Enter a job title or keyword

Vulnerability Management Lead

Steampunk


Job Location:

McLean, MD - USA

Monthly Salary: $ 125000 - 175000
Posted: 22 August 2026 (Yesterday)
Application Deadline: 19 November 2026
Vacancies: 1 Vacancy

Job Summary

Overview

We are seeking a Vulnerability Management Lead responsible for planning executing and continuously maturing the enterprise vulnerability management program across a large-scale complex IT environment supporting more than 30000 enterprise assets including servers workstations high performance computing (HPC) systems cloud workloads and network infrastructure.

The Vulnerability Management Lead serves as the primary technical authority for enterprise vulnerability management partnering with cybersecurity operations infrastructure cloud engineering and system owners to identify prioritize and drive remediation efforts. This role is responsible for developing risk-based vulnerability management processes improving automation and reporting capabilities and ensuring alignment with federal cybersecurity directives NIST guidance and organizational security policies.

Contributions

Responsibilities include:

  • Lead the enterprise vulnerability management program across servers workstations HPC systems cloud environments and network devices supporting more than 30000 managed assets.
  • Plan coordinate and oversee enterprise vulnerability scanning assessment prioritization remediation tracking validation and reporting activities.
  • Collaborate with Service Areas system owners cloud administrators cybersecurity engineers and infrastructure teams to identify prioritize and track vulnerability remediation efforts.
  • Develop and maintain risk-based prioritization methodologies utilizing exploitability threat intelligence asset criticality and business impact to mature enterprise vulnerability management practices.
  • Drive enterprise remediation activities in alignment with applicable federal directives including Binding Operational Directive (BOD) 22-01 and organizational security requirements.
  • Develop and enhance enterprise vulnerability management processes procedures templates and operational standards.
  • Design and implement automation solutions that improve vulnerability data collection remediation tracking reporting and operational efficiency.
  • Leverage automation and artificial intelligence/machine learning (AI/ML) capabilities to improve vulnerability scan integration prioritization reporting and risk trend prediction across the enterprise vulnerability management program.
  • Develop and maintain enterprise dashboards weekly reporting and executive visualizations utilizing Power BI Power Apps SharePoint and similar enterprise reporting platforms including R/Y/G reporting and heat-map visualizations.
  • Identify tool process and data flow improvement opportunities while maintaining the Vulnerability Management Process Improvement Plan and Vulnerability Management Automation Plan to continuously mature the enterprise vulnerability management program.
  • Ensure vulnerability management activities align with NIST SP 800-53 organizational policies and applicable federal cybersecurity directives including BOD 22-01.
  • Develop and maintain vulnerability management documentation including standard operating procedures (SOPs) remediation guidance risk mitigation strategies process improvement plans and automation roadmaps.
  • Identify opportunities to improve enterprise vulnerability management through process optimization workflow improvements enhanced automation and data quality initiatives.
  • Support continuous monitoring activities and collaborate with stakeholders to strengthen the organizations overall cybersecurity posture.
  • Stay current on emerging vulnerabilities threat intelligence federal cybersecurity directives and industry best practices.

Qualifications

  • Ability to obtain and maintain a U.S. government Security Clearance.
  • Bachelors degree in Cybersecurity Information Technology Computer Science Information Systems or a related field (or equivalent combination of education and experience).
  • Minimum of 5 years of hands-on experience supporting enterprise vulnerability management cybersecurity operations and risk remediation workflows.
  • Experience managing enterprise vulnerability management programs across more than 30000 enterprise assets including servers workstations high performance computing (HPC) systems cloud workloads (AWS Azure and Google Cloud Platform) and network devices while driving patching and remediation activities in accordance with BOD 22-01.
  • Experience collaborating with Service Areas system owners cloud administrators cybersecurity engineers and infrastructure teams to identify prioritize and track vulnerability remediation efforts.
  • Experience developing and implementing risk-based prioritization methodologies utilizing exploitability threat intelligence asset criticality and business impact to mature enterprise vulnerability management practices.
  • Experience leveraging automation and AI/ML capabilities to improve vulnerability scan integration prioritization reporting and risk trend prediction.
  • Experience developing enterprise dashboards weekly reporting and operational metrics utilizing Power BI Power Apps SharePoint and similar enterprise reporting platforms including R/Y/G reporting and heat-map visualizations.
  • Experience identifying enterprise tool process and data flow improvement opportunities while maintaining vulnerability management process improvement and automation plans.
  • Experience developing enterprise vulnerability management processes standard operating procedures documentation and continuous process improvement initiatives.
  • Strong knowledge of federal cybersecurity requirements including NIST SP 800-53 and applicable federal vulnerability management directives.
  • Strong analytical organizational written and verbal communication skills with the ability to communicate effectively across technical and executive stakeholders.

Preferred

  • Experience supporting cybersecurity programs within a federal government environment.
  • Experience supporting enterprise continuous monitoring initiatives.
  • One or more of the following certifications:
    • CompTIA Security
    • CISSP
    • CISM
    • CISA
    • CCSP
    • OSCP

About steampunk

Steampunk relies on several factors to determine salary including but not limited to geographic location contractual requirements education knowledge skills competencies and experience. The projected compensation range for this position is $125000 to $175000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunks total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is a Change Agent in the Federal contracting industry bringing new thinking to clients in the Homeland Federal Civilian Health and DoD sectors. Through our Human-Centered delivery methodology we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company we focus on investing in our employees to enable them to do the greatest work of their careers and rewarding them for outstanding contributions to our growth. If you want to learn more about our story visit .

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race color religion sex national origin disability status protected veteran status or any other characteristic protected by participates in the E-Verify program.


About Company

Company Logo

Federal government clients at the center of everything we design, develop, and deliver to drive game-changing mission impacts.

View Profile View Profile