1

Vulnerability Management Lead Jobs (NOW HIRING)

The Vulnerability Management Lead directs client's vulnerability management program across the Continuous Diagnostics and Mitigation (CDM), Web Application Surveillance Program (WASP), and Cyber ...

Vulnerability Management Lead

Austin, TX · On-site

$101K - $133K/yr

Job Overview We're looking for a hands-on Vulnerability Management Lead to own Saronic's VM program end-to-end. You will be the technical authority for vulnerability discovery, triage, prioritization ...

Vulnerability Management Lead

Alexandria, VA · Hybrid

$109K - $144K/yr

RiVidium is seeking a Vulnerability Management Lead to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data ...

Vulnerability Management Lead

Alexandria, VA · On-site

$109K - $144K/yr

Full-Time/Part-Time Full-Time Description RiVidium is seeking a Vulnerability Management Lead to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role ...

next page

Showing results 1-20

Vulnerability Management Lead information

See salary details

$42.5K

$123.8K

$180.5K

How much do vulnerability management lead jobs pay per year?

As of Jul 21, 2026, the average yearly pay for vulnerability management lead in the United States is $123,784.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,500.00 and $135,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Vulnerability Management Lead position, and why are they important?

To thrive as a Vulnerability Management Lead, you need deep knowledge in cybersecurity practices, vulnerability assessment methodologies, and a strong background in IT systems or network administration, typically backed by a relevant degree and industry certifications like CISSP, CISM, or CompTIA Security+. Familiarity with vulnerability scanning tools such as Nessus, Qualys, or Rapid7, and experience with security information and event management (SIEM) systems are highly valued. Strong leadership, analytical thinking, and effective communication skills help in leading teams, interpreting complex risks, and collaborating with cross-functional partners. These abilities are vital for identifying threats, driving remediation efforts, and maintaining the organization’s overall security posture.

What are the main challenges faced by Vulnerability Management Leads in their day-to-day responsibilities?

Vulnerability Management Leads often face the challenge of prioritizing numerous security risks across diverse systems while ensuring minimal disruption to business operations. They must stay current with the rapidly evolving threat landscape and often coordinate across multiple departments to implement remediation plans effectively. Another common hurdle is balancing technical requirements with organizational constraints, such as resource limitations and compliance demands. Successfully navigating these challenges requires strong problem-solving skills, as well as the ability to clearly communicate risk and urgency to both technical teams and executive leadership.

What is a Vulnerability Management Lead job?

A Vulnerability Management Lead is responsible for overseeing an organization's vulnerability management program. They identify, assess, and prioritize security vulnerabilities across systems, networks, and applications. This role involves coordinating with IT and security teams to remediate risks and ensure compliance with security policies and regulations. They also develop strategies, processes, and tools to enhance the organization's security posture. The role requires strong leadership, technical expertise, and the ability to communicate risks effectively to stakeholders.

More about Vulnerability Management Lead jobs
Infographic showing various Vulnerability Management Lead job openings in the United States as of July 2026, with employment types broken down into 88% Full Time, 9% Part Time, and 3% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $123,784 per year, or $59.5 per hour.

$115K - $135K/yr

Other

Posted 9 days ago


Job description

Job Description
Everforth ECS is seeking a Remote Vulnerability Management Lead who lives in close proximity to the National Capital Region (NCR) to join a premier, enterprise-scale cybersecurity program supporting a major federal civilian agency.
Please Note: This position is contingent upon contract award.
Salary Range: $115,000 - $135,000
This flagship initiative unifies 24x7x365 Security Operations (SOC), proactive threat hunting, and advanced Security Engineering and Architecture into a cohesive defensive mission. As a key leader on this program, you will drive the protection of highly sensitive, national-level financial and personally identifiable information (PII). You will be at the forefront of modernizing the agency's cyber posture, implementing advanced automation, and ensuring continuous operational resilience across a massive, highly complex federal IT enterprise.
As the Vulnerability Management Lead, you will serve as the principal technical authority for enterprise vulnerability identification, prioritization, and remediation across a large-scale federal civilian environment. Working closely with Information System Security Officers (ISSOs), Information System Owners (ISOs), compliance teams, and engineering personnel. You will drive a proactive, risk-based approach to vulnerability management, delivering measurable reductions in the agency's attack surface while ensuring continuous alignment with federal compliance requirements.
Position Responsibilities:
  • Oversee enterprise vulnerability scanning operations, remediation tracking, and stakeholder communication with POA&M support across the program.
  • Coordinate with ISOs, ISSOs, compliance, and engineering teams to identify, prioritize, and close security gaps in a timely and risk-informed manner.
  • Leads ATO, POA&M and continuous monitoring activities.
  • Develop and maintain dashboards and metrics to provide real-time visibility into vulnerability management posture, trends, and remediation progress.
  • Produce compliance reports and vulnerability governance data to support continuous monitoring, audit readiness, and cybersecurity decision-making.
  • Manage integration of vulnerability management tools including Tenable, AquaSec, and the Continuous Diagnostics and Mitigation (CDM) program into enterprise workflows.
  • Apply risk-based prioritization methodologies to ensure the most critical vulnerabilities are addressed in alignment with agency risk tolerance and compliance requirements.
  • Support the review and maintenance of Plans of Action & Milestones (POA&Ms), ensuring timely and accurate tracking of identified vulnerabilities and remediation activities.
  • Collaborate with SOC, threat hunting, and security engineering teams to correlate vulnerability data with active threat intelligence and hunting findings.
  • Present vulnerability management findings, risk recommendations, and program metrics to both technical teams and senior government officials in a clear, actionable format.
  • Develop and refine vulnerability management policies, procedures, and standard operating procedures to ensure alignment with federal regulations and agency requirements.
Support continuous monitoring activities and provide input into the overall security posture of the agency's federal IT enterprise.
Required Skills
  • US. Citizenship required.
  • 6+ years of cybersecurity experience, with demonstrated expertise in vulnerability management, operating systems, and networking.
  • Remote but within close proximity to the NCR.
  • Active Public Trust 6c clearance, or the ability to obtain and maintain one.
  • At least one of the following certifications: GCIH, CISSP, CISM, or CRISC.
  • Hands-on experience with Tenable, AquaSec, and CDM integration in a federal or enterprise environment.
  • Strong understanding of federal compliance frameworks including NIST RMF, NIST SP 800-53, FISMA, and FedRAMP requirements.
  • Experience developing and maintaining POA&Ms and supporting remediation tracking within federal information system environments.
  • Demonstrated ability to coordinate cross-functional teams, including ISOs, ISSOs, compliance, and engineering stakeholders, to drive vulnerability remediation efforts.
  • Proven ability to translate complex technical vulnerability findings into clear, actionable language for both technical and executive audiences.
  • Strong written and verbal communication skills, with a track record of producing high-quality federal security documentation.

Desired Skills
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent professional experience.
  • One of the following certifications
    • Certified Information Systems Auditor (CISA)
    • Tenable Certified Security Engineer or equivalent
    • AWS Cloud Practitioner or higher, with AWS GovCloud experience desired
  • CompTIA Security+ or equivalent
  • Familiarity with federal cybersecurity governance frameworks including IRS Publication 1075 and OMB compliance requirements.
  • Prior experience working on large-scale federal civilian agency programs with complex, multi-stakeholder environments.
  • Experience with cloud-native vulnerability management in AWS GovCloud or Azure Government environments.
  • Ability to provide strategic guidance that enhances and optimizes an agency's overall information security and vulnerability management posture.
  • Experience developing vulnerability management dashboards using tools such as Splunk, Elasticsearch, or agency-specific reporting platforms.
  • Knowledge of DevSecOps pipelines and the integration of vulnerability scanning within CI/CD workflows.
ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.
Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!