×
Register Here to Apply for Jobs or Post Jobs. X

Vulnerability Management Lead

Job in Washington, District of Columbia, 20022, USA
Listing for: K2United, LLC.
Full Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 130000 - 170000 USD Yearly USD 130000.00 170000.00 YEAR
Job Description & How to Apply Below

Description

K2

United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2

Share and Career Safe, we provide advisory services in cyber risk management and online education for workforce readiness.

Our four core values define how we show up every day:
  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients' mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.

Our programs make a meaningful difference. Career Safe supports more than two million users each year, while K2

Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.

Position Summary

Own enterprise vulnerability management as a sustained program function — tracking, analysis, prioritization, remediation coordination, and trend reporting across systems, applications, devices, and other in-scope assets. This position converts scan output into risk-informed decisions, drives remediation to closure with system and business stakeholders, and integrates vulnerability data into the broader risk and compliance picture.

Key Responsibilities
  • Operate vulnerability management as a sustained enterprise function: identification, documentation, prioritization, monitoring, and closure across all in-scope assets.
  • Analyze vulnerability data, scan results, remediation status, and related security findings to enable risk-based decision making.
  • Coordinate remediation with system owners and stakeholders; assist in evaluating remediation actions, timelines, and residual risk.
  • Identify aging vulnerabilities and recurring or systemic issues; recommend process improvements and risk-reduction measures.
  • Lead recurring vulnerability review meetings with applicable stakeholders to review status and support remediation planning.
  • Produce periodic reporting covering severity, age, trend, and system-level status.
  • Provide monthly vulnerability reporting and an accompanying risk mitigation plan. Escalate critical and high vulnerabilities to the client's Chief Information Officer and Chief Information Security Officer and drive remediation as rapidly as possible, with POA&Ms established and prioritized by the risks implicated.
  • Integrate vulnerability management activity into overall risk and compliance support, feeding the POA&M workflow and authorization-boundary tracking maintained by the ISSO/ISCM Lead.
  • Support risk identification, analysis, tracking, and mitigation related to vulnerabilities, control gaps, and system changes.
Requirements
  • Bachelor's degree in cybersecurity, information technology, or a related field. Equivalent experience considered in lieu of degree.
  • Six or more years in vulnerability management, including at least two years leading or coordinating an enterprise vulnerability program.
  • Hands-on proficiency with enterprise vulnerability scanning and management platforms — Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent.
  • Demonstrated ability to apply risk-based prioritization beyond raw CVSS, incorporating exploitability, the CISA Known Exploited Vulnerabilities catalog, asset criticality, and compensating controls.
  • Experience driving remediation across organizational boundaries with system owners who do not report to the vulnerability function.
  • Experience producing executive-facing vulnerability trend reporting and defensible remediation timelines aligned to federal expectations.
  • Working knowledge of POA&Ms processes and NIST vulnerability management controls.
Preferred Qualifications
  • Cloud and container vulnerability management experience — Azure and Microsoft 365, AWS, container image scanning.
  • Experience correlating vulnerability data with…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary