Jobs · Project Management · Maryland

Vulnerability Management Team Lead

GovCIO · Bethesda, MD · 3 wk ago
On-siteProject Management$150k/yrFull-time

About the role

GovCIO is hiring a Vulnerability Management Team Lead to support a Federal government contract. The lead will oversee the Information Security’s vulnerability management program (VM) within the Office of the CIO, creating a proactive approach to prevent unauthorized access, changes, or exploitation of vulnerabilities through mitigation, active defenses, and automated responses. The VM team’s responsibilities include vulnerability detection and remediation oversight, vulnerability research, secure baseline compliance, web application security, host-based security, network security, and serving as security subject matter experts for the organization. This is a hybrid remote position located in Bethesda, MD.

Responsibilities

  • Perform project management activities, including assigning tasks, 1-1 coaching, timesheet reconciliation, and performance evaluations.
  • Lead the redesign, build, and day-to-day operations of the vulnerability management (VM) team, standardizing processes and managing customer expectations.
  • Manage a team of vulnerability management professionals focused on proactively preventing the exploitation of IT vulnerabilities.
  • Assign and complete VM projects, tasks, and initiatives on time and to vulnerability management standards.
  • Maintain a schedule of all VM team projects, tasks, and initiatives.
  • Track all team projects, tasks, and initiatives in a centralized location (e.g., Microsoft Lists, Jira).
  • Provide presentations and communications on relevant security documents across multiple teams and various layers of Federal management, including VM weekly project status reports, updates to the ISSO Forum presentation, monthly Executive briefings, and ad hoc reports.
  • Drive actionable metrics to reduce the time and resources needed to detect, investigate, analyze, and remediate vulnerabilities.
  • Manage performance of risk-based assessments of current and emerging information security issues to prioritize remediation efforts.
  • Proactively delegate support for regular vulnerability, compliance/configuration, database, and web application scanning.
  • Provide subject matter expert support and guidance to Information Security Systems Officers (ISSO), System Owners, and others through the risk management process and secure configuration baseline management, including regulatory and remediation compliance monitoring.
  • Apply problem-solving and critical thinking skills to evaluate solutions, conduct pilot evaluations for proof of concepts, and implement better mitigating controls.
  • Research current and emerging information security exploits, threats, and vulnerabilities and disseminate contextual information to appropriate stakeholders.
  • Facilitate exception handling, waiver processing, and escalations as needed.
  • Gather and organize technical information about the organization’s security posture, mission goals, information systems, and networks.
  • Proactively identify and troubleshoot problems within managed security tools.
  • Maintain regular communication with security leadership on process optimization, tool tuning, and resetting VM priorities as business needs recommend.

Requirements

  • Bachelor of Arts (B.A.) or Bachelor of Science (B.S.) degree, preferably in Computer Science, Information Technology, Electrical Engineering, or a related field.
  • 12 or more years of professional work experience in cybersecurity, with at least 5 years in Vulnerability Management.
  • 3 or more years managing or supervising a team of vulnerability management professionals.
  • Information Security-related certification(s) such as GPEN, GEVA, CISSP, etc.
  • US Citizenship is required to obtain and maintain Public Trust clearance.

Skills

Technical Competencies

  • Extensive knowledge and hands-on experience with Vulnerability Management Tools such as Tenable, DB Protect, Netsparker, Qualys, etc.
  • Expert knowledge of the Vulnerability Management lifecycle.
  • Proven track record of designing, implementing, and managing a Fortune 100-level Vulnerability Management Program.
  • Strong knowledge of networking, operating systems, databases, and web applications.
  • Strong knowledge of cybersecurity operations (Cyber Threat Intelligence, Penetration testing, & Incident Response).
  • Deep knowledge and experience performing both manual and automated asset discovery and enumeration.
  • Deep knowledge and experience of systematic and data-driven asset prioritization.
  • Expert knowledge and successful application of risk management frameworks.

Management Competencies

  • Track record of leading enterprise-level vulnerability management teams with a history of increasing responsibility.
  • Expert project management skills.
  • Ability to explain vulnerability management concepts to a wide range of audiences verbally and in writing.
  • Expertise in developing and improving vulnerability management operations and processes.
  • Strong interpersonal skills and the ability to collaborate with a variety of stakeholders to ensure vulnerability management compliance.
  • Expert problem-solving and critical thinking skills.
  • Proactive disposition and ability to execute on leadership vision with minimal oversight.

Pay

Posted Salary Range: USD $150,000.00 - USD $180,000.00 per year.

Similar jobs