The Vulnerability Management Lead directs client's vulnerability management program across the ... Deliver threat modeling analysis for critical applications and ensure WASP findings feed ...
The Vulnerability Management Lead directs client's vulnerability management program across the ... Deliver threat modeling analysis for critical applications and ensure WASP findings feed ...
Sr Vulnerability Management Engineer
OR · Remote
$104K - $143K/yr
Analyze findings, validate exploitability, and provide clear, actionable remediation guidance to ... Bachelor's Degree or higher and 7+ years of vulnerability management experience Experience ...
Sr Vulnerability Management Engineer
OR · Remote
$104K - $143K/yr
Analyze findings, validate exploitability, and provide clear, actionable remediation guidance to ... Bachelor's Degree or higher and 7+ years of vulnerability management experience Experience ...
$114K - $156K/yr
As a Senior Staff Engineer, Vulnerability Management, you'll play a meaningful role in ... Working with cutting-edge GenAI tools and technology to analyze findings, improve prioritization ...
Oversee activities supporting the Cybersecurity Web/Application Vulnerability Management branch responsible for identifying, analyzing, and mitigating vulnerabilities across DLA IT, Cloud, and OT ...
Oversee activities supporting the Cybersecurity Web/Application Vulnerability Management branch responsible for identifying, analyzing, and mitigating vulnerabilities across DLA IT, Cloud, and OT ...
Support threat hunting, detection engineering, incident response, vulnerability management, fraud ... Analyze threat actor behavior and map activity to frameworks such as MITRE ATT&CK to support ...
Support threat hunting, detection engineering, incident response, vulnerability management, fraud ... Analyze threat actor behavior and map activity to frameworks such as MITRE ATT&CK to support ...
Technology Consultant II
OR · On-site
$54.75 - $74.75/hr
Deploy and manage vulnerability scanning platforms in customer environments * Configure and tune scanning platforms alongside customers, including patching strategy development * Analyze scan results ...
Technology Consultant II
OR · On-site
$54.75 - $74.75/hr
Deploy and manage vulnerability scanning platforms in customer environments * Configure and tune scanning platforms alongside customers, including patching strategy development * Analyze scan results ...
Lead Security & Compliance Analyst
OR · On-site +1
$80K - $135K/yr
Run the vulnerability management program: scanning, triage, prioritization, and driving remediation ... Support security incident response: log analysis, forensic evidence collection, and containment
Lead Security & Compliance Analyst
OR · On-site +1
$80K - $135K/yr
Run the vulnerability management program: scanning, triage, prioritization, and driving remediation ... Support security incident response: log analysis, forensic evidence collection, and containment
... Vulnerability Management Branch supporting DLA's J6 Information Operations (IO) Directorate. * The CE supports the assessment, analysis, and remediation of CS vulnerabilities across DLA enterprise IT ...
... Vulnerability Management Branch supporting DLA's J6 Information Operations (IO) Directorate. * The CE supports the assessment, analysis, and remediation of CS vulnerabilities across DLA enterprise IT ...
Senior Security Analyst
OR · Remote
$95K - $125K/yr
Vulnerability and Risk Management Conduct regular vulnerability scans and coordinate remediation ... Mentor junior analysts and contribute to the development of the security team. Familiarity with:
Senior Security Analyst
OR · Remote
$95K - $125K/yr
Vulnerability and Risk Management Conduct regular vulnerability scans and coordinate remediation ... Mentor junior analysts and contribute to the development of the security team. Familiarity with:
... cause analysis efforts. Coordinate post-incident reviews and remediation planning. Maintain incident response playbooks and operational procedures. Vulnerability & Risk Management Direct ...
Quick apply
... cause analysis efforts. Coordinate post-incident reviews and remediation planning. Maintain incident response playbooks and operational procedures. Vulnerability & Risk Management Direct ...
IT Security Engineer
$120K - $160K/yr
... analyst role * Experience with enterprise security technologies, incident response, vulnerability management, and security monitoring * Industry certifications such as Security+, CEH, CISSP, GSEC ...
IT Security Engineer
$120K - $160K/yr
... analyst role * Experience with enterprise security technologies, incident response, vulnerability management, and security monitoring * Industry certifications such as Security+, CEH, CISSP, GSEC ...
IT Security Engineer
Portland, OR · On-site
$120K - $160K/yr
... analyst role * Experience with enterprise security technologies, incident response, vulnerability management, and security monitoring * Industry certifications such as Security+, CEH, CISSP, GSEC ...
Quick apply
IT Security Engineer
Portland, OR · On-site
$120K - $160K/yr
... analyst role * Experience with enterprise security technologies, incident response, vulnerability management, and security monitoring * Industry certifications such as Security+, CEH, CISSP, GSEC ...
IT Security Engineer
Portland, OR · On-site
$120K - $160K/yr
... analyst role * Experience with enterprise security technologies, incident response, vulnerability management, and security monitoring * Industry certifications such as Security+, CEH, CISSP, GSEC ...
IT Security Engineer
Portland, OR · On-site
$120K - $160K/yr
... analyst role * Experience with enterprise security technologies, incident response, vulnerability management, and security monitoring * Industry certifications such as Security+, CEH, CISSP, GSEC ...
Mentor Junior Analysts * Provide guidance and training to junior members of the VCM team. * Process Improvements * Identify potential gaps in the vulnerability or compliance management programs and ...
Mentor Junior Analysts * Provide guidance and training to junior members of the VCM team. * Process Improvements * Identify potential gaps in the vulnerability or compliance management programs and ...
Mentor Junior Analysts * Provide guidance and training to junior members of the VCM team. * Process Improvements * Identify potential gaps in the vulnerability or compliance management programs and ...
Mentor Junior Analysts * Provide guidance and training to junior members of the VCM team. * Process Improvements * Identify potential gaps in the vulnerability or compliance management programs and ...
OR · On-site
$142K/yr
... production vulnerability management, and AI-assisted developer workflows. As the Principal ... analysis, risk-based prioritization, and long-term architectural improvements. * Elevate ...
Manager, Security Engineering & Operations
OR · On-site +1
... analysts and engineers, providing technical guidance, career development, and performance coaching. * Program Oversight: Oversee the vulnerability management lifecycle, ensuring that scanning ...
Manager, Security Engineering & Operations
OR · On-site +1
... analysts and engineers, providing technical guidance, career development, and performance coaching. * Program Oversight: Oversee the vulnerability management lifecycle, ensuring that scanning ...
Cyber Security Engineer
Portland, OR · On-site
Drive root cause analysis, blast radius determination, and implementation of corrective and ... Oversee vulnerability management efforts by correlating scan results with asset criticality ...
Cyber Security Engineer
Portland, OR · On-site
Drive root cause analysis, blast radius determination, and implementation of corrective and ... Oversee vulnerability management efforts by correlating scan results with asset criticality ...
Product Cybersecurity Architect
OR · On-site +1
Coordinate vulnerability management activities, including intake, triage, risk assessment ... root cause analyses, and remediation efforts. * Partner with engineering teams to implement ...
Product Cybersecurity Architect
OR · On-site +1
Coordinate vulnerability management activities, including intake, triage, risk assessment ... root cause analyses, and remediation efforts. * Partner with engineering teams to implement ...
Support risk management process and vulnerability management process. REQUIREMENTS/SKILLS ... Must be able to analyze data, draw conclusions, interpret results, and make recommendations with ...
Support risk management process and vulnerability management process. REQUIREMENTS/SKILLS ... Must be able to analyze data, draw conclusions, interpret results, and make recommendations with ...
Vulnerability Management Analyst information
What is a vulnerability management analyst?
A Vulnerability Management Analyst is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT infrastructure. They use scanning tools, analyze threat data, and collaborate with teams to prioritize and remediate risks. Their role is crucial in maintaining cybersecurity by ensuring systems are patched and configured securely. Additionally, they may develop reports and provide recommendations to improve security posture. This position requires knowledge of security frameworks, risk assessment, and vulnerability management tools.
What are the typical daily responsibilities of a vulnerability management analyst?
On a typical day, a Vulnerability Management Analyst reviews system scans, analyzes reports for potential vulnerabilities, and works with IT or security teams to prioritize remediation efforts. They may also track the status of vulnerabilities, ensure timely patch application, and help develop or update security policies. Collaboration with various departments is common to coordinate testing, remediation, and communicate risk summary findings. This role requires keeping up with emerging threats and sometimes participating in security audits or compliance reviews, making it both dynamic and integral to the organization's overall cybersecurity posture.
What are the key skills and qualifications needed to thrive as a vulnerability management analyst?
A Vulnerability Management Analyst requires a strong background in cybersecurity principles, risk assessment, and IT networking, often supported by a relevant degree or certifications like CompTIA Security+, CISSP, or CEH. Experience with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7) and familiarity with ticketing systems or SIEM platforms is essential. Strong analytical skills, attention to detail, effective communication, and the ability to work collaboratively help individuals succeed in this role. These capabilities are vital to proactively identify, assess, and mitigate security vulnerabilities, ensuring the organization's digital assets remain secure and compliant.

Full-time
Medical, Dental, Vision, Life
Re-posted 10 days ago
Job description
Valiant Solutions is seeking a Vulnerability Management Lead to join our rapidly growing and innovative cybersecurity team!
The Vulnerability Management Lead directs client's vulnerability management program across the Continuous Diagnostics and Mitigation (CDM), Web Application Surveillance Program (WASP), and Cyber Hygiene workstreams within the Cybersecurity Services Division. The lead owns the end-to-end process from discovery and scanning through remediation tracking and Plan of Action and Milestones (POA&M) closure, working across Information System Owners (ISOs), Information System Security Officers (ISSOs), the Policy, Risk & Compliance branch, and engineering teams. The role produces the dashboards, metrics, and reporting that give client leadership a current view of agency risk and progress against remediation targets.
Named one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!
Location: The Vulnerability Management Lead can expect 100% telework. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.Â
Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, along with the ability to successfully pass a federal background investigation.
Required Experience:
- Six or more years of cybersecurity experience, including hands-on work with operating systems (Windows, Linux) and networking (TCP/IP, routing, firewalls, segmentation).
- At least one of the following certifications: GCIH, CISSP, CISM, or CRISC.
- Hands-on experience with Tenable (Tenable ONE, Nessus, or Tenable.io), AquaSec, and CDM integration in a federal or large enterprise environment.
- Working knowledge of DHS CDM Program requirements, NIST SP 800-137 (Information Security Continuous Monitoring), NIST SP 800-53 controls (in particular RA-5 and SA-11), DHS BOD 18-01, and CISA Cyber Hygiene Services.
- Experience supporting POA&M development, remediation tracking, and closure within Cyber Security Assessment and Management (CSAM) or a comparable governance, risk, and compliance system.
- Demonstrated ability to build dashboards and metrics that translate scan output into prioritized, executable remediation work for technical and executive audiences.
- Strong written and verbal communication skills, with the ability to coordinate across ISOs, ISSOs, compliance, and engineering stakeholders.
- Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance, Tier 4/6c.
Preferred Qualifications:
- Experience with AWS GovCloud and cloud-native vulnerability scanning, including container image and Infrastructure-as-Code (IaC) assessment.
- Familiarity with CI/CD pipeline security controls and policy-as-code enforcement.
- Experience integrating vulnerability data with SIEM and ticketing platforms such as ServiceNow.
- Familiarity with the client Technology Standards and Products Guide and client Lifecycle Management Methodology (LMM).
Â
Responsibilities:
- Oversee enterprise vulnerability scanning across infrastructure, web applications, containers, and cloud workloads using Tenable ONE, AquaSec, and integrated CDM tooling.
- Direct remediation tracking from finding to closure, including communication and coordination with POA&M support within the Policy, Risk & Compliance branch.
- Coordinate with ISOs, ISSOs, compliance teams, and engineering teams to triage findings, assign ownership, and close gaps within agency and federal timelines.
- Lead Cyber Hygiene activities, including weekly scans of internet-facing interfaces and URLs, review of CISA Cyber Hygiene reports, and distribution of issue reports to ISSOs within two business days of receipt.
- Maintain the authoritative inventory of externally facing IPs and URLs, updated in real time and reconciled monthly.
- Monitor digital certificate expiration, generate alerts 30 days prior to expiration, and escalate unresolved items within 10 days.
- Lead WASP activities, including static and dynamic scans of client web applications in development and production environments, vendor plugin updates, and integration of CISA Known Exploited Vulnerabilities (KEVs) into scan coverage.
- Deliver threat modeling analysis for critical applications and ensure WASP findings feed remediation and Cyber Hygiene dashboards.
- Operate and maintain the CDM integration layer and ensure CDM data flows into SIEM for centralized visibility, supporting the Vulnerability (VUL) capability area and AWARE-based prioritization.
- Develop and maintain dashboards and metrics for vulnerability management, including remediation cycle time, scan coverage, KEV exposure, certificate health, and POA&M aging.
- Coordinate with OCIO, Cyber Risk, client Vulnerability Management, and the DHS CDM PMO on program reporting and integration changes.
- Update Vulnerability Management standard operating procedures, playbooks, and runbooks at least quarterly, or sooner when a gap or improvement is identified, with major changes reviewed by the Change Control Board.
About Valiant Solutions
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, Washington Technology's Fast 50, and Washington Business Journal's Best Places to Work in the D.C. area, Valiant Solutions prides itself on providing its employees with great benefits and career development opportunities. As a company, we are just as committed to growing careers as we are to building world-class IT solutions, all while enjoying an unparalleled work-life balance. We are in a phase of tremendous growth and building the team that will take us to the next level. We seek people whose talents and accomplishments will contribute to a thriving company, who have the character to support their capacity, and can make a positive impact on our culture. Alongside our talented team, you'll learn to think quickly on your feet and expand your own personal and professional skill set. Our management team will inspire you to consider new perspectives and challenge you to become a better practitioner in the fast-paced industry of IT security. We hire people we respect - and we trust them to deliver results leveraging their expertise. If you would enjoy working in a dynamic environment as part of a stellar team of professionals, then we invite you to apply online today.
Benefits Snapshot (includes, but not limited to)Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time EmployeesValiant contributes 25% towards Health Coverage for Family and Dependents100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees100% Paid Certifications401K Matching up to 4%Paid Time OffPaid Federal HolidaysWellness & Fitness ProgramValiant University - Online Education and Training PortalFSA programs for: Medical Costs, Dependent Care, Transit, and ParkingReferral Bonuses
Remote Work PolicyÂ
Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.
Equal Employment Opportunity
Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.
Physical Demands
Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.
Authorization to Share Resume and Personal Information
By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.
#LI-JM1
Employment Type: FULL_TIMEAbout Valiant Solutions
Sourced by ZipRecruiter
Company size
51 - 200 Employees
Headquarters location
Henderson, NC, US
Year founded
2005