Cybersecurity Vulnerability Management Lead
Listed on 2026-08-22
-
IT/Tech
Cybersecurity
- CMDB enrichment
- Threat intelligence
Position Overview
Cherokee Federal Systems is seeking a highly experienced Cybersecurity Vulnerability Management Team Lead to support the National Science Foundation (NSF) Cybersecurity Program.
This is a highly visible role supporting a strategic modernization effort within the NSF Cybersecurity Program.
We are not seeking a traditional vulnerability manager who simply operates scanners, generates reports, and tracks POA&Ms.
We are seeking a technical leader who can help transform Vulnerability Management into a modern, threat-informed Exposure Management capability.
This individual will serve as the technical authority for Vulnerability Management, lead a small team of analysts, partner closely with Security Operations, Cloud Engineering, Infrastructure, Compliance, and Development teams, and introduce new detection, validation, and prioritization capabilities that measurably reduce organizational cyber risk.
The ideal candidate possesses a passion for innovation, continuously evaluates emerging technologies, and is capable of challenging traditional approaches to vulnerability management.
Why This Role MattersVulnerability Management has been identified as a key opportunity for improvement and modernization within the NSF Cybersecurity Program.
We Are Intentionally Looking For a Leader Who Can Help Evolve The Program From a Traditional Scan-and-report Model Into a Proactive Capability Focused On
- Exposure Reduction
- Threat-Informed Prioritization
- Detection Engineering
- Continuous Validation
- Cloud-Native Security
- Automation
- Actionable Executive Metrics
Candidates whose experience is primarily limited to running Nessus scans, distributing reports, or supporting annual compliance activities are unlikely to be successful in this role.
Key Responsibilities Lead Enterprise Vulnerability Management Operations- Lead and mature NSF's Vulnerability Management capability across enterprise, cloud, containerized, application, and hybrid environments.
- Provide technical leadership to a team of vulnerability analysts and establish a culture of accountability, ownership, collaboration, and continuous improvement.
- Develop and maintain a Vulnerability Management roadmap aligned with evolving threats and organizational priorities.
- Introduce and operationalize modern vulnerability prioritization techniques utilizing:
- CISA Known Exploited Vulnerabilities (KEV)
- EPSS
- Threat intelligence feeds
- Asset criticality scoring
- Internet-facing asset identification
- Attack path analysis
- MITRE ATT&CK mapping
- Evaluate and recommend emerging technologies that improve vulnerability validation, attack surface visibility, and exposure management.
- Own end-to-end vulnerability management processes including:
- Discovery
- Validation
- Prioritization
- Remediation coordination
- Exception handling
- Verification
- Executive reporting
- Operate and optimize enterprise scanning platforms including Tenable.sc, Tenable.io, and Nessus.
- Improve scan coverage, credential management, accuracy, and false-positive reduction.
- Integrate findings from cloud-native security capabilities such as:
- AWS Inspector
- Security Hub
- Guard Duty
- Wiz
- Prisma Cloud
- Microsoft Defender for Cloud
- Partner with Application Security and Dev Sec Ops teams to support:
- App Scan
- DAST
- SAST
- CI/CD integrations
- Container image scanning
- Mature Service Now Vulnerability Response capabilities including:
- CMDB enrichment
- Automated ticket creation
- SLA tracking
- Ownership assignment
- Escalation workflows
- Develop automation opportunities through APIs, Python, Power Shell, and orchestration capabilities.
- Build executive dashboards and metrics including:
- MTTR
- SLA adherence
- Vulnerability aging
- Exposure trends
- Scan coverage
- Remediation effectiveness
- Brief cybersecurity leadership on emerging risks, remediation progress, and program maturity initiatives.
- 8+ years of cybersecurity experience.
- 4+ years of direct Vulnerability Management experience in a federal or large enterprise environment.
- 3+ years leading…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).