ECS

SOC Vulnerability Management Manager - Senior

ECS$110K — $140K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in cybersecurity
  • Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, IT, or Software Engineering
  • Eligible for Secret Security Clearance
  • Certifications such as CEH(P), Cloud+, Security+, or other relevant security credentials
  • Demonstrated ability to lead vulnerability management operations effectively

Responsibilities

  • Lead enterprise vulnerability management activities across ARNG environments
  • Establish and enforce governance for vulnerability processes
  • Oversee POA&M management for high-risk findings
  • Coordinate with teams to mitigate vulnerabilities and operational cyber risk
  • Monitor performance metrics and analyze trends for compliance management
  • Integrate vulnerability management with broader cybersecurity operations
  • Support collaboration with external cybersecurity stakeholders

Benefits

  • Opportunity to support a mission serving over 120,000 users
  • Work within a comprehensive cybersecurity ecosystem including 24x7 SOC operations
  • Direct contribution to national cybersecurity efforts through the ARNG
  • Engagement with advanced cybersecurity processes and frameworks
  • Flexible work arrangements contingent upon contract award
Full Job Description
Position Summary

ECS is seeking a SOC Vulnerability Management Manager - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This senior role supports Task 3 - Cybersecurity Operations Support by leading enterprise vulnerability management operations across ARNG classified and unclassified network environments. The position directs vulnerability scanning execution, remediation prioritization, exception handling, compliance reporting, and POA&M management while coordinating closely with system owners, ISSOs, engineering teams, and SOC personnel to reduce enterprise cyber risk. As part of the broader ENOCS cybersecurity team, this role contributes directly to Defensive Cyberspace Operations - Internal Defensive Measures (DCO-IDM), continuous monitoring, and audit-ready cybersecurity operations across the DoDIN-Army-NG area of responsibility.

This position supports a mission environment serving more than 120,000 users and approximately 141,000 endpoints across roughly 2,800 sites in 54 states and territories, helping sustain ARNG Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and classified SIPRNet operations. The SOC Vulnerability Management Manager - Senior operates within an enterprise cybersecurity ecosystem that includes 24x7x365 SOC operations, RMF processes, eMASS updates and integration, USIEM analytics, IDS/IPS and EDR-enabled monitoring, and coordination with the NETCOM Global Cyber Center and DISA DCDC. The role helps ensure vulnerabilities are identified, tracked, mitigated, and reported in alignment with STIGs, IAVMs, DoD and ARNG cybersecurity directives, and the operational needs of the ARNG enterprise.

Please Note: This position is contingent upon contract award.

Responsibilities

  • Lead enterprise vulnerability management activities across supported ARNG environments, including scanning execution, finding validation, remediation prioritization, exception handling, and closure tracking.
  • Establish and enforce governance processes for vulnerability identification, validation, reporting, and remediation in alignment with STIGs, IAVMs, RMF requirements, and ARNG and DoD cybersecurity directives.
  • Oversee POA&M management to ensure high-risk findings are accurately documented, tracked to resolution, and reflected in continuous monitoring and compliance reporting.
  • Coordinate with system owners, ISSOs, engineering teams, and SOC personnel to drive timely mitigation of vulnerabilities and reduce operational cyber risk across classified and unclassified enclaves.
  • Monitor vulnerability management performance metrics, analyze trends, and provide leadership reporting that supports audit readiness, compliance management, and sustained risk reduction across the enterprise.
  • Support Task 3 deliverables by integrating vulnerability management activities with broader cybersecurity operations, including continuous monitoring, secure baseline configuration, and compliance validation.
  • Coordinate vulnerability management actions with ARNG cybersecurity stakeholders and external operational partners, including the NETCOM Global Cyber Center and DISA DCDC, to support DCO-IDM objectives across the DoDIN-A(NG) area of responsibility.
  • Contribute to eMASS update and integration activities and ensure vulnerability artifacts, compliance status, and remediation actions are aligned with RMF support processes.
  • Help inform enterprise defense by aligning vulnerability findings with SOC monitoring and analysis functions, including data flowing through USIEM, IDS/IPS, and related security operations processes.


Required Qualifications

U.S. Citizenship is required

Security Clearance: Secret Eligible

Required Certifications: DCWF Work Role 541-Vulnerability Assessment Analyst - Intermediate proficiency; must hold ONE OR MORE of the following: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, Security+,

Experience: 7+ years of experience in cybersecurity

Education: Bachelors degree or higher in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
  • Demonstrated ability to lead vulnerability management operations, including remediation prioritization, exception handling, compliance reporting, and closure tracking.
  • Experience managing vulnerability findings in alignment with STIGs, IAVMs, RMF requirements, and DoD or ARNG cybersecurity directives.
  • Experience coordinating remediation and risk reduction activities with system owners, ISSOs, engineering teams, and security operations personnel.
  • Experience developing or maintaining POA&Ms and supporting continuous monitoring and audit readiness activities.
  • Ability to analyze vulnerability metrics and trends and present actionable status and risk information to leadership.
  • Experience supporting cybersecurity operations in classified and unclassified network environments.
  • Experience contributing to compliance management and artifact maintenance, including eMASS update or integration activities.

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

  • ECS
    Analytic Engineer
    $90K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Falls Church, VA 22042 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Senior Governance Training Specialist
    $100K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Education, Government & Non-Profit
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Washington, DC 20310 (District Of Columbia County)
    Aerospace & Defense
    In-Person
  • ECS
    Senior Governance Training Specialist
    $100K — $130K *
    Falls Church, VA 22042 (Fairfax County)
    Education, Government & Non-Profit
    In-Person

More Aerospace & Defense Jobs

Find similar SOC Vulnerability Management Manager - Senior jobs: