Vulnerability Management Lead (R-00190)

3 days, 16 hours ago
Full-time
Senior
Cybersecurity
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Lead the enterprise Vulnerability Management and Continuous Diagnostics and Mitigation (CDM) program.
  • Direct vulnerability scanning across infrastructure, cloud, endpoints, network devices, and applications.
  • Prioritize vulnerabilities using exploitability, mission impact, Known Exploited Vulnerabilities (KEVs), threat intelligence, and operational context.
  • Coordinate remediation with system owners, engineering teams, and ISSOs to reduce cyber risk.
  • Track remediation progress, validate corrective actions, and manage vulnerabilities through POA&M and RMF processes.
  • Lead recurring vulnerability review meetings and communicate remediation priorities to Government stakeholders.
  • Develop executive dashboards, metrics, and reports on vulnerability posture, remediation performance, and risk trends.
  • Coordinate with penetration testing personnel to validate attack paths and remediation effectiveness.
  • Collaborate with incident response and threat intelligence teams to reprioritize vulnerabilities based on emerging threats.
  • Support Continuous Monitoring and federal cybersecurity reporting requirements.
  • Recommend improvements to vulnerability management processes, automation, workflows, and security tooling.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field.
  • 5+ years of experience leading enterprise vulnerability management, exposure management, or cybersecurity operations programs.
  • Experience managing enterprise vulnerability scanning platforms and remediation in large, distributed environments.
  • Strong understanding of CVSS, Known Exploited Vulnerabilities (KEVs), threat intelligence, and attack surface management.
  • Experience supporting Federal cybersecurity programs under FISMA and the NIST Risk Management Framework (RMF).
  • Experience developing executive reporting, operational dashboards, and cybersecurity performance metrics.
  • Strong leadership, communication, and stakeholder management skills.
  • Experience supporting NIH, HHS, or other Federal civilian agencies (preferred).
  • Experience with Tenable, Qualys, Rapid7, or similar vulnerability management platforms (preferred).
  • Experience supporting CDM programs, integrating vulnerability management with RMF/POA&M/continuous monitoring, and working with cloud security, Zero Trust, or penetration testing programs (preferred).
  • Preferred certifications include CISSP, GCVA, CySA+, GMON, CGRC, Security+, or CEH.

Benefits

  • Competitive salary, paid twice per month.
  • Best-in-class medical coverage with 100% of medical premiums covered by True Zero.
  • Company-wide new business incentive programs.
  • Contribution incentives for white papers, blog posts, and internal webinars.
  • 3 weeks of PTO to start plus 11 paid holidays annually.
  • 401(k) with 100% company match on the first 4%.
  • Monthly reimbursement for cell phone and home internet costs.
  • Paternity/maternity leave.
  • Investment in training and certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer

Hummingbird 1K-5K Professional Services

Hummingbird is hiring a Senior Security Engineer to own and strengthen security for its remote-first SaaS platform that helps financial institutions fight financial crime.

AWS Azure CircleCI Docker Encryption GraphQL JavaScript Network Security PostgreSQL Python React Redis Ruby Ruby on Rails Terraform TypeScript
1 day, 15 hours ago

Principal IAM Engineer Consultant

Kalles Group 11-50 Internet Software & Services

Kalles Group is hiring a remote Principal IAM Engineer Consultant to lead engineering design and delivery for a customer identity and access management platform in a highly regulated financial services environment.

DevSecOps Microservices REST API SAML
2 days, 15 hours ago

Senior Security Research Engineer

PlayStation 100K+ Household Durables

Sony Interactive Entertainment is hiring a Senior Security Research Engineer to lead Global Vulnerability Management efforts that advance its Threat Exposure Management program and strengthen security risk reduction across the PlayStation ecosystem.

Bash CI/CD Domo Git JavaScript PowerShell Python Snowflake SQL
2 days, 15 hours ago

Senior Capabilities Developer

Dragos 251-1K Professional Services

Dragos is hiring a Senior Capabilities Developer to build and maintain the Synapse-based threat intelligence infrastructure that powers analysis and reporting for critical infrastructure cybersecurity.

2 days, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers