Vulnerability Management Lead
Maseru, Lesotho · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 jam yang lalu
- Work mode
- In office
- Education
- Bachelor’s degree in Cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About True Zero Technologies
True Zero Technologies is a veteran-owned small business committed to empowering people and technology to achieve excellent outcomes. The organization prioritizes its workforce, fostering a community of passionate innovators dedicated to delivering superior services. Recognized as one of the Best Places to Work in 2023 and 2025, and a multiple-time Inc. 5000 honoree, True Zero exemplifies growth and excellence through a people-first approach.
Role Overview
The Vulnerability Management Lead will oversee enterprise vulnerability management and Continuous Diagnostics and Mitigation (CDM) initiatives for the National Institutes of Health (NIH). This role manages the operational vulnerability program across a complex enterprise, ensuring rapid identification, precise prioritization, effective communication, and successful remediation of vulnerabilities.
Key Responsibilities
- Lead and manage the enterprise-wide Vulnerability Management and CDM program.
- Coordinate vulnerability scanning activities across infrastructure, cloud environments, endpoints, network devices, and applications.
- Develop prioritization strategies considering exploitability, mission impact, Known Exploited Vulnerabilities (KEVs), threat intelligence, and operational context.
- Oversee remediation processes by collaborating with system owners, engineering teams, and ISSOs to mitigate cyber risks.
- Track remediation progress, validate corrective measures, and ensure accurate tracking through POA&M and RMF frameworks.
- Conduct regular vulnerability review meetings and communicate priorities to Government stakeholders.
- Create executive-level metrics, dashboards, and reports illustrating vulnerability posture, remediation status, and risk trends.
- Work closely with penetration testing teams to verify exploitable attack paths and confirm remediation efficacy.
- Collaborate with incident response and threat intelligence units to quickly re-evaluate vulnerabilities amid emerging threats.
- Integrate vulnerability data within enterprise cybersecurity reporting and support continuous monitoring activities.
- Recommend and implement enhancements to vulnerability management processes, automation, workflows, and security tools.
- Ensure compliance with Federal cybersecurity requirements, including CISA Binding Operational Directives and NIH guidance.
Qualifications
- Bachelor’s degree in Cybersecurity, IT, Computer Science, Information Systems, or a related field.
- At least five years’ experience leading enterprise vulnerability management or cybersecurity operations programs.
- Proficiency managing enterprise vulnerability scanning platforms and coordinating remediation across extensive distributed environments.
- Thorough knowledge of vulnerability management methods, CVSS, KEVs, threat intelligence, and attack surface principles.
- Experience with Federal cybersecurity programs under FISMA and NIST RMF.
- Capability in producing executive reporting, operational dashboards, and cybersecurity performance metrics.
- Strong leadership, communication, and stakeholder engagement skills.
Preferred Qualifications
- Experience with NIH, HHS, or Federal civilian agencies.
- Hands-on knowledge of vulnerability management platforms like Tenable, Qualys, or Rapid7.
- Familiarity with Continuous Diagnostics and Mitigation (CDM) programs.
- Integration experience with RMF, POA&M management, and continuous monitoring.
- Understanding of cloud security, Zero Trust frameworks, and enterprise security engineering.
- Background supporting penetration testing and remediation validation.
Preferred Certifications
- CISSP
- GIAC Certified Vulnerability Assessor (GCVA)
- CompTIA CySA+
- GIAC Continuous Monitoring Certification (GMON)
- Certified in Governance, Risk and Compliance (CGRC)
- Security+
- Certified Ethical Hacker (CEH)
Employee Benefits
- Competitive salary paid bi-monthly.
- Premium medical coverage fully paid by True Zero.
- Company-wide new business incentives.
- Contribution rewards for white papers, blogs, and internal webinars.
- Three weeks of paid time off plus 11 paid holidays annually.
- 401k plan with full company match on the first 4% contribution.
- Monthly reimbursements for cell phone and home internet expenses.
- Paternity and maternity leave benefits.
- Support for training and certifications to enhance technical expertise.
Additional Information
True Zero may utilize artificial intelligence tools during parts of the recruiting process to assist in reviewing applications and resumes, as well as evaluating responses to identify discrepancies or verification indicators. While AI supports this process, final hiring decisions are made by human recruiters. For inquiries about data processing, applicants may request further details.
Minimum education
Bachelor's Degree