National Vulnerability Database Program Manager
National Institute of Standards and Technology (NIST) · Gaithersburg, MD · 4 days ago
Information TechnologyFull-time
Duties
- ZP-IV: National Vulnerability Database Program Manager:
- Lead information security projects and technical teams with limited oversight to support NIST's cybersecurity mission.
- Manage the NVD and its associated software infrastructure, overseeing project lifecycles and technical teams to ensure operational excellence.
- Interact with relevant stakeholder groups to anticipate and determine the needs of end users, planning and implementing new capabilities as required.
- Support the ongoing development of global standards, including CVSS, CVE, and CPE, through active participation in international standards organizations.
- Identify deficiencies in the existing vulnerability management ecosystem to suggest and develop new capabilities and technical guidelines.
- ZP-V: National Vulnerability Database Program Manager:
- Provide expert leadership and strategic direction for the NVD portfolio and serve as a primary authority on vulnerability management standards.
- Define program goals and exercise wide latitude to influence the national security posture and the broader vulnerability management portfolio.
- Cook up with high-level stakeholders to identify complex end-user requirements and plan the integration of next-generation capabilities.
- Influence and drive the development of standards (e.g., CVSS, CVE, CPE) through leadership roles and high-impact contributions within standards-developing organizations.
- Architect new NIST-developed guidelines and national-level capabilities by identifying and addressing critical gaps in the vulnerability management ecosystem.
Qualifications
- Experience must be IT-related; the experience may be demonstrated by paid or unpaid experience and/or completion of specific, intensive training (for example, IT certification), as appropriate GS-5 through GS-15 (or equivalent).
- For all positions, individuals must have IT-related experience demonstrating each of the four competencies listed below.
- Attention to Detail- Is thorough when performing work and conscientious about attending to detail.
- Customer Service- Works with clients and customers to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services.
- Oral Communication- Expresses information effectively, taking into account the audience and nature of the information; makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately.
- Problem Solving- Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations.
- For the ZP-V: In addition to the above basic requirements, all applicants must have one year (52 weeks) of specialized experience equivalent to at least the GS-14 level (ZP-IV at NIST).
- The specialized experience is defined as:
- Experience working with vulnerability management identifiers and specifications such as CVE, CVSS, CPE, and CWE.
- Experience with CPE, Product-URL, SBOM, SWID, or different mechanisms of representing or modeling vulnerability information.
- Experience working with or in standards development to produce standards.