Jobs and Careers
VA

Vulnerability Management Lead

Valiant Solutions
Washington, United Statesfull_timeVerifiedPosted 17 Jun 2026

About the role

Position Description

Valiant Solutions is seeking a Vulnerability Management Lead to join our rapidly growing and innovative cybersecurity team!

 

The Vulnerability Management Lead directs client's vulnerability management program across the Continuous Diagnostics and Mitigation (CDM), Web Application Surveillance Program (WASP), and Cyber Hygiene workstreams within the Cybersecurity Services Division. The lead owns the end-to-end process from discovery and scanning through remediation tracking and Plan of Action and Milestones (POA&M) closure, working across Information System Owners (ISOs), Information System Security Officers (ISSOs), the Policy, Risk & Compliance branch, and engineering teams. The role produces the dashboards, metrics, and reporting that give client leadership a current view of agency risk and progress against remediation targets.

 

Named one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!

 

Location: The Vulnerability Management Lead can expect 100% telework. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below. 

 

Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, along with the ability to successfully pass a federal background investigation.

 

Required Experience:

  • Six or more years of cybersecurity experience, including hands-on work with operating systems (Windows, Linux) and networking (TCP/IP, routing, firewalls, segmentation).
  • At least one of the following certifications: GCIH, CISSP, CISM, or CRISC.
  • Hands-on experience with Tenable (Tenable ONE, Nessus, or Tenable.io), AquaSec, and CDM integration in a federal or large enterprise environment.
  • Working knowledge of DHS CDM Program requirements, NIST SP 800-137 (Information Security Continuous Monitoring), NIST SP 800-53 controls (in particular RA-5 and SA-11), DHS BOD 18-01, and CISA Cyber Hygiene Services.
  • Experience supporting POA&M development, remediation tracking, and closure within Cyber Security Assessment and Management (CSAM) or a comparable governance, risk, and compliance system.
  • Demonstrated ability to build dashboards and metrics that translate scan output into prioritized, executable remediation work for technical and executive audiences.
  • Strong written and verbal communication skills, with the ability to coordinate across ISOs, ISSOs, compliance, and engineering stakeholders.
  • Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance, Tier 4/6c.

 

Preferred Qualifications:

  • Experience with AWS GovCloud and cloud-native vulnerability scanning, including container image and Infrastructure-as-Code (IaC) assessment.
  • Familiarity with CI/CD pipeline security controls and policy-as-code enforcement.
  • Experience integrating vulnerability data with SIEM and ticketing platforms such as ServiceNow.
  • Familiarity with the client Technology Standards and Products Guide and client Lifecycle Management Methodology (LMM).

 

Responsibilities:

  • Oversee enterprise vulnerability scanning across infrastructure, web applications, containers, and cloud workloads using Tenable ONE, AquaSec, and integrated CDM tooling.
  • Direct remediation tracking from finding to closure, including communication and coordination with POA&M support within the Policy, Risk & Compliance branch.
  • Coordinate with ISOs, ISSOs, compliance teams, and engineering teams to triage findings, assign ownership, and close gaps within agency and federal timelines.
  • Lead Cyber Hygiene activities, including weekly scans of internet-facing interfaces and URLs, review of CISA Cyber Hygiene reports, and distribution of issue reports to ISSOs within two business days of receipt.
  • Maintain the authoritative inventory of externally facing IPs and URLs, updated in real time and reconciled monthly.
  • Monitor digital certificate expiration, generate alerts 30 days prior to expiration, and escalate unresolved items within 10 days.
  • Lead WASP activities, including static and dynamic scans of client web applications in development and production environments, vendor plugin updates, and integration of CISA Known Exploited Vulnerabilities (KEVs) into scan coverage.
  • Deliver threat modeling analysis for critical applications and ensure W

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Valiant Solutions

View company profile →