2

Remote Vulnerability Management Jobs in Silver Spring, MD

Sr GRC Analyst

Herndon, VA · Remote

$98K - $129K/yr

26-May-2026 Senior GRC Engineering Analyst US (Remote) 10880BR Company Summary Built on 40 years of ... vulnerability management, container security, infrastructure-as-code, and CI/CD pipelines.

... vulnerability management, compliance tracking, or IT security support functions - Basic ... remote Minimum Requirements TCS039, T3, Band 6 EEO Statement Maximus is an equal opportunity ...

Security Engineer

Washington, DC · On-site +1

$40 - $48/hr

The role focuses on endpoint vulnerability management, risk assessment and mitigation, and clear communication with technical and non-technical stakeholders. You will collaborate with cross ...

Security Engineer

Washington, DC · On-site +1

$40 - $48/hr

The role focuses on endpoint vulnerability management, risk assessment and mitigation, and clear communication with technical and non-technical stakeholders. You will collaborate with cross ...

Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... vulnerability management capabilities. * Understand enterprise operating environments, including ...

FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... vulnerability management capabilities. * Understand enterprise operating environments, including ...

FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... vulnerability management capabilities. * Understand enterprise operating environments, including ...

FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... vulnerability management capabilities. * Understand enterprise operating environments, including ...

FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... vulnerability management capabilities. * Understand enterprise operating environments, including ...

... vulnerability management and compliance activities, including remediation coordination and ... Remote • Minimum Requirements TCS056, T2, Band 5 EEO Statement Maximus is an equal opportunity ...

This position is based in Washington, DC and may require a combination of on-site and remote ... Support vulnerability management activities throughout the software development lifecycle ...

... vulnerability management and compliance activities, including remediation coordination and ... Remote Minimum Requirements TCS056, T2, Band 5 EEO Statement Maximus is an equal opportunity ...

next page

Showing results 1-20

Remote Vulnerability Management information

See Silver Spring, MD salary details

$34.6K

$142.4K

$179.9K

How much do remote vulnerability management jobs pay per year?

As of Jun 11, 2026, the average yearly pay for remote vulnerability management in Silver Spring, MD is $142,398.00, according to ZipRecruiter salary data. Most workers in this role earn between $114,700.00 and $178,800.00 per year, depending on experience, location, and employer.

What are some typical challenges faced in a Remote Vulnerability Management role?

Professionals in Remote Vulnerability Management often encounter challenges such as coordinating remediation efforts across global teams, prioritizing vulnerabilities in large, complex environments, and keeping up with rapidly evolving cyber threats. Working remotely also requires proactive communication to ensure all stakeholders stay informed and aligned on security initiatives. You will need to adapt to different IT infrastructures and collaborate effectively with both technical and non-technical colleagues. Successfully navigating these challenges builds your problem-solving skills and deepens your expertise in protecting organizational assets.

What is a Remote Vulnerability Management job?

A Remote Vulnerability Management job involves identifying, assessing, and mitigating security vulnerabilities in an organization's systems, networks, and applications from a remote location. Professionals in this role use various tools to scan for weaknesses, analyze risks, and collaborate with IT and security teams to implement remediation measures. They also monitor threat intelligence, ensure compliance with security policies, and generate reports on findings. Strong knowledge of cybersecurity frameworks, vulnerability assessment tools, and risk management is crucial for success in this role.

What are the key skills and qualifications needed to thrive in the Remote Vulnerability Management position, and why are they important?

To thrive in Remote Vulnerability Management, you need a solid understanding of cybersecurity principles, vulnerability assessment, and risk mitigation, often supported by a degree in information security or related certifications such as CompTIA Security+ or CISSP. Familiarity with vulnerability scanning tools like Nessus, Qualys, or Rapid7, as well as experience with SIEM platforms and ticketing systems, is essential. Strong analytical skills, problem-solving abilities, and effective written communication are critical for collaborating with distributed teams and reporting findings. These skills ensure accurate identification, remediation of security risks, and smooth teamwork in a remote, fast-paced digital environment.

What are the most commonly searched types of Vulnerability Management jobs in Silver Spring, MD? The most popular types of Vulnerability Management jobs in Silver Spring, MD are:
What are popular job titles related to Remote Vulnerability Management jobs in Silver Spring, MD? For Remote Vulnerability Management jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Remote Vulnerability Management jobs in Silver Spring, MD look for? The top searched job categories for Remote Vulnerability Management jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Remote Vulnerability Management jobs? Cities near Silver Spring, MD with the most Remote Vulnerability Management job openings:
Infographic showing various Remote Vulnerability Management job openings in Silver Spring, MD as of June 2026, with employment types broken down into 83% Full Time, 6% Part Time, and 11% Contract. Highlights an 100% Remote job distribution, with an average salary of $142,398 per year, or $68.5 per hour.
Sr GRC Analyst

Sr GRC Analyst

Deltek, Inc.

Herndon, VA • Remote

$98K - $129K/yr

Other

Medical, Life, Retirement, PTO

Posted 26 days ago


Job description

26-May-2026

Senior GRC Engineering Analyst

US (Remote)

10880BR

Company Summary

Built on 40 years of industry expertise Deltek is a leading provider of ERP solutions for Government contractors of all sizes. And whether these firms call them a contract within the government contracting space, an engagement within professional services firms or refer to them as a project within the AEC space, these organizations share the same ultimate goal-to win and deliver successful projects. Deltek offerscomplete and integrated software solutions that connect and automate every stage of the project lifecycle, enhancing project intelligence, management and collaboration. With Deltek's industry-focused expertise and end-to-end visibility into project and financial performance, we empower businesses to make data-driven decisions, mitigate risks and deliver projects on time and within budget.

Position Responsibilities

As a Senior GRC Engineering Analyst, you will ensure Deltek's cloud environments and information systems meet security and compliance obligations by testing technical controls, supporting audits, and maturing core GRC services. To support Deltek's flagship GovCon products, you will partner with Cloud Operations, Product Security, Platform Delivery, and Security Operations to translate requirements into test procedures, produce audit-ready artifacts, and drive remediation.

  • Lead audits and assessments with a key focus on engineering, technical control design, and control implementation aligned to frameworks/programs such as NIST 800-53 Rev. 5, FedRAMP, CMMC, ISO 27001, PCI DSS, SOC 1, and SOC 2.
  • Test, validate, and document cloud control implementations across AWS, Azure, and OCI, including IAM, network segmentation, encryption/key management, logging/monitoring, vulnerability management, container security, infrastructure-as-code, and CI/CD pipelines.
  • Partner with Security Engineering, Cloud Engineering, DevOps, IT, and Product teams to translate compliance requirements into scalable, automated, and auditable technical controls.
  • Own assessment execution end-to-end, including scope definition, technical walkthroughs, control testing, evidence validation, issue tracking, remediation follow-up, and reporting.
  • Design, maintain, and improve audit-ready artifacts, including control narratives, test procedures, evidence mappings, technical diagrams, implementation documentation, and control validation results.
  • Facilitate technical walkthroughs with stakeholders and auditors; clearly explain control intent, system architecture, implementation details, evidence sources, and test results.
  • Identify control gaps, assess technical risk and business impact, and drive remediation to closure with accountable engineering and control owners.
  • Support continuous compliance through control automation, recurring evidence collection, control health monitoring, and integration with tools such as cloud security platforms, ticketing systems, SIEM, vulnerability management tools, and GRC platforms.
  • Own or support key GRC services, including policy lifecycle, risk management, FedRAMP continuous monitoring, POA&M management, customer due diligence, security questionnaires, and audit readiness, with a focus on process improvement and automation.
  • Build compliance metrics and reporting, including dashboards, scorecards, executive summaries, control health indicators, remediation trends, and audit readiness reporting.
  • Develop or support automation scripts, queries, workflows, or integrations to streamline evidence collection, control testing, compliance monitoring, and reporting.
  • Evaluate cloud services, system changes, and new technical implementations for compliance impact and advise teams on control requirements early in the design and deployment lifecycle.
  • Maintain strong working knowledge of cloud security architecture, identity and access management, secure SDLC, infrastructure-as-code, logging/monitoring, vulnerability management, encryption, and change management practices.
Success in the first 90 days looks like: You effectively support Cloud Operations, Product Security, Platform Delivery, and Security Operations by partnering with them to implement, validate, and improve the technical controls they own. You ensure control evidence, testing results, technical documentation, and supporting artifacts are complete, accurate, and audit-ready.

Qualifications

Required Qualifications:

  • 3+ years of experience in GRC engineering, cloud security or compliance, IT audit/ITGC, Security Operations (SecOps), internal audit, IT risk management, or related fields, with hands-on experience implementing, validating, security tooling and assessing technical controls.
  • Bachelor's degree in information security, Computer Science, Informatics with Security, MIS, Engineering, or equivalent practical experience.
  • Experience assessing and validating controls in one or more major cloud platforms, including AWS, Azure, or OCI. Practical OCI experience is preferred.
  • Working knowledge of cloud security control areas such as IAM, logging and monitoring, encryption/key management, vulnerability management, network security, change management, secure SDLC, CI/CD, and infrastructure-as-code.
  • Experience partnering with engineering, security, cloud operations, or platform teams to collect evidence, validate control implementation, identify gaps, and support remediation.
  • Ability to review technical documentation, system configurations, screenshots, logs, tickets, diagrams, and other evidence to determine whether controls are operating effectively.
  • Familiarity with one or more security and compliance frameworks, such as NIST 800-53, FedRAMP, CMMC, ISO 27001, PCI DSS, SOC 1, or SOC 2.
  • Possess a security, audit, or cloud certification, such as CISA, CISSP, CCSK/CCAK, AWS, Azure, GCP, or OCI certification, or obtain one within 12 months. Candidates with relevant certification(s) already held are preferred.
US Citizenship is required for this position.

Core Competencies:
  • Excellent ability to:
    • Self-manage time and priorities while working with minimal direction and supervision.
    • Handle multiple competing priorities and projects.
    • Resolve business and technical roadblocks independently through structured problem-solving.
    • Think critically and apply strong analytical, written, verbal, and interpersonal communication skills.
  • Collaborate effectively in a team environment and take directions from senior-level staff.
  • Demonstrated initiative to learn through a combination of structured, on-the-job, and self-directed training.
Preferred Qualifications:
  • OCI experience.
  • ITAR and/or Government Cloud assessment experience.
  • Hands-on experience with FedRAMP and/or NIST 800-171, plus familiarity with CSA CCM and CIS Benchmarks.
  • Experience supporting or assessing secure software development in cloud environments (e.g., CI/CD, infrastructure as code, containers).

Career Interests

Legal

Compensation Info

The U.S. salary range for this position is $76,000.00-$134,000.00. This range is subject to change as Deltek takes a number of factors into consideration when determining individual base pay, such as location, job-related knowledge, skills and experience. Certain roles are eligible for additional rewards, including incentive compensation and equity.
Benefits and perks listed here may vary depending on the nature of employment with Deltek. Employees have access to healthcare benefits, a 401(k) plan and company match, paid vacation time and holidays, well-living programs, short-term and long-term disability coverage, basic life insurance and tuition reimbursement.

Position Type

FT

Travel Requirements

10%

Compliance Requirements

Certain roles may have additional privacy, security and compliance requirements to the extent they support Costpoint GCCM or similar product offerings.

EEO Statement

Deltek, Inc. is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.

E-Verify Statement

Deltek, Inc., utilizes the E-Verify program with every potential new hire. This makes it possible for us to make certain that every employee who works for Deltek is eligible to work in the United States. To learn more about E-Verify you can call 1-800-255-7688 or visit their website by clicking the logo below. E-Verify is a registered trademark of the United States Department of Homeland Security.

Applicant Privacy Notice

Deltek is committed to the protection and promotion of your privacy. In connection with your application for employment with us at Deltek, it is necessary for us to collect, store and use information about you ("Personal Data") to administer and evaluate your application. We are the "controller" of the Personal Data you provide us and will process any such Personal Data in accordance with applicable law and the statements contained in this Employment Candidate Privacy Notice. Additionally, we have not sold and do not sell Personal Data you provide to us through the job application process.

Job Expires

15-Apr-2027