← Back to jobs
Virginia Drive, Springfield, VA, USA
No related jobs found
PRIMARY DUTIES
Strategy & Planning
• Support the execution and continuous improvement of the enterprise Vulnerability Management Program.
• Assist in developing vulnerability management standards, procedures, metrics, and reporting processes.
• Work with cybersecurity architecture and engineering teams to identify systemic security gaps and recommend remediation strategies.
• Provide subject matter expertise to project teams throughout project lifecycles to ensure security vulnerabilities are appropriately addressed.
• Participate in risk discussions and provide recommendations regarding remediation prioritization and compensating controls.
Acquisition & Deployment
• Support deployment, configuration, and optimization of vulnerability management and security assessment technologies.
• Assist with onboarding new environments, applications, and cloud services into the vulnerability management program.
• Support implementation and operation of Breach and Attack Simulation (BAS) capabilities to validate security controls and identify opportunities for improvement.
• Collaborate with cloud, infrastructure, and application teams to improve security posture and vulnerability visibility.
Operational Management
• Conduct vulnerability assessments across infrastructure, cloud, and application environments.
• Analyze, validate, and prioritize vulnerabilities based on risk, exploitability, business impact, and threat intelligence.
• Coordinate remediation activities with project teams, technical teams, managed service providers, and third-party vendors.
• Track remediation progress and escalate high-risk issues as required.
• Facilitate vulnerability review meetings and drive accountability for remediation commitments.
• Utilize ServiceNow to manage workflows, remediation tracking, exception management, and reporting activities.
• Generate operational and executive reporting that communicates vulnerability trends, risk exposure, remediation performance, and program effectiveness.
• Support audits, assessments, penetration tests, and regulatory reviews related to cyber security controls.
• Collaborate with Cyber Operations, Cyber Risk Management, Architecture, Infrastructure, and Application Delivery teams to ensure vulnerabilities are addressed in a manner that balances security, operational reliability, and project delivery objectives.
• Assist in validating remediation efforts and confirming closure of identified vulnerabilities.
• Support continuous improvement initiatives aimed at reducing organizational risk and improving security posture.
QUALIFICATIONS, SKILLS & ABILITIES
Technical Attributes
Required Experience
• 7+ years of cyber security, vulnerability management, or security operations experience.
• Demonstrated experience managing enterprise vulnerability remediation programs.
• Hands-on experience with Qualys Vulnerability Management.
• Experience with Breach and Attack Simulation (BAS) technologies.
• Experience with Microsoft security technologies, including:
• Microsoft Defender
• Microsoft Cloud Security Posture Management (CSPM)
• Azure
• Azure DevOps (ADO)
• Experience with ServiceNow workflow management and reporting.
• Experience supporting cloud security and vulnerability management initiatives.
• Experience working within large enterprise environments with diverse technology ecosystems.
• Strong understanding of vulnerability prioritization methodologies and risk-based remediation approaches.
• Knowledge of cybersecurity frameworks and industry best practices, including NIST.
Preferred Experience
• Experience supporting utility, critical infrastructure, energy, or industrial organizations.
• Experience leveraging threat intelligence to prioritize remediation activities.
• Experience supporting security assessments, penetration testing, and audit remediation programs.
• Familiarity with security operations, incident response, and defensive security technologies.
Personal Attributes
• Strong relationship-building and stakeholder engagement skills.
• Ability to work collaboratively with business, technical, and third-party teams.
• Capable of influencing and driving remediation activities without direct authority.
• Strong analytical and problem-solving abilities.
• Excellent verbal, written, and presentation skills.
• Ability to communicate technical security issues in business-friendly language.
• Strong organizational skills with the ability to manage multiple priorities simultaneously.
• Highly self-motivated with strong attention to detail.
• Team-oriented and committed to supporting enterprise objectives while maintaining security requirements.
EDUCATION
Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or a related field preferred.
Equivalent combination of education and relevant professional experience will be considered.
WORK EXPERIENCE
• Minimum 7 years of experience in Cyber Security, Vulnerability Management, Security Operations, Infrastructure Security, or a related discipline.
• Demonstrated experience working with project delivery teams and enterprise technology stakeholders.
• Experience producing executive-level metrics, dashboards, and program reporting.
CERTIFICATIONS (Preferred)
One or more of the following:
• CISSP
• GIAC Vulnerability Management (if held)
• GIAC Security Essentials (GSEC)
• GIAC Continuous Monitoring Certification (GMON)
• Certified Information Security Manager (CISM)
• Microsoft Security Certifications
• Microsoft Azure Security Engineer Associate (AZ-500)
• Qualys Certified Specialist certifications
Bachelor's degree
No related jobs found
← Back to jobs