1

Vulnerability Management Jobs in Silver Spring, MD

Vulnerability Management Lead

Mclean, VA ยท On-site

$103K - $136K/yr

The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and ...

Vulnerability Management Lead

Mclean, VA ยท On-site

$103K - $136K/yr

We are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT ...

New

Vulnerability Management Lead

Mclean, VA ยท On-site

$103K - $136K/yr

The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and ...

Vulnerability Management Lead

Washington, DC ยท On-site

$116K - $152K/yr

Position Summary Own enterprise vulnerability management as a sustained program function - tracking, analysis, prioritization, remediation coordination, and trend reporting across systems ...

New

Vulnerability Management Analyst Location- Joint Base Andrews, MD Clearance- Secret Certifications- CompTIA Security+ or equivalent About TIME Systems At TIME Systems, we are at the forefront of ...

Vulnerability Management Analyst Location- Joint Base Andrews, MD Clearance- Secret Certifications- CompTIA Security+ or equivalent About TIME Systems At TIME Systems, we are at the forefront of ...

ISSO - Vulnerability Management

MD ยท On-site

$100K - $114K/yr

The ISSO - Vulnerability Management will play a critical role in maintaining the cybersecurity posture of enterprise systems supporting national defense missions. This position is responsible for ...

Vulnerability Management Lead (RFP)

Washington, DC ยท On-site

$115K - $152K/yr

They are in search of a highly motivated candidate to join their talented team as a Vulnerability Management Lead, responsible for coordinating vulnerability tracking, remediation support, reporting ...

Vulnerability Management Team Lead

Bethesda, MD ยท On-site

$150K - $180K/yr

GovCIO is currently hiring for a Vulnerability Management Team Lead to provide support to a Federal government contract. The Vulnerability Team Lead will be leading critical support for the ...

next page

Showing results 1-20

Vulnerability Management information

See Silver Spring, MD salary details

$5

$62

$86

How much do vulnerability management jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for vulnerability management in Silver Spring, MD is $62.80, according to ZipRecruiter salary data. Most workers in this role earn between $51.87 and $74.49 per hour, depending on experience, location, and employer.

What are the common challenges faced in a vulnerability management role?

Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.

What does a vulnerability management do?

A vulnerability management professional is responsible for identifying, assessing, and prioritizing security vulnerabilities in an organization's systems and networks. They use tools like vulnerability scanners and follow best practices to mitigate risks, often working closely with security teams and maintaining documentation for compliance. This role requires technical knowledge of cybersecurity principles and may involve certifications such as CISSP or CompTIA Security+.

What are the key skills and qualifications needed to thrive in a vulnerability management position?

To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires knowledge of security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and demand for skilled professionals.

What is vulnerability management?

A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

What are the most commonly searched types of Vulnerability Management jobs in Silver Spring, MD? The most popular types of Vulnerability Management jobs in Silver Spring, MD are:
What are popular job titles related to Vulnerability Management jobs in Silver Spring, MD? For Vulnerability Management jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Vulnerability Management jobs in Silver Spring, MD look for? The top searched job categories for Vulnerability Management jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Vulnerability Management jobs? Cities near Silver Spring, MD with the most Vulnerability Management job openings:
Infographic showing various Vulnerability Management job openings in Silver Spring, MD as of August 2026, with employment types broken down into 78% Full Time, 19% Part Time, 1% Temporary, and 2% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $130,626 per year, or $62.8 per hour.

Vulnerability Management Lead

Steampunk

Mclean, VA โ€ข On-site

$103K - $136K/yr

Other

Posted 4 days ago


Job description

Overview
We are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise vulnerability management program across a large-scale, complex IT environment supporting more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads, and network infrastructure.
The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management, partnering with cybersecurity operations, infrastructure, cloud, engineering, and system owners to identify, prioritize, and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes, improving automation and reporting capabilities, and ensuring alignment with federal cybersecurity directives, NIST guidance, and organizational security policies.
Contributions
Responsibilities include:
  • Lead the enterprise vulnerability management program across servers, workstations, HPC systems, cloud environments, and network devices supporting more than 30,000 managed assets.
  • Plan, coordinate, and oversee enterprise vulnerability scanning, assessment, prioritization, remediation tracking, validation, and reporting activities.
  • Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.
  • Develop and maintain risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.
  • Drive enterprise remediation activities in alignment with applicable federal directives, including Binding Operational Directive (BOD) 22-01, and organizational security requirements.
  • Develop and enhance enterprise vulnerability management processes, procedures, templates, and operational standards.
  • Design and implement automation solutions that improve vulnerability data collection, remediation tracking, reporting, and operational efficiency.
  • Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction across the enterprise vulnerability management program.
  • Develop and maintain enterprise dashboards, weekly reporting, and executive visualizations utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.
  • Identify tool, process, and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program.
  • Ensure vulnerability management activities align with NIST SP 800-53, organizational policies, and applicable federal cybersecurity directives, including BOD 22-01.
  • Develop and maintain vulnerability management documentation, including standard operating procedures (SOPs), remediation guidance, risk mitigation strategies, process improvement plans, and automation roadmaps.
  • Identify opportunities to improve enterprise vulnerability management through process optimization, workflow improvements, enhanced automation, and data quality initiatives.
  • Support continuous monitoring activities and collaborate with stakeholders to strengthen the organization's overall cybersecurity posture.
  • Stay current on emerging vulnerabilities, threat intelligence, federal cybersecurity directives, and industry best practices.

Qualifications
Required
  • Ability to obtain and maintain a U.S. government Security Clearance.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience).
  • Minimum of 5 years of hands-on experience supporting enterprise vulnerability management, cybersecurity operations, and risk remediation workflows.
  • Experience managing enterprise vulnerability management programs across more than 30,000 enterprise assets, including servers, workstations, high performance computing (HPC) systems, cloud workloads (AWS, Azure, and Google Cloud Platform), and network devices while driving patching and remediation activities in accordance with BOD 22-01.
  • Experience collaborating with Service Areas, system owners, cloud administrators, cybersecurity engineers, and infrastructure teams to identify, prioritize, and track vulnerability remediation efforts.
  • Experience developing and implementing risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature enterprise vulnerability management practices.
  • Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration, prioritization, reporting, and risk trend prediction.
  • Experience developing enterprise dashboards, weekly reporting, and operational metrics utilizing Power BI, Power Apps, SharePoint, and similar enterprise reporting platforms, including R/Y/G reporting and heat-map visualizations.
  • Experience identifying enterprise tool, process, and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans.
  • Experience developing enterprise vulnerability management processes, standard operating procedures, documentation, and continuous process improvement initiatives.
  • Strong knowledge of federal cybersecurity requirements, including NIST SP 800-53 and applicable federal vulnerability management directives.
  • Strong analytical, organizational, written, and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders.

Preferred
  • Experience supporting cybersecurity programs within a federal government environment.
  • Experience supporting enterprise continuous monitoring initiatives.
  • One or more of the following certifications:
    • CompTIA Security+
    • CISSP
    • CISM
    • CISA
    • CCSP
    • OSCP

About steampunk
Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers - and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit http://www.steampunk.com.
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.