... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
Vulnerability Management Analyst
Camp Springs, MD · On-site
$87K - $157K/yr
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
Vulnerability Management Analyst
Camp Springs, MD · On-site
$87K - $157K/yr
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
The Northern Trust Company is seeking a Global Director of Vulnerability Management & Security Configuration to define and execute enterprise risk reduction across infrastructure, cloud, and AI ...
New
The Northern Trust Company is seeking a Global Director of Vulnerability Management & Security Configuration to define and execute enterprise risk reduction across infrastructure, cloud, and AI ...
New
Vulnerability Management Analyst
Camp Springs, MD · On-site
$87K - $157K/yr
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
Vulnerability Management Analyst
Camp Springs, MD · On-site
$87K - $157K/yr
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
Exposure & Vulnerability Management Lead
Euclid, OH · Hybrid
$100K - $132K/yr
Security Engineer, Exposure & Vulnerability Management Lead, Cybersecurity Operations Type ... Ability to drive execution and accountability across multiple teams without direct authority.
Exposure & Vulnerability Management Lead
Euclid, OH · Hybrid
$100K - $132K/yr
Security Engineer, Exposure & Vulnerability Management Lead, Cybersecurity Operations Type ... Ability to drive execution and accountability across multiple teams without direct authority.
Director, Security Engineering, Architecture & Vulnerability Management
Atlanta, GA · On-site
$178 - $296.70/hr
Role Summary Director, Security Architecture, Vulnerability Management and Response reports to the Chief Information Security Officer. This leadership role sets and drives strategy for Security ...
Director, Security Engineering, Architecture & Vulnerability Management
Atlanta, GA · On-site
$178 - $296.70/hr
Role Summary Director, Security Architecture, Vulnerability Management and Response reports to the Chief Information Security Officer. This leadership role sets and drives strategy for Security ...
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
... directed by senior analysts. Coordinate with Queue Managers, ISSOs, and Engineering teams to ... Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
Vulnerability Manager
Pittsburgh, PA · On-site
The position will initially lead one direct report and is expected to build and develop the vulnerability management function as organizational needs evolve. Responsibilities * Manages enterprise ...
Quick apply
Vulnerability Manager
Pittsburgh, PA · On-site
The position will initially lead one direct report and is expected to build and develop the vulnerability management function as organizational needs evolve. Responsibilities * Manages enterprise ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... of the Vulnerability Management Team Supervisor. ResponsibilitiesEssential Duties and ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... of the Vulnerability Management Team Supervisor. ResponsibilitiesEssential Duties and ...
Vulnerability Management & Offensive Security Analyst
Chicago, IL · Remote
$118K - $130K/yr
Direct Hire Overview TalentFish is casting a line for a Vulnerability Management & Offensive Security Analyst. This is a [Direct Hire/Contract] role in Chicago, IL. (The reason this position exists ...
Quick apply
Vulnerability Management & Offensive Security Analyst
Chicago, IL · Remote
$118K - $130K/yr
Direct Hire Overview TalentFish is casting a line for a Vulnerability Management & Offensive Security Analyst. This is a [Direct Hire/Contract] role in Chicago, IL. (The reason this position exists ...
Director/Sr Director, Product Management, Risk-Based Vulnerability Mgmt (RBVM)
Foster City, CA · On-site
$266K - $278K/yr
Drive innovation across: * vulnerability prioritization (RBVM) * remediation workflows * asset-risk correlation * Deliver features that reduce MTTR and improve risk reduction outcomes Business ...
Director/Sr Director, Product Management, Risk-Based Vulnerability Mgmt (RBVM)
Foster City, CA · On-site
$266K - $278K/yr
Drive innovation across: * vulnerability prioritization (RBVM) * remediation workflows * asset-risk correlation * Deliver features that reduce MTTR and improve risk reduction outcomes Business ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... the Vulnerability Management Team Supervisor. Responsibilities Essential Duties and ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... the Vulnerability Management Team Supervisor. Responsibilities Essential Duties and ...
Drive innovation across: * vulnerability prioritization (RBVM) * remediation workflows * asset-risk correlation * Deliver features that reduce MTTR and improve risk reduction outcomes Business ...
Drive innovation across: * vulnerability prioritization (RBVM) * remediation workflows * asset-risk correlation * Deliver features that reduce MTTR and improve risk reduction outcomes Business ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... of the Vulnerability Management Team Supervisor. ResponsibilitiesEssential Duties and ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... of the Vulnerability Management Team Supervisor. ResponsibilitiesEssential Duties and ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... the direction of the Vulnerability Management Team Supervisor. Essential Duties and ...
... direct involvement in 3rd-party assessment engagements, including penetration tests. T3 technicians ... the direction of the Vulnerability Management Team Supervisor. Essential Duties and ...
Director/Sr Director, Product Management, Risk-Based Vulnerability Mgmt (RBVM)
Foster City, CA · On-site
$210 - $240/hr
Risk-Based Vulnerability Management (RBVM)** product powered by **Qualys VMDR** and drive the ... Direct impact on revenue, growth, and company strategy* Lead the next evolution of cybersecurity ...
Director/Sr Director, Product Management, Risk-Based Vulnerability Mgmt (RBVM)
Foster City, CA · On-site
$210 - $240/hr
Risk-Based Vulnerability Management (RBVM)** product powered by **Qualys VMDR** and drive the ... Direct impact on revenue, growth, and company strategy* Lead the next evolution of cybersecurity ...
Must demonstrate direct involvement in vulnerability management programs (not just remediation participation) * Strong understanding of: * Vulnerability identification, triage, risk rating, and ...
Must demonstrate direct involvement in vulnerability management programs (not just remediation participation) * Strong understanding of: * Vulnerability identification, triage, risk rating, and ...
Director Vulnerability Management information
What are some common challenges faced by a Director of Vulnerability Management, and how can they be addressed?
What does a Director of Vulnerability Management do?
What are the key skills and qualifications needed to thrive as a Director of Vulnerability Management, and why are they important?
What is the difference between Director Vulnerability Management vs Security Manager?
| Aspect | Director Vulnerability Management | Security Manager |
|---|---|---|
| Primary Focus | Overseeing vulnerability assessment and remediation strategies | Managing overall security policies and team operations |
| Certifications | Certifications like CISSP, CISA, GIAC | Certifications like CISSP, CISM, CompTIA Security+ |
| Work Environment | Security teams, vulnerability scanning tools, incident response | Security teams, policy development, risk management |
| Industry Usage | Common in large enterprises with dedicated vulnerability teams | Widespread across organizations managing overall security |
The main difference is that the Director Vulnerability Management focuses specifically on identifying and addressing security vulnerabilities, while the Security Manager oversees broader security policies and team management. Both roles require similar certifications and work in security-focused environments, but their scope and responsibilities differ.

Leidos rating
8.4
Based on 149 frontline employees who took The Breakroom Quiz
57th of 454 rated business services
Job description
Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program.
The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), Office of the Secretary of Defense (OSD), Joint Chiefs of Staff, and other Air Force activities within the AFNCR, missions to include the Pentagon, Joint Base Andrews (JBA), Joint Base Anacostia-Bolling (JBAB), and other locations, leased spaces, and alternate sites. The major support areas required are IT Operations and Maintenance; Plans, Projects, and Engineering (PP&E); and National Military Command Center (NMCC). The senior leaders and national defense missions that are supported require that the AFNCR operations never fail, resulting in a fast-paced, challenging, but also rewarding environment.
If this sounds like the kind of environment where you can thrive, keep reading!
Leidos Defense Group provides a diverse portfolio of systems, solutions, and services covering land, sea, air, space, and cyberspace for customers worldwide. Solutions for Defense include enterprise and mission IT, large-scale intelligence systems, command and control, geospatial and data analytics, cybersecurity, logistics, training, and intelligence analysis and operations support. Our team is solving the world's toughest security challenges for customers with "can't fail" missions. To explore and learn more, click here!
Are you ready to make an impact? Begin your journey of a flourishing and meaningful career, share your resume with us today!
POSITION SUMMARY:
Leidos is seeking a Vulnerability Management Analyst to join our Cybersecurity Operations team supporting the AFNCR IT Services (AFNCRIT) program. This T1-level position is ideal for an entry-level cybersecurity professional interested in learning vulnerability management processes. The role will assist with running vulnerability scans using ACAS, reviewing STIG findings, and supporting remediation coordination across Air Force enterprise systems under the guidance of senior team members.
PRIMARY RESPONSIBILITIES:
Assist with scheduling and running vulnerability scans using Tenable SecurityCenter/Nessus (ACAS) in classified and unclassified environments under senior staff guidance.
Review scan results to help identify potential CAT I/II/III findings, false positives, and basic configuration issues.
Support tracking of remediation actions, Plans of Action and Milestones (POA&Ms), and exceptions in accordance with RMF guidance.
Follow established procedures to validate DISA STIG checklists and work with team members to ensure secure system configurations.
Help prepare basic vulnerability reports, compliance summaries, and metrics to support leadership briefings and inspection readiness (e.g., CCRI/CORA).
Assist in maintaining asset groupings, scan zones, and credentialed scanning configurations as directed by senior analysts.
Coordinate with Queue Managers, ISSOs, and Engineering teams to support the remediation of high-priority vulnerabilities.
Maintain data accuracy within ACAS, including proper tagging and grouping for consistent reporting.
BASIC QUALIFICATIONS:
Active DoD Secret clearance required.
CompTIA Security+ CE or higher DoD 8570 IAT Level II certification must meet 8140 ISSM role qualification
Bachelor's Degree and 4-8 years of cybersecurity or system administration experience, with at least 1 year of direct ACAS or Tenable experience. Additional education and years of experience may be considered in lieu of a degree.
Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.
Familiarity with NIST SP 800-53, RMF compliance, and Air Force cybersecurity policy (AFMAN 17-130).
Strong attention to detail, documentation skills, and the ability to interpret technical vulnerability data.
PREFERRED QUALIFICATIONS:
Experience supporting USAF, DISA, or other DoD mission systems.
Familiarity with eMASS, SCAP Compliance Checker (SCC), or HBSS.
Prior involvement in CCRI/CORA preparation or vulnerability remediation campaigns.
Ability to communicate risk-based recommendations to both technical and non-technical stakeholders.
Understanding of automation tools/scripts (e.g., PowerShell, Nessus APIs) to support scan or report optimization.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Original Posting:July 13, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Sourced by ZipRecruiter
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Reston, VA, US