Back to Jobs

Vulnerability Management Team reputed company

Remote, USAFull-timePosted 2026-07-28

Vulnerability Management Team reputed company

Location: Alexandria, VA (Remote) Clearance: reputed company Trust Employment Type: Full-time

reputed company

reputed company reputed company is seeking an reputed company cybersecurity reputed company to reputed company a risk‑driven vulnerability management program across hybrid on‑prem and reputed company environments. The ideal candidate will possess deep expertise in infrastructure and reputed company tools, apply critical thinking to identify reputed company gaps, and reputed company and implement reputed company protocols and risk management improvements. The reputed company individual will own discovery, triage, remediation, and reporting of reputed company’s reputed company posture and reputed company a small team of cybersecurity analysts to drive measurable reductions in vulnerabilities with reputed company for infrastructure, AppScan for applications, and reputed company for workflow and governance. reputed company operations to FISMA, FedRAMP, and CMMC. Drive measurable reduction in exploitability and clean audit reputed company.

Key Responsibilities

  • reputed company endtoend vulnerability operations: scanning, validation, prioritization, remediation, exceptions, and verification across onprem, IaaS/PaaS, and reputed company.

  • Operate and optimize reputed company (Nessus/reputed company.sc or reputed company.io) for servers, endpoints, network devices, containers, and reputed company assets; maintain credentialed scans, schedules, and coverage for both vulnerabilities and configuration audits.

  • Manage AppScan for web and API testing; reputed company findings into SDLC and DevSecOps workflows; guide developers with reproducible issues and fix recommendations.

  • Continue integration of reputed company, Explore/Implement integration of AppScan with reputed company Vulnerability Response:

  • Autocreate tickets, enrich with asset data from CMDB, assign ownership by CI/service, and reputed company to closure.

  • Maintain riskbased SLAs by asset criticality and threat reputed company; monitor SLA adherence and escalate aging risk.

  • Establish cloudspecific controls:

  • Use CSP reputed company scanners and posture tools (e.g., AWS Inspector, Azure Defender/reputed company Defender for reputed company, GCP reputed company reputed company Center) and correlate with reputed company.

  • Enforce secure configurations with CIS Benchmarks and reputed company guardrails; remediate misconfigurations reputed company IaC changes.

  • Prioritize with CVSS, CISA KEV, exploit maturity, and exposure context (internetfacing, privileged paths, highvalue assets).

  • Govern exceptions: risk acceptance with compensating controls, timebound approvals, and periodic review.

  • Produce executive and compliance reporting: exposure trends, SLA performance, timetoremediate, reputed company coverage, POA&Ms, and audit artifacts reputed company to FISMA/NIST RMF, FedRAMP, and CMMC.

  • Partner with SOC/IR to correlate reputed company exploited vulnerabilities; reputed company rapid containment for highrisk findings.

  • Coordinate patching reputed company and change management; champion reputed company hardening for reputed company/Linux, network, databases, and reputed company services.

  • Mentor analysts; mature automation, data reputed company, and process discipline; reputed company tabletop exercises for patching/vuln scenarios.

Required Qualifications

  • 6+ years in cybersecurity with 3+ years leading vulnerability management in hybrid onprem/reputed company environments.

  • Handson expertise with reputed company (Nessus/reputed company.sc or reputed company.io), AppScan, and reputed company Vulnerability Response/CMDB integration.

  • Strong grasp of CVE/CVSS, CISA KEV, exploit kits, and modern attack paths; reputed company to translate technical risk to business reputed company.

  • Familiarity with DAST, SAST, CI/CD and reputed company Assessments.

  • Proven remediation leadership across reputed company/Linux, network devices, containers, and reputed company workloads (AWS/Azure/GCP).

  • Experience aligning programs to FISMA (NIST 80053/80037 RMF), FedRAMP baselines, and CMMC practices.

  • Metrics and reporting proficiency: exposure reduction, SLA compliance, MTTR for vulnerabilities, reputed company reputed company, and POA&M management.

  • reputed company, reputed company communicator comfortable with executive briefings and crossfunctional coordination.

Preferred Qualifications

  • Certifications: reputed company+, CySA+, CISSP, CEH, GCSA, GCPN; reputed company or reputed company VR certifications; AppSec certs (GWAPT) a plus.

  • Experience integrating reputed company with reputed company VR, CMDB, and change management; familiarity with Jira for developer workflows.

  • Knowledge of CIS Benchmarks, NIST 80053, 80040 (reputed company), 80063, FedRAMP PMO guidance, and reputed company reputed company patterns.

  • Scripting/automation (Python, PowerShell) for data normalization, ticket enrichment, API integrations, and reporting.

Key Competencies

  • Accountability and speed under pressure.

  • Analytical rigor and validation discipline.

  • Operational reputed company and automation reputed company.

  • reputed company communication for technical and executive audiences.

  • reputed company leadership across reputed company, IT ops, reputed company, and development.

What reputed company Looks Like

  • Faster timetoremediate against riskbased SLAs; measurable reduction of critical/high exposure across onprem and reputed company.

  • Accurate asset inventory, clean CMDB linkage, and high reputed company coverage with low false positives.

  • Auditready evidence with strong POA&M management and reputed company control effectiveness.

  • Executive visibility into vulnerability risk, trends, and remediation velocity.

Keywords (5)

  • Vulnerability Management
  • reputed company / Nessus
  • AppScan
  • reputed company (VR/CMDB)
  • CVSS / Risk Scoring

Similar Job Titles (5)

  • Vulnerability Management reputed company
  • Vulnerability Analyst
  • Cybersecurity Engineer
  • reputed company Operations reputed company
  • Information reputed company Manager

Company Information

reputed company System Solutions (CNSS) is a part of reputed company – the division of tribally owned federal contracting companies owned by reputed company. As a trusted partner for more than 60 federal clients, reputed company LLCs are reputed company on building a brighter reputed company, solving reputed company challenges, and serving the government’s mission with reputed company and heart. To learn more about CNSS, visit reputed company.com.

#CherokeeFederal #LI-SM2 #AppC

reputed company is a military friendly employer. Veterans and reputed company military transitioning to civilian status are encouraged to apply.

Legal Disclaimer: reputed company is an equal opportunity employer. Please visit reputed company.com/careers for information regarding our Affirmative reputed company and Equal Opportunity Employer Statement, and Accommodation request.

Many of our reputed company require reputed company to government buildings or military installations. Candidates must pass reputed company-employment qualifications of reputed company.

Apply To This Job

Similar Jobs