Steampunk

Vulnerability Management Lead

Steampunk$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. government Security Clearance required.
  • Bachelor's in Cybersecurity, IT, Computer Science, or related field.
  • 5+ years in enterprise vulnerability management and cybersecurity operations.
  • Experience with over 30,000 assets including servers and cloud platforms.
  • Proven track record in risk-based prioritization methodologies.
  • Expertise in automation and AI/ML for vulnerability management.
  • Strong understanding of NIST SP 800-53 and federal cybersecurity directives.

Responsibilities

  • Lead the enterprise vulnerability management program for 30,000+ assets.
  • Plan and oversee vulnerability scanning and remediation tracking.
  • Collaborate with cross-functional teams for vulnerability identification and tracking.
  • Develop risk-based prioritization methodologies for vulnerability management.
  • Drive remediation activities complying with federal directives and security policies.
  • Enhance vulnerability management processes and automation solutions.
  • Create enterprise dashboards and reporting tools using BI platforms.

Benefits

  • Comprehensive healthcare coverage.
  • Flexible work arrangements.
  • Professional development opportunities.
  • Collaborative work environment.
  • Exposure to cutting-edge cybersecurity technologies.
Full Job Description
Overview

We are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT environment supporting more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads, and network infrastructure.

 

The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and system owners to identify, prioritize, and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes, improving automation and reporting capabilities, and ensuring alignment with federal cybersecurity directives, NIST guidance, and organizational security policies.

 

Contributions

Responsibilities include:

  • Lead the enterprise vulnerability management program across servers, workstations, HPC systems, cloud environments, and network devices supporting more than 30,000 managed assets.
  • Plan, coordinate, and oversee enterprise vulnerability scanning, assessment, prioritization, remediation tracking, validation, and reporting activities.
  • Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.
  • Develop and maintain risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.
  • Drive enterprise remediation activities in alignment with applicable federal directives, including Binding Operational Directive (BOD) 22-01, and organizational security requirements.
  • Develop and enhance enterprise vulnerability management processes, procedures, templates, and operational standards.
  • Design and implement automation solutions that improve vulnerability data collection, remediation tracking, reporting, and operational efficiency.
  • Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction across the enterprise vulnerability management program.
  • Develop and maintain enterprise dashboards, weekly reporting, and executive visualizations utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.
  • Identify tool, process, and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program.
  • Ensure vulnerability management activities align with NIST SP 800-53, organizational policies, and applicable federal cybersecurity directives, including BOD 22-01.
  • Develop and maintain vulnerability management documentation, including standard operating procedures (SOPs), remediation guidance, risk mitigation strategies, process improvement plans, and automation roadmaps.
  • Identify opportunities to improve enterprise vulnerability management through process optimization, workflow improvements, enhanced automation, and data quality initiatives.
  • Support continuous monitoring activities and collaborate with stakeholders to strengthen the organization's overall cybersecurity posture.
  • Stay current on emerging vulnerabilities, threat intelligence, federal cybersecurity directives, and industry best practices.

 

Qualifications

Required

  • Ability to obtain and maintain a U.S. government Security Clearance.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience).
  • Minimum of 5 years of hands-on experience supporting enterprise vulnerability management, cybersecurity operations, and risk remediation workflows.
  • Experience managing enterprise vulnerability management programs across more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads (AWS, Azure, and Google Cloud Platform), and network devices while driving patching and remediation activities in accordance with BOD 22-01.
  • Experience collaborating with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.
  • Experience developing and implementing risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.
  • Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction.
  • Experience developing enterprise dashboards, weekly reporting, and operational metrics utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.
  • Experience identifying enterprise tool, process, and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans.
  • Experience developing enterprise vulnerability management processes, standard operating procedures, documentation, and continuous process improvement initiatives.
  • Strong knowledge of federal cybersecurity requirements, including NIST SP 800-53 and applicable federal vulnerability management directives.
  • Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders.

Preferred

  • Experience supporting cybersecurity programs within a federal government environment.
  • Experience supporting enterprise continuous monitoring initiatives.
  • One or more of the following certifications:
    • CompTIA Security+
    • CISSP
    • CISM
    • CISA
    • CCSP
    • OSCP

 

Similar Jobs

More Jobs at Steampunk

More Information Technology Jobs

Find similar Vulnerability Management Lead jobs: