1. Vulnerability Management Lead vulnerability management operations, ensuring alignment with BOD 22-01 and federal cybersecurity mandates. Manage, monitor, and report vulnerabilities across NIH/HHS systems using tools such as Tenable.sc / Tenable.io, and coordinate timely remediation activities. Develop vulnerability prioritization models based on risk, exposure, and asset criticality. Ensure compliance with patching timelines and federal vulnerability directives. Collaborate with infrastructure, cloud, and application teams to validate remediation actions. 2. Security Operations & Automation Enhance and maintain SecOps workflows through automation and dashboard development. Utilize Power BI, Python, and Power Automate (or similar tools) to automate reporting, trend analysis, and compliance tracking. Develop API integrations with vulnerability management tools (e.g., Tenable, Splunk, ServiceNow, or CSAM) for real-time monitoring dashboards. Support automation of vulnerability data ingestion and normalization across multiple environments (cloud and on-premises). 3. Compliance & Policy Alignment Ensure continuous compliance with CISA's Binding Operational Directive (BOD) 22-01, NIST SP 800-53, and FISMA requirements. Work closely with Risk Management Framework (RMF) and SA&A teams to align vulnerability findings with system security plans (SSPs), POA&Ms, and ATO documentation. Support preparation of reports for leadership and federal oversight bodies. 4. Reporting & Dashboards Build and maintain interactive Power BI dashboards that visualize vulnerabilities, risk posture, remediation progress, and compliance trends. Translate technical findings into executive-level risk summaries. Develop KPI and SLA metrics for vulnerability closure rates, asset risk scoring, and compliance tracking. 5. Communication & Coordination Communicate complex technical information clearly to both technical and non-technical audiences. Collaborate with cross-functional teams (IT Operations, Cloud Engineering, Privacy, and Compliance). Provide status briefings and vulnerability insights to leadership.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Industry
Professional, Scientific, and Technical Services
Education Level
No Education Listed
Number of Employees
5,001-10,000 employees