2

Remote Vulnerability Management Jobs in Silver Spring, MD

Cybersecurity & Governance Engineer

Washington, DC · On-site +1

$64.50 - $79.25/hr

This position will be on-site, hybrid, or remote, at the discretion of the customer. The role ... vulnerability and configuration management, audit logging, cloud security, security documentation ...

Hybrid Columbia MD 3 times a week OR Remote (as applicable to role) Work Authorization Requirements ... Vulnerability Management & Remediation * Identify, track, and support remediation of security ...

Senior Systems Administrator

Vienna, VA · Remote

$170K - $190K/yr

... vulnerability management to maintain system security and reliability. The position requires ... new installations, and remote support activities while ensuring high system availability ...

Cybersecurity Engineer - ISSO

Vienna, VA · On-site +1

$160K - $200K/yr

None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking a Cyber Security Engineer ... You will lead assessment, authorization, vulnerability management, and secure operations for ...

... vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes. • Evaluate, deploy, integrate, and operate ...

Automate secure configuration, patching, vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes. Evaluate ...

... vulnerability remediation, credential and certificate management, backup protection, recovery, remote administration, and system lifecycle processes. • Evaluate, deploy, integrate, and operate ...

Herndon, VA 20171 (Remote) Employment Type: FTE + Benefits Client is supporting the FedRAMP and ... vulnerability management capabilities. * Understand enterprise operating environments, including ...

Showing results 21-40

Remote Vulnerability Management information

See Silver Spring, MD salary details

$34.6K

$142.4K

$179.9K

How much do remote vulnerability management jobs pay per year?

As of Sep 6, 2026, the average yearly pay for remote vulnerability management in Silver Spring, MD is $142,398.00, according to ZipRecruiter salary data. Most workers in this role earn between $114,700.00 and $178,800.00 per year, depending on experience, location, and employer.

What is remote vulnerability management?

A Remote Vulnerability Management job involves identifying, assessing, and mitigating security vulnerabilities in an organization's systems, networks, and applications from a remote location. Professionals in this role use various tools to scan for weaknesses, analyze risks, and collaborate with IT and security teams to implement remediation measures. They also monitor threat intelligence, ensure compliance with security policies, and generate reports on findings. Strong knowledge of cybersecurity frameworks, vulnerability assessment tools, and risk management is crucial for success in this role.

What are some typical challenges faced in remote vulnerability management?

Professionals in Remote Vulnerability Management often encounter challenges such as coordinating remediation efforts across global teams, prioritizing vulnerabilities in large, complex environments, and keeping up with rapidly evolving cyber threats. Working remotely also requires proactive communication to ensure all stakeholders stay informed and aligned on security initiatives. You will need to adapt to different IT infrastructures and collaborate effectively with both technical and non-technical colleagues. Successfully navigating these challenges builds your problem-solving skills and deepens your expertise in protecting organizational assets.

What are the key skills and qualifications needed to thrive in remote vulnerability management?

To thrive in Remote Vulnerability Management, you need a solid understanding of cybersecurity principles, vulnerability assessment, and risk mitigation, often supported by a degree in information security or related certifications such as CompTIA Security+ or CISSP. Familiarity with vulnerability scanning tools like Nessus, Qualys, or Rapid7, as well as experience with SIEM platforms and ticketing systems, is essential. Strong analytical skills, problem-solving abilities, and effective written communication are critical for collaborating with distributed teams and reporting findings. These skills ensure accurate identification, remediation of security risks, and smooth teamwork in a remote, fast-paced digital environment.

What are the most commonly searched types of Vulnerability Management jobs in Silver Spring, MD?

The most popular types of Vulnerability Management jobs in Silver Spring, MD are:

What are popular job titles related to Remote Vulnerability Management jobs in Silver Spring, MD?

For Remote Vulnerability Management jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Remote Vulnerability Management jobs in Silver Spring, MD look for?

The top searched job categories for Remote Vulnerability Management jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Remote Vulnerability Management jobs?

Cities near Silver Spring, MD with the most Remote Vulnerability Management job openings:

Infographic showing various Remote Vulnerability Management job openings in Silver Spring, MD as of August 2026, with employment types broken down into 91% Full Time, 5% Part Time, and 4% Contract. Highlights an 100% Remote job distribution, with an average salary of $142,398 per year, or $68.5 per hour.

Senior Manager - Security Engineering

Ferguson Enterprises, LLC

Springfield, VA • On-site, Remote

$119K - $164K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 10 days ago


Ferguson Waterworks rating

9.3

Company rating: 9.3 out of 10

Based on 14 frontline employees who took The Breakroom Quiz

14th of 429 rated retail wholesalers


Job description

Job Posting:
Since 1953, Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure, better homes and better businesses. We exist to make our customers' complex projects simple, successful, and sustainable. We proactively solve problems, adapt and grow to continuously serve our customers, communities and each other. Ferguson, a Fortune 500 company, is proud to provide best-in-class products, service and capabilities across the following industries: Commercial/Mechanical, Facilities Supply, Fire and Fabrication, HVAC, Industrial, Residential Trade, Residential Building and Remodel, Waterworks and Residential Digital Commerce. Ferguson has approximately 36,000 associates across 1,700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of, at a company you can believe in.
Senior Manager - Security Engineering
Department: Ferguson, Information Security
Reports To: Director, Information Security
The Senior Manager, Security Engineering provides vision, leadership, and operational accountability for Ferguson's enterprise security engineering capabilities. This role leads the teams and services responsible for identifying, reducing, and reporting technology risk across applications, infrastructure, cloud platforms, endpoints, identity-integrated services, email, edge protections, and emerging AI-enabled attack surfaces. The leader is accountable for ensuring Ferguson has the people, processes, tooling, and partnerships required to continuously assess risk, harden technology baselines, validate defenses, support secure delivery, and drive remediation in partnership with Technology, Security, business, and third-party participants. This position requires deep technical judgment, collaborative leadership, and operational rigor. It also requires the ability to translate complex security risks into actionable priorities. These priorities help Ferguson complete its business plans securely.
Location: This role is approved to be either Remote within the United States or Hybrid for associates in Newport News, VA, in accordance with company policy.
Duties and Responsibilities:
Leadership and Strategy (40%)
  • Build, lead, and develop a high-performing Security Engineering team through recruiting, hiring, coaching, mentorship, performance management, and career development.
  • Define and maintain the operating model, service ownership, roadmap, and measurable objectives related to Security Engineering capabilities across vulnerability management, DevSecOps, penetration testing, edge security, email security, endpoint security, cloud and configuration posture, and related engineering services.
  • Represent Security Engineering performance, risks, resource needs, and strategic opportunities with Information Security leadership and multi-functional Technology leadership forums.
  • Partner with Security Architecture, Security Operations, GRC, Identity, Infrastructure, Application Development, Cloud, and business technology teams to align engineering priorities to enterprise risk reduction and business enablement.
  • Continuously assess team skills, capacity, vendor support, and tooling maturity against current and emerging threats, including AI-enabled attack techniques and post-quantum readiness considerations.
  • Drive a culture of secure-by-default engineering, shared accountability, transparency, and practical risk-based decision making across Ferguson technology teams.
  • Establish clear metrics, performance indicators, reporting routines, and executive-ready narratives that communicate risk posture, control effectiveness, remediation progress, service value, and investment needs.

Security Engineering Management (60%)
  • Own and mature Security Engineering service areas including vulnerability management, DevSecOps, penetration testing and adversarial validation, edge security, email security, endpoint detection and response, cloud security posture, configuration risk, application security testing, and security tooling integrations.
  • Lead Ferguson's risk-based vulnerability management capability, ensuring asset visibility, authenticated scanning, application and infrastructure assessment, risk contextualization, remediation tracking, exception management, and leadership reporting are operating effectively.
  • Advance secure software delivery by integrating security testing and guidance into development workflows, including static analysis, software composition analysis, container security, secrets protection, code signing, secure repository practices, and developer-facing remediation support.
  • Run penetration testing, AI-enabled security testing, purple team support, and continuous adversarial validation activities for critical applications, APIs, external assets, cloud services, identity entry points, and business-critical technology platforms.
  • Ensure public-facing applications and digital channels are protected through effective use of edge security capabilities, including WAF, bot management, CDN security, origin protection, API protections, and secure traffic patterns.
  • Provide engineering ownership and oversight for email and endpoint security capabilities, including migration planning, policy tuning, telemetry quality, detection support, deployment health, and operational readiness.
  • Drive enterprise configuration and posture management across cloud, infrastructure, endpoints, applications, and identity-adjacent services to identify deviations from hardened baselines and support timely remediation.
  • Partner with Identity, PAM, SSO, certificate, and non-human identity teams where security engineering capabilities depend on identity controls, privileged access, machine identity, key management, or cryptographic services.
  • Support pivotal initiatives such as AI resilience, post-quantum readiness, enterprise cryptographic visibility, secrets removal, cloud posture modernization, and security tooling rationalization.
  • Ensure Security Engineering platforms and service offerings are reliable, monitored, documented, supportable, and aligned with published policies, standards, organizational change expectations, and regulatory or audit obligations.
  • Establish and maintain runbooks, customer concern paths, operational handoffs, service ownership documentation, vendor engagement models, and cross-training practices to prevent coverage gaps.
  • Prioritize engineering work based on business risk, exploitability, asset criticality, exposure, compliance requirements, operational impact, and available remediation capacity.
  • Partner with Technology teams to close visibility and deployment gaps in required security tooling so Ferguson can assess and protect operational assets consistently.
  • Contribute technical requirements to security technology selection, proof-of-value efforts, vendor evaluations, architecture reviews, and implementation planning.
  • Actively monitor new and emerging technologies, threats, attack patterns, regulatory expectations, and industry practices to assess their applicability to Ferguson's security engineering program.
  • Perform other duties or functions as requested by management.
  • Drive and report on Service restoration activities as required.
  • Support enterprise business and sales objectives through the effective and efficient performance of job responsibilities

Qualifications and Requirements:
  • Experience leading information security engineering, application security, vulnerability management, cloud security, endpoint security, or related technical security teams is required.
  • Experience managing full-time associates, contractors, vendors, and multi-functional delivery partners is required.
  • Experience building or operating risk-based vulnerability management, application security testing, DevSecOps, penetration testing, security tooling, or cloud posture management programs is strongly preferred.
  • Experience partnering with infrastructure, application development, cloud, identity, security operations, GRC, and business technology teams to reduce enterprise technology risk is strongly preferred.
  • Eight (8) or more years of information security, technology risk, security engineering, or related experience is strongly preferred, including demonstrated leadership accountability.
  • Strong leadership, communication, organizational, and internal business customer leadership skills.
  • Ability to translate technical security findings, control gaps, and threat scenarios into business risk, prioritized action, and executive-level communication.
  • Broad knowledge of vulnerability management, exposure management, application security, DevSecOps, penetration testing, web application security, API security, cloud security, endpoint protection, email security, and configuration management practices.
  • Solid understanding of modern security tooling such as vulnerability scanners, risk reporting platforms, SAST, SCA, container security, WAF, bot management, EDR, CSPM, SIEM integrations, secrets management, certificate management, and identity-related security platforms.
  • Ability to lead multi-functional remediation efforts where ownership, technical complexity, business impact, and risk acceptance decisions must be coordinated across teams.
  • Knowledge of security frameworks, standards, and practices such as NIST CSF, ISO 27001/27002, OWASP, MITRE ATT&CK, CIS Benchmarks, secure SDLC, and IT service management.
  • Ability to develop metrics and reporting that demonstrate security posture, remediation progress, control effectiveness, service health, and business value.
  • Ability to operate effectively in a distributed, matrixed environment with contending priorities and high demand for security engineering services.
  • Ability to partner with architecture, delivery, operations, infrastructure, cloud, identity, and business teams to embed security into technology planning and delivery.
  • Strong vendor management, proof-of-value, requirements development, and technology evaluation skills.
  • Fluent with Microsoft Office and collaboration tools; experience with Microsoft security, cloud, and identity ecosystems strongly preferred.
  • Certifications such as CISSP, CISM, CCSP, GIAC, Azure Security, AWS Security, or similar security and cloud certifications are preferred but not required.
  • Solid ability to prioritize work, establish timelines, handle tradeoffs, and deliver outcomes by deadline.

At Ferguson, we care for each other. We value our well-being just as much as our hard work. We are committed to a holistic approach towards benefits plans and programs that support the mental, physical and financial well-being of our associates. Our competitive offering not only includes benefits like health, dental, vision, paid time off, life insurance and a 401(k) with a company match, but our associates also enjoy additional meaningful and inclusive enhancements that are adaptable to their diverse situations and needs, including mental health coverage, gender affirming and family building benefits, paid parental leave, associate discounts, community involvement opportunities and more!
#LI-REMOTE
Pay Range:
Actual pay rate may vary depending upon location. The estimated pay range for this position is below. The specific rate will depend on a candidate's qualifications and prior experience.
$9,458.97 - $16,551.03
Estimated Ranges displayed are Monthly for Salaried roles OR Hourly for all other roles.
This role is Bonus or Incentive Plan eligible.
Ferguson complies with all wage regulations. The starting wage may be higher in certain locations based on local or state wage requirements.
The Company is an equal opportunity employer as well as a government contractor that shall abide by the requirements of 41 CFR 60-300.5(a), which prohibits discrimination against qualified protected Veterans and the requirements of 41 CFR 60-741.5(A), which prohibits discrimination against qualified individuals on the basis of disability.
Ferguson Enterprises, LLC. is an equal employment employer F/M/Disability/Vet/Sexual Orientation/Gender Identity.
Equal Employment Opportunity and Reasonable Accommodation Information

What Ferguson Waterworks employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom