Job Title: Senior Vulnerability Management Engineer / Lead
Location: Bethesda, Maryland
Type: Direct Hire / Perm
Work Model: 99% remote with occasional onsite for meetings
Security Clearance: Public Trust
Position Summary
The Senior Vulnerability Management Engineer leads enterprise vulnerability management activities across NIH/OD-managed environments, providing technical leadership for vulnerability identification, risk prioritization, remediation coordination, reporting, and compliance.
Key Responsibilities
- Lead enterprise vulnerability management operations and continuous program improvement.
- Manage and optimize vulnerability scanning infrastructure and tools.
- Oversee credentialed host, network, application, database, and endpoint vulnerability scanning.
- Analyze scan results and prioritize vulnerabilities based on risk and federal requirements.
- Lead vulnerability discovery, validation, mitigation, remediation tracking, and closure.
- Ensure critical vulnerabilities are escalated and tracked through resolution.
- Monitor the CISA Known Exploited Vulnerabilities (KEV) Catalog and other authoritative sources.
- Coordinate remediation activities with system owners and technical teams.
- Provide risk analysis and technical recommendations for identified vulnerabilities.
- Support specialized vulnerability assessments for High Value Assets.
- Develop reports, dashboards, metrics, and executive briefings.
- Ensure reporting complies with NIH, HHS, CISA, FISMA, and HVA requirements.
- Improve tool tuning, asset visibility, and reporting accuracy.
- Mentor mid-level and junior staff.
Minimum Qualifications - Bachelor''s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
- 8–12 years of cybersecurity experience, including at least 5 years in enterprise vulnerability management.
- Experience with Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or similar tools.
- Knowledge of CVEs, CVSS, KEVs, NIST guidance, FISMA, CISA directives, and federal vulnerability remediation requirements.
- Strong communication and reporting skills.
Recommended Certifications - CISSP
- CISM
- GIAC Certified Enterprise Defender (GCED)
- GIAC Certified Vulnerability Assessor (GCVA)
- CompTIA CySA+
- Tenable Certified Professional
- Qualys VMDR Certification
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
#M-2
#LI-CB5
Ref: #856-Baltimore-S1