuardDuty, Wiz, Prisma Cloud, and Microsoft Defender for Cloud findings
  • Partner with Application Security and DevSecOps teams on AppScan, DAST, SAST, CI/CD integrations, and container image scanning
  • Mature ServiceNow Vulnerability Response and CMDB integrations, including ticketing, SLA tracking, ownership, and escalation workflows
  • Develop automation through APIs, Python, PowerShell, and orchestration capabilities
  • Build executive dashboards and metrics covering MTTR, SLA adherence, vulnerability aging, exposure trends, scan coverage, and remediation effectiveness
  • Brief cybersecurity leadership on emerging risks, remediation progress, and program maturity initiatives

Requirements:

  • 8+ years of cybersecurity experience
  • 4+ years of direct Vulnerability Management experience in a federal or large enterprise environment
  • 3+ years leading vulnerability analysts, remediation programs, or enterprise VM initiatives
  • Deep hands-on expertise with Tenable.sc, Tenable.io, and Nessus
  • Experience implementing or significantly improving a Vulnerability Management or Exposure Management capability
  • Experience with ServiceNow Vulnerability Response and CMDB integrations
  • Experience leveraging CISA KEV, EPSS, threat intelligence, asset criticality, and attack path analysis
  • Experience supporting AWS, Azure, or hybrid cloud environments
  • Experience collaborating with Security Operations and Incident Response teams to identify and rapidly remediate actively exploited vulnerabilities
  • Experience briefing technical teams, executives, and federal stakeholders
  • Candidates must pass pre-employment qualifications of Cherokee Federal
  • Preferred certifications include CISSP, GCIH, CySA+, Security+, Tenable Certified Professional, AWS Security Specialty, and ServiceNow Vulnerability Response Certification
  • Highly desired experience includes SafeBreach, AttackIQ, Pentera, XM Cyber, Wiz, Prisma Cloud, AppScan, BAS, CCV, EASM, Kubernetes Security, and Detection Engineering

Benefits:

  • Equal opportunity employer
  • Pre-employment qualifications required
  • Opportunity to support a strategic modernization effort within the NSF Cybersecurity Program
  • Highly visible role with technical leadership responsibility