$155,000 – $160,000/yr

Vulnerability Manager Lead

United StatesUnited States·Herndonlead
OtherManager
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Key Responsibilities Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets, traditional hybrid infrastructure, and AI/LLM application stacks.

Technical Tools
OtherManager

Responsibilities

~2 min read
  • Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets, traditional hybrid infrastructure, and AI/LLM application stacks. 
  • Evaluate raw vulnerability data generated by ACAS (Tenable.sc) and AWS security tools to determine its actual threat vector; identify true contextual risk based on compensating controls, network exposure, and the system's specific cloud architecture.
  • Leverage ACAS to execute and analyze SCAP-compliant configuration audits, verifying system alignment with established DISA STIG security benchmarks and identifying configuration drift across cloud assets. 
  • Monitor, document, and track the end-to-end lifecycle of technical remediation efforts.
  • Establish and manage cybersecurity vulnerability tickets within Jira to maintain a clear audit trail from identification to closure.
  • Serve as a primary point of contact for hands-on IT support, system administrators, and engineers; clearly communicate the technical details of vulnerabilities, outline required remediation steps, and assist in prioritizing patches.
  • Translate un-remediated, high-true-risk vulnerabilities into actionable Plan of Action and Milestones (POA&Ms), clearly detailing the technical milestones and business impacts.
  • Translate complex technical findings and AI-specific security risks into concrete, step-by-step remediation guidance for platform, data science, and DevOps engineering teams. 
  • Collaborate with the team to cross-reference active exploit intelligence against known system vulnerabilities, refining true risk prioritizations based on active real-world threats.
  • Compile and deliver vulnerability posture reports, metrics dashboards, and executive briefings for government stakeholders. 
  • Mentor mid-level analysts on triage methodologies, emerging AI threat vectors, technical writing, and workflow automation. 

Requirements

~2 min read
  • 6+ years of experience in Cybersecurity, Vulnerability Management, or Systems Administration supporting federal or DoD information systems.
  • Direct, hands-on experience utilizing ACAS (Tenable.sc) to filter, analyze, and report on enterprise vulnerabilities.
  • Operational understanding of the Security Content Automation Protocol (SCAP) ecosystem, including how automated configuration audit files translate into compliance metrics within vulnerability scanners.
  • Comprehensive understanding of how Splunk Enterprise Security and Trellix (ESS) correlate with vulnerability monitoring activities 
  • Practical experience writing SQL queries for reporting and/or analytics
  • Proven proficiency utilizing Jira (or equivalent enterprise ticketing infrastructure) to track, update, and manage technical workflows through completion.
  • Excellent interpersonal and written communication skills, with a demonstrated ability to translate complex security vulnerabilities into actionable guidance for IT personnel.
  • Solid understanding of core AWS services (EC2, VPC, Security Groups, IAM) and how vulnerabilities manifest within a cloud-native environment.
  • Must hold an active DoD 8570/8140 IAT Level II certification (e.g., Security+, CySA+).
  • U.S. Citizenship with an active Top Secret security clearance
  • Possess a valid DISA certification for ACAS, Trellix, or Splunk issued or renewed within the last three years, or demonstrate the capability to successfully obtain the required DISA certification upon hire.
  • Familiarity with tracking vulnerabilities across containerized microservices (Docker/Kubernetes) or modern data platforms like Databricks.
  • Ability to identify and evaluate vulnerabilities unique to AI/LLM environments, including model training/inference pipelines, API endpoints, microservices, and AI framework dependencies (e.g., PyTorch, LangChain, Hugging Face) using frameworks like the OWASP Top 10 for LLM Applications.

The salary range for this position is estimated to be between $155,000.00 - $160,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.

Location & Eligibility

Where is the job
Herndon, United States
On-site at the office
Who can apply
US

Listing Details

Posted
August 6, 2026
First seen
August 6, 2026
Last seen
August 7, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
71%
Scored at
August 6, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

D
Vulnerability Manager Lead $155k–$160k