CyberSecurity Engineer (Vulnerability Management)

NexivaSpringfield, VA
Hybrid

About The Position

The Vulnerability Management Specialist Contractor is responsible for supporting Clients enterprise vulnerability management program through the identification, assessment, prioritization, reporting, and remediation of cybersecurity vulnerabilities across corporate IT, cloud, and digital environments. This role will work closely with project teams, infrastructure teams, application owners, cybersecurity personnel, and third-party service providers to ensure vulnerabilities are addressed in a timely and risk-informed manner. The position requires strong technical expertise, collaboration skills, and the ability to influence remediation activities without direct authority. The successful candidate will have hands-on experience with vulnerability assessment technologies, Breach and Attack Simulation (BAS) platforms, Microsoft cloud security technologies, ServiceNow workflows, and enterprise remediation programs. The individual must be capable of translating technical findings into actionable business outcomes while maintaining alignment with cybersecurity standards, regulatory obligations, and project delivery timelines.

Requirements

  • 7+ years of cyber security, vulnerability management, or security operations experience.
  • Demonstrated experience managing enterprise vulnerability remediation programs.
  • Hands-on experience with Qualys Vulnerability Management.
  • Experience with Breach and Attack Simulation (BAS) technologies.
  • Experience with Microsoft security technologies, including: Microsoft Defender, Microsoft Cloud Security Posture Management (CSPM), Azure, Azure DevOps (ADO).
  • Experience with ServiceNow workflow management and reporting.
  • Experience supporting cloud security and vulnerability management initiatives.
  • Experience working within large enterprise environments with diverse technology ecosystems.
  • Strong understanding of vulnerability prioritization methodologies and risk-based remediation approaches.
  • Knowledge of cybersecurity frameworks and industry best practices, including NIST.
  • Minimum 7 years of experience in Cyber Security, Vulnerability Management, Security Operations, Infrastructure Security, or a related discipline.
  • Demonstrated experience working with project delivery teams and enterprise technology stakeholders.
  • Experience producing executive-level metrics, dashboards, and program reporting.

Nice To Haves

  • Experience supporting utility, critical infrastructure, energy, or industrial organizations.
  • Experience leveraging threat intelligence to prioritize remediation activities.
  • Experience supporting security assessments, penetration testing, and audit remediation programs.
  • Familiarity with security operations, incident response, and defensive security technologies.
  • CISSP
  • GIAC Vulnerability Management (if held)
  • GIAC Security Essentials (GSEC)
  • GIAC Continuous Monitoring Certification (GMON)
  • Certified Information Security Manager (CISM)
  • Microsoft Security Certifications
  • Microsoft Azure Security Engineer Associate (AZ-500)
  • Qualys Certified Specialist certifications

Responsibilities

  • Support the execution and continuous improvement of the enterprise Vulnerability Management Program.
  • Assist in developing vulnerability management standards, procedures, metrics, and reporting processes.
  • Work with cybersecurity architecture and engineering teams to identify systemic security gaps and recommend remediation strategies.
  • Provide subject matter expertise to project teams throughout project lifecycles to ensure security vulnerabilities are appropriately addressed.
  • Participate in risk discussions and provide recommendations regarding remediation prioritization and compensating controls.
  • Support deployment, configuration, and optimization of vulnerability management and security assessment technologies.
  • Assist with onboarding new environments, applications, and cloud services into the vulnerability management program.
  • Support implementation and operation of Breach and Attack Simulation (BAS) capabilities to validate security controls and identify opportunities for improvement.
  • Collaborate with cloud, infrastructure, and application teams to improve security posture and vulnerability visibility.
  • Conduct vulnerability assessments across infrastructure, cloud, and application environments.
  • Analyze, validate, and prioritize vulnerabilities based on risk, exploitability, business impact, and threat intelligence.
  • Coordinate remediation activities with project teams, technical teams, managed service providers, and third-party vendors.
  • Track remediation progress and escalate high-risk issues as required.
  • Facilitate vulnerability review meetings and drive accountability for remediation commitments.
  • Utilize ServiceNow to manage workflows, remediation tracking, exception management, and reporting activities.
  • Generate operational and executive reporting that communicates vulnerability trends, risk exposure, remediation performance, and program effectiveness.
  • Support audits, assessments, penetration tests, and regulatory reviews related to cyber security controls.
  • Collaborate with Cyber Operations, Cyber Risk Management, Architecture, Infrastructure, and Application Delivery teams to ensure vulnerabilities are addressed in a manner that balances security, operational reliability, and project delivery objectives.
  • Assist in validating remediation efforts and confirming closure of identified vulnerabilities.
  • Support continuous improvement initiatives aimed at reducing organizational risk and improving security posture.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service