More jobs:
Vulnerability Management Lead, Top Secret
Job in
Herndon, Fairfax County, Virginia, 22070, USA
Listed on 2026-06-21
Listing for:
General Dynamics - IT
Full Time
position Listed on 2026-06-21
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Position Summary
The Vulnerability Management Lead oversees teams that deliver comprehensive, standards‑aligned security assessments and validation services across cloud, operational technology (OT), industrial control systems (ICS), and enterprise environments. The role identifies vulnerabilities, evaluates control effectiveness, and measures readiness to strengthen the cybersecurity posture of government and commercial information systems. The successful lead directs tailored test plans (e.g., vulnerability assessments, penetration testing, SOC evaluations, phishing exercises), ensures actionable findings, and prioritized mitigation guidance.
Key Responsibilities- Assessment & Security Validation Leadership
:
Oversee teams conducting site‑based and remote assessments for vulnerability management, compliance validation, and ad‑hoc inspection needs. Ensure detailed assessments of technical and non‑technical controls are aligned to NIST frameworks, Federal guidance, and Cyber Performance Goals. Direct tailored test plans, oversee assessments of performance using red‑, blue‑, and purple‑team methodologies, manage automated system and web‑application scanning, phishing assessments, and develop customized plugin policies.
Enforce clear operational oversight practices—including weekly status reports, daily assessment updates, formal kickoffs, and structured out‑briefs. - Remediation Orchestration & Risk Reduction
:
Oversee end‑to‑end management of assessment findings—advising system owners on corrective actions and ensuring vulnerabilities are prioritized, fixed, mitigated, or appropriately risk‑accepted. Direct the delivery of automated remediation tracking, trend analysis, and documented mitigation strategies. Ensure machine‑readable assessment outputs aligned with CISA‑standard tools, techniques, and procedures. Leverage AI/ML‑enabled vulnerability discovery, risk scoring models, AI‑assisted analytics, automated reasoning, NLP technologies, and AI‑powered attack simulation to support prioritization and early warning indicators.
Guide adoption of ML‑assisted configuration baselining and drift detection while promoting responsible use of AI/ML in vulnerability management. - Threat Emulation & Simulation Operations
:
Oversee teams emulating and simulating real‑world threat actors in live and synthetic environments. Ensure creation and operation of realistic, secure, and rapidly reconfigurable emulated network environments for cyber‑range experimentation. Direct reproduction of adversary behaviors in test environments to improve detection and prevention. Oversee red‑ and blue‑team exercises using realistic tools, malware, and tradecraft. Employ ML‑based behavior modeling engines, AI‑assisted cyber range orchestration tools, AI/ML analytics, and autonomous red‑team augmentation tools.
Incorporate AI‑powered anomaly detection systems into blue‑team exercises and transform telemetry into machine‑readable threat intelligence artifacts. - Governance, Reporting & Continuous Improvement
:
Maintain continuous communication with system owners and stakeholders. Recommend innovative processes and technologies that modernize assessment efficiency and accuracy. Drive analytic rigor by producing custom testing artifacts and enhancing tooling/processes. Implement AI‑enabled reporting workflows that automatically transform assessment data into dashboards, executive summaries, and audit‑ready artifacts aligned with federal and CISA reporting standards. Employ NLP tools to analyze narratives, find trends, and identify opportunities for standardization or process optimization.
Use AI‑assisted governance tools to predict remediation timelines, estimate risk reduction outcomes, and support priority decisions. Continuously evaluate effectiveness of assessment methodologies and recommend evidence‑based improvements. Ensure responsible, transparent, and auditable use of AI/ML technologies within governance and reporting workflows.
- 10 years of overall cybersecurity experience with 5 years of management of cybersecurity teams.
- Experience overseeing vulnerability management programs and security assessments (cloud,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×