Vulnerability Management Engineer
Listed on 2026-09-08
-
IT/Tech
Cybersecurity -
Engineering
Cybersecurity
Job Title:
Vulnerability Management Engineer
Job Category:
Security
Time Type:
Full time
Minimum Clearance Required to Start:
None
Employee Type:
Regular
Percentage of
Travel Required:
None
Type of Travel:
None
* * *
The Opportunity:CACI is searching for a Vulnerability Management Engineer to support the FEMA Office of the Chief Information Security Officer (OCISO) in Washington, D.C. As a Vulnerability Management Engineer, you will play a crucial role in ensuring the security and resilience of FEMA’s information systems through comprehensive vulnerability identification, assessment, and remediation coordination. You will work in a dynamic environment, collaborating with system owners, cybersecurity professionals, and enterprise administrators to identify and eliminate security vulnerabilities.
Your efforts will directly contribute to safeguarding FEMA’s mission-critical systems and data. The Vulnerability Management Engineer will be responsible for leading vulnerability identification, prioritization, remediation coordination, and closure validation across the environment and assigned systems. This position requires administering scanning processes across FEMA systems and analyzing vulnerability findings for risk and accuracy. The Vulnerability Management Engineer will monitor all FEMA systems Remediation Work Plans (RWPs), coordinate remediation efforts across Enterprise systems, and provide daily technical remediation support services.
This role is critical for producing dashboards and surge reporting for critical vulnerabilities and ensuring remediation validation.
The Vulnerability Management Engineer will administer scanning processes across FEMA systems and analyze vulnerability findings for risk and accuracy while monitoring all FEMA systems Remediation Work Plans (RWPs). This position requires coordinating remediation efforts across Enterprise systems, providing daily technical remediation support services, and supporting all remediation activities in a detailed, technical, and audit manner. The Vulnerability Management Engineer will ensure remediation validation and produce dashboards and surge reporting for critical vulnerabilities, as well as provide vulnerability reduction reports and trend analysis reports.
Responsibilities include analyzing vulnerability reports and remediation efforts and reporting to leadership as required, conducting monthly POA&M remediation test events, and developing test reports within 5 days after testing. The position involves validating closure of vulnerabilities and providing monthly compliance remediation briefs while utilizing automated security authorization tools for managing remediation efforts and managing POA&M's using automated tools. The Vulnerability Management Engineer will support internal and external audit events, track and suggest technologies, processes, and practices designed to protect networks, devices, programs, and data from malicious attack, damage, or unauthorized access, and research and maintain proficiency in tools, techniques, countermeasures, and trends in computer and network vulnerabilities, data hiding, and network and device security and encryption.
Required:
- - U.S. Citizenship required
- - FEMA EOD suitability or Current DHS or FEMA EOD preferred
- - BS/BA + 6 years of applicable experience in vulnerability management and cybersecurity
- - Demonstrated expertise with Qualys
- - Experience with other vulnerability scanning tools (db Protect, Web inspect, or Tenable)
- - Experience with automated security authorization tools
- - Knowledge of vulnerability assessment methodologies and risk analysis
- - Strong analytical skills for vulnerability prioritization and trend analysis
Desired:
- - Active Secret security clearance
- - Previous DHS or DoD experience
- - Experience with managing and administering automated scanning tools
- - Knowledge of DISA STIGs and security compliance frameworks
- - Experience with dashboard and reporting tools (Tableau, Power BI, Splunk)
- - Experience supporting audit activities
A culture of integrity.
At CACI, we place character and innovation at the center of everything we do. As a valued…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).