Vulnerability Management Specialist

Hybrid in Springfield, VA, US • Posted 1 hour ago • Updated 1 hour ago
Contract W2
12 Months
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • vulnerability management
  • Qualys
  • Breach and Attack
  • Microsoft Defender
  • CSPM
  • CISSP
  • ServiceNow

Summary

Role: Vulnerability Management Specialist
Location :Springfield, VA
( Springfield, Virginia: Minimum three (3) days per week in office, mandatory. Duration: 12 months

Interview Process/# of Rounds: Targeting 1 round, but might go into 2

Additional Notes:

Why the role is open: Standing up an internial AI practice.

Job Title: Contractor, Vulnerability Management

Reporting Relationship: Reports to the Practice Lead, Vulnerability Management
PRIMARY DUTIES
Strategy & Planning

Support the execution and continuous improvement of the enterprise Vulnerability Management Program.

Assist in developing vulnerability management standards, procedures, metrics, and reporting processes.

Work with cybersecurity architecture and engineering teams to identify systemic security gaps and recommend remediation strategies.

Provide subject matter expertise to project teams throughout project lifecycles to ensure security vulnerabilities are appropriately addressed.

Participate in risk discussions and provide recommendations regarding remediation prioritization and compensating controls.

Acquisition & Deployment

Support deployment, configuration, and optimization of vulnerability management and security assessment technologies.

Assist with onboarding new environments, applications, and cloud services into the vulnerability management program.

Support implementation and operation of Breach and Attack Simulation (BAS) capabilities to validate security controls and identify opportunities for improvement.

Collaborate with cloud, infrastructure, and application teams to improve security posture and vulnerability visibility.

Operational Management

Conduct vulnerability assessments across infrastructure, cloud, and application environments.

Analyze, validate, and prioritize vulnerabilities based on risk, exploitability, business impact, and threat intelligence.

Coordinate remediation activities with project teams, technical teams, managed service providers, and third-party vendors.

Track remediation progress and escalate high-risk issues as required.

Facilitate vulnerability review meetings and drive accountability for remediation commitments.

Utilize ServiceNow to manage workflows, remediation tracking, exception management, and reporting activities.

Generate operational and executive reporting that communicates vulnerability trends, risk exposure, remediation performance, and program effectiveness.

Support audits, assessments, penetration tests, and regulatory reviews related to cyber security controls.

Collaborate with Cyber Operations, Cyber Risk Management, Architecture, Infrastructure, and Application Delivery teams to ensure vulnerabilities are addressed in a manner that balances security, operational reliability, and project delivery objectives.

Assist in validating remediation efforts and confirming closure of identified vulnerabilities.

Support continuous improvement initiatives aimed at reducing organizational risk and improving security posture.

QUALIFICATIONS, SKILLS & ABILITIES
Technical Attributes
Required Experience

7+ years of cyber security, vulnerability management, or security operations experience.

Demonstrated experience managing enterprise vulnerability remediation programs.

Hands-on experience with Qualys Vulnerability Management.

Experience with Breach and Attack Simulation (BAS) technologies.

Experience with Microsoft security technologies, including:

Microsoft Defender

Microsoft Cloud Security Posture Management (CSPM)

Azure

Azure DevOps (ADO)

Experience with ServiceNow workflow management and reporting.

Experience supporting cloud security and vulnerability management initiatives.

Experience working within large enterprise environments with diverse technology ecosystems.

Strong understanding of vulnerability prioritization methodologies and risk-based remediation approaches.

Knowledge of cybersecurity frameworks and industry best practices, including NIST.

Preferred Experience

Experience supporting utility, critical infrastructure, energy, or industrial organizations.

Experience leveraging threat intelligence to prioritize remediation activities.

Experience supporting security assessments, penetration testing, and audit remediation programs.

Familiarity with security operations, incident response, and defensive security technologies.

Personal Attributes

Strong relationship-building and stakeholder engagement skills.

Ability to work collaboratively with business, technical, and third-party teams.

Capable of influencing and driving remediation activities without direct authority.

Strong analytical and problem-solving abilities.

Excellent verbal, written, and presentation skills.

Ability to communicate technical security issues in business-friendly language.

Strong organizational skills with the ability to manage multiple priorities simultaneously.

Highly self-motivated with strong attention to detail.

Team-oriented and committed to supporting enterprise objectives while maintaining security requirements.

EDUCATION
Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or a related field preferred.
Equivalent combination of education and relevant professional experience will be considered.
WORK EXPERIENCE

Minimum 7 years of experience in Cyber Security, Vulnerability Management, Security Operations, Infrastructure Security, or a related discipline.

Demonstrated experience working with project delivery teams and enterprise technology stakeholders.

Experience producing executive-level metrics, dashboards, and program reporting.

CERTIFICATIONS (Preferred)
One or more of the following:

CISSP

GIAC Vulnerability Management (if held)

GIAC Security Essentials (GSEC)

GIAC Continuous Monitoring Certification (GMON)

Certified Information Security Manager (CISM)

Microsoft Security Certifications

Microsoft Azure Security Engineer Associate (AZ-500)

Qualys Certified Specialist certifications

Regards,

Nick Arthur (Nizam)

Associate Director, Recruitment

Pull Skill Technologies Inc.

Direct: +1 551-272-o197

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90922281
  • Position Id: 9080656
  • Posted 1 hour ago
Contact the job poster
Nick Arthur

Nick Arthur

Recruiter @ Pull Skill Technologies
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Oxon Hill, Maryland

Today

Easy Apply

Full-time

$48 - $50 per hour

Suitland-Silver Hill, Maryland

5d ago

Full-time

USD 110,000.00 - 130,000.00 per year

Reston, Virginia

Today

Full-time

Bethesda, Maryland

Today

Full-time

USD 90,000.00 - 130,000.00 per year

Search all similar jobs