Vulnerability and Audit Remediation Specialist (Henrico)

Virginia Information Technologies AgencyHenrico, Virginia, VA
$90,000 - $110,000Onsite

About The Position

The Virginia Employment Commission (VEC) is seeking a Vulnerability and Audit Remediation Specialist who will lead the agency’s efforts to identify, prioritize, and resolve security vulnerabilities while coordinating the closure of technical audit findings that reduce operational and security risk. In this role, you will analyze vulnerability scan results, collaborate with system owners and technical teams to implement patches and mitigation strategies, track and validate remediation activities, and ensure timely closure of findings in alignment with compliance requirements. You will also serve as the central point of coordination for audit findings, translate technical and regulatory requirements into actionable tasks, maintain a comprehensive remediation register, support evidence collection for audits, and partner across IT, security, compliance, and development teams to drive effective risk reduction. This position plays a critical role in strengthening the agency’s security posture and supporting governance efforts that protect systems, data, and mission operations. Join the VEC and be part of a mission-driven agency dedicated to supporting workers, strengthening communities, and promoting economic stability across the Commonwealth. We administer Virginia’s Unemployment Insurance (UI) benefits program with a commitment to providing customer-centered, accessible, inclusive, and impactful services to support our shared mission: lifting up Virginia, one unemployed worker at a time. The VEC is also an integral part of a historic milestone as Virginia becomes the first state in the South to offer Paid Family and Medical Leave (PFML). Our agency will be responsible for standing up and administering this new program, which will expand the vital support we provide for employees when they need it most.

Requirements

  • Strong understanding of operating systems (Windows, Linux), networks, and application architectures.
  • Experience with vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7, Nucleus).
  • Knowledge of patch management processes and secure configuration standards (CIS, NIST).
  • Ability to analyze and resolve vulnerabilities under tight deadlines.
  • Strong attention to detail and ability to identify subtle or complex vulnerabilities.
  • Excellent organizational skills with the ability to manage multiple remediation streams simultaneously.
  • Ability to interpret audit findings and translate them into actionable tasks.
  • Strong problem‑solving skills and the ability to work independently.
  • Ability to work effectively across IT, security, compliance, and development teams.
  • Clear written and verbal communication skills.
  • Ability to present technical information to nontechnical audiences.
  • Strong relationship building skills and the ability to influence without authority.
  • A valid Virginia Driver's License is required to operate a state vehicle or if operating a personal vehicle while conducting business on behalf of the agency.

Nice To Haves

  • Familiarity with cloud environments (Azure, AWS) and containerized workloads
  • Demonstrated experience with vulnerability management, security operations, audit coordination, or system administration.
  • Experience supporting internal or external audits (SOC 2, PCI‑DSS, IRS, HIPAA, NIST).
  • Experience with ITSM tools for tracking remediation tasks.
  • Understanding of risk management and governance frameworks.

Responsibilities

  • Analyze vulnerability scan results
  • Collaborate with system owners and technical teams to implement patches and mitigation strategies
  • Track and validate remediation activities
  • Ensure timely closure of findings in alignment with compliance requirements
  • Serve as the central point of coordination for audit findings
  • Translate technical and regulatory requirements into actionable tasks
  • Maintain a comprehensive remediation register
  • Support evidence collection for audits
  • Partner across IT, security, compliance, and development teams to drive effective risk reduction

Benefits

  • Paid leave
  • A minimum of 13 paid state holidays per year
  • Medical, dental, vision, and life insurance options
  • Retirement plans (including 401a Cash Match and 457 Deferred Compensation Plan for classified positions)
  • Federally recognized Public Service Loan Forgiveness (PSLF) employer
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service