Role Description:
The successful candidate will support the planning, operation, modernization, and continuous improvement of the Department's Vulnerability Management and Contingency Planning Programs. Responsibilities include program management, cybersecurity operations, compliance, reporting, automation, and technical advisory services.
Key Responsibilities:
• Support enterprise Vulnerability Management (VM) operations across on-premises, cloud, SaaS, and hybrid environments.
• Perform vulnerability analysis, prioritization, tracking, and remediation oversight.
• Manage Known Exploited Vulnerabilities (KEVs) and ensure compliance with CISA Binding Operational Directives.
• Coordinate enterprise vulnerability data collection, validation, and quality assurance.
• Administer and maintain vulnerability management platforms and security tools.
• Support scanning technologies including operating systems, databases, web applications, cloud environments, and external assets.
• Monitor cybersecurity tools for operational health and performance.
• Coordinate change management activities, maintenance windows, and operational support.
• Develop Standard Operating Procedures (SOPs), policies, templates, implementation guidance, and technical documentation.
• Assist with Governance, Risk, and Compliance (GRC) activities and enterprise control implementation.
• Prepare audit artifacts, evidence packages, corrective action plans (CAPs), and responses to audit findings.
• Track remediation activities and support audit readiness initiatives.
• Support enterprise Contingency Planning (CP), Disaster Recovery (DR), Business Continuity (BCP), Tabletop Exercises (TTXs), and Incident Response planning.
• Produce After-Action Reports (AARs), lessons learned, and process improvements.
• Maintain contingency planning documentation and templates.
• Support AI-assisted vulnerability management, analytics, and reporting.
• Assist with enterprise cybersecurity modernization initiatives.
Required Qualifications & Education:
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related technical discipline.
• Minimum 6 to 10+ years of progressively responsible experience in Working knowledge of DHS CDM Program requirements, NIST SP 800-137 (Information Security Continuous Monitoring), NIST SP 800-53 controls (in particular RA-5 and SA-11), DHS BOD 18-01, and CISA Cyber Hygiene Services.
• Experience supporting POA&M development, remediation tracking, and closure within Cyber Security Assessment and Management (CSAM) or a comparable governance, risk, and compliance system.
• Experience with Cloud and cloud-native vulnerability scanning, including container image and Infrastructure-as-Code (IaC) assessment.
• Familiarity with CI/CD pipeline security controls and policy-as-code enforcement.
Experience integrating vulnerability data with SIEM and ticketing platforms such as ServiceNow.
• Familiarity with the client Technology Standards and Products Guide and client Lifecycle Management Methodology (LMM).
• Working knowledge of:
o NIST Risk Management Framework (RMF)
o NIST SP 800-53 Security Controls
o Federal Information Security Modernization Act (FISMA)
o CISA Binding Operational Directives (BODs)
o OMB cybersecurity guidance
• Experience conducting vulnerability assessments, security analysis, remediation tracking, and risk reporting.
• Experience supporting security audits, including FISMA, OIG, GAO, or independent assessments.
• Experience developing technical documentation such as Standard Operating Procedures (SOPs), implementation guides, playbooks, policies, and reports.
• Experience using enterprise vulnerability management and security assessment tools.
• Strong analytical, organizational, and problem-solving skills with the ability to manage multiple priorities.
• Excellent written and verbal communication skills with experience presenting technical information to technical and executive audiences.
• Experience collaborating with cross-functional teams, stakeholders, and government customers.
• Working knowledge of DHS CDM Program requirements, NIST SP 800-137 (Information Security Continuous Monitoring), NIST SP 800-53 controls (in particular RA-5 and SA-11), DHS BOD 18-01, and CISA Cyber Hygiene Services.
• Experience supporting POA&M development, remediation tracking, and closure within Cyber Security Assessment and Management (CSAM) or a comparable governance, risk, and compliance system.
Preferred Technical Experience
• Experience with one or more of the following technologies is highly desirable:
• Tenable Nessus
• OWASP
• Microsoft Power BI
• Microsoft Teams
• SharePoint
• Splunk
• Governance, Risk & Compliance (GRC) platforms
• Agile project management tools
Preferred Certifications
• Certified Information Security Manager (CISM)
• CompTIA Security+
• Other industry-recognized cybersecurity certifications relevant to vulnerability management, risk management, or information security.
Clearance and Location Requirements:
• Able to be cleared for a Public Trust clearance.
• This is a remote position.
We're ready to discuss your needs or dive in on your cyber defense journey. Let us know how we can help.
Contact us