Cherokee Federal Logo

Cherokee Federal

Cybersecurity Vulnerability Management Lead

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead and modernize an enterprise vulnerability management program into a threat-informed exposure management capability. Manage vulnerability analysts, oversee discovery through remediation and verification, operate Tenable platforms, integrate cloud and application security findings, and improve prioritization using KEV, EPSS, threat intelligence, asset criticality, and attack path analysis. Develop ServiceNow workflows and automation with Python and PowerShell, create executive metrics, and brief technical, executive, and federal stakeholders.
The summary above was generated by AI

Cybersecurity Vulnerability Management Team Lead


Position Overview

Cherokee Federal Systems is seeking a highly experienced Cybersecurity Vulnerability Management Team Lead to support the National Science Foundation (NSF) Cybersecurity Program.

This is a highly visible role supporting a strategic modernization effort within the NSF Cybersecurity Program.

We are not seeking a traditional vulnerability manager who simply operates scanners, generates reports, and tracks POA&Ms.

We are seeking a technical leader who can help transform Vulnerability Management into a modern, threat-informed Exposure Management capability.

This individual will serve as the technical authority for Vulnerability Management, lead a small team of analysts, partner closely with Security Operations, Cloud Engineering, Infrastructure, Compliance, and Development teams, and introduce new detection, validation, and prioritization capabilities that measurably reduce organizational cyber risk.

The ideal candidate possesses a passion for innovation, continuously evaluates emerging technologies, and is capable of challenging traditional approaches to vulnerability management.

Why This Role Matters

Vulnerability Management has been identified as a key opportunity for improvement and modernization within the NSF Cybersecurity Program.

We are intentionally looking for a leader who can help evolve the program from a traditional scan-and-report model into a proactive capability focused on:

  • Exposure Reduction
  • Threat-Informed Prioritization
  • Detection Engineering
  • Continuous Validation
  • Cloud-Native Security
  • Automation
  • Actionable Executive Metrics

Candidates whose experience is primarily limited to running Nessus scans, distributing reports, or supporting annual compliance activities are unlikely to be successful in this role.

Key Responsibilities

Lead Enterprise Vulnerability Management Operations

  • Lead and mature NSF's Vulnerability Management capability across enterprise, cloud, containerized, application, and hybrid environments.
  • Provide technical leadership to a team of vulnerability analysts and establish a culture of accountability, ownership, collaboration, and continuous improvement.
  • Develop and maintain a Vulnerability Management roadmap aligned with evolving threats and organizational priorities.

Modernize Detection & Prioritization Capabilities

  • Introduce and operationalize modern vulnerability prioritization techniques utilizing:
    • CISA Known Exploited Vulnerabilities (KEV)
    • EPSS
    • Threat intelligence feeds
    • Asset criticality scoring
    • Internet-facing asset identification
    • Attack path analysis
    • MITRE ATT&CK mapping
  • Evaluate and recommend emerging technologies that improve vulnerability validation, attack surface visibility, and exposure management.

Vulnerability Lifecycle Management

  • Own end-to-end vulnerability management processes including:
    • Discovery
    • Validation
    • Prioritization
    • Remediation coordination
    • Exception handling
    • Verification
    • Executive reporting
  • Operate and optimize enterprise scanning platforms including Tenable.sc, Tenable.io, and Nessus.
  • Improve scan coverage, credential management, accuracy, and false-positive reduction.

Cloud and Application Security

  • Integrate findings from cloud-native security capabilities such as:
    • AWS Inspector
    • Security Hub
    • GuardDuty
    • Wiz
    • Prisma Cloud
    • Microsoft Defender for Cloud
  • Partner with Application Security and DevSecOps teams to support:
    • AppScan
    • DAST
    • SAST
    • CI/CD integrations
    • Container image scanning

ServiceNow and Automation

  • Mature ServiceNow Vulnerability Response capabilities including:
    • CMDB enrichment
    • Automated ticket creation
    • SLA tracking
    • Ownership assignment
    • Escalation workflows
  • Develop automation opportunities through APIs, Python, PowerShell, and orchestration capabilities.

Reporting & Leadership

  • Build executive dashboards and metrics including:
    • MTTR
    • SLA adherence
    • Vulnerability aging
    • Exposure trends
    • Scan coverage
    • Remediation effectiveness
  • Brief cybersecurity leadership on emerging risks, remediation progress, and program maturity initiatives.

Required Qualifications

  • 8+ years of cybersecurity experience.
  • 4+ years of direct Vulnerability Management experience in a federal or large enterprise environment.
  • 3+ years leading vulnerability analysts, remediation programs, or enterprise VM initiatives.
  • Deep hands-on expertise with:
    • Tenable.sc
    • Tenable.io
    • Nessus
  • Experience implementing or significantly improving a Vulnerability Management or Exposure Management capability.
  • Experience with ServiceNow Vulnerability Response and CMDB integrations.
  • Experience leveraging modern vulnerability prioritization methodologies including:
    • CISA KEV
    • EPSS
    • Threat intelligence
    • Asset criticality
    • Attack path analysis
  • Experience supporting AWS, Azure, or hybrid cloud environments.
  • Experience collaborating with Security Operations and Incident Response teams to identify and rapidly remediate actively exploited vulnerabilities.
  • Experience briefing technical teams, executives, and federal stakeholders.

Highly Desired Experience

Candidates with experience in one or more of the following areas will receive strong consideration:

  • SafeBreach
  • AttackIQ
  • Pentera
  • XM Cyber
  • Wiz
  • Prisma Cloud
  • AppScan
  • Breach and Attack Simulation (BAS)
  • Continuous Control Validation (CCV)
  • External Attack Surface Management (EASM)
  • Kubernetes Security
  • Detection Engineering

Preferred Certifications

  • CISSP
  • GCIH
  • CySA+
  • Security+
  • Tenable Certified Professional
  • AWS Security Specialty
  • ServiceNow Vulnerability Response Certification

Criterion Systems is part of Cherokee Federal—the federal contracting division of tribally owned companies owned by Cherokee Nation Businesses. As a trusted partner to more than 60 federal clients, Cherokee Federal companies are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and heart. For more information, visit cherokee-federal.com.

#CherokeeFederal #LI-SM2 #AppC2

Legal Disclaimer: Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, and Accommodation request. 

Many of our job openings require access to government buildings or military installations. Candidates must pass pre-employment qualifications of Cherokee Federal. 

Similar Jobs

Yesterday
Remote
United States
Senior level
Senior level
Information Technology • Professional Services • Defense • Manufacturing
Lead and modernize enterprise vulnerability management into a threat-informed exposure management capability. Direct a team of analysts, manage vulnerability discovery through verification, improve Tenable scanning and ServiceNow workflows, integrate cloud and application security findings, develop automation, and implement prioritization using CISA KEV, EPSS, threat intelligence, asset criticality, and attack path analysis. Produce executive metrics and brief cybersecurity leaders, technical teams, and federal stakeholders on risk and remediation progress.
Top Skills: APIsAppscanAttack Path AnalysisAttackiqAWSAws GuarddutyAws InspectorAws Security HubAzureCi/CdCisa KevCmdbContainer Image ScanningDastEpssKubernetesMicrosoft Defender For CloudMitre Att&CkNessusPenteraPowershellPrisma CloudPythonSafebreachSastServicenow Vulnerability ResponseTenable.IoTenable.ScThreat IntelligenceWizXm Cyber
47 Minutes Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
107K-144K Annually
Senior level
107K-144K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Owns sales compensation policy strategy, crediting frameworks, exception governance, audits, and field enablement. The role manages compensation policies across draws, transfers, promotions, terminations, clawbacks, renewals, overlays, splits, and non-standard deals. It partners with sales and cross-functional leaders, documents decisions, improves governance controls, and translates recurring exceptions into policy and plan changes.
Top Skills: AIBigQueryClaudeGoogle SheetsSalesforceTableauXactly
54 Minutes Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
120K-152K Annually
Senior level
120K-152K Annually
Senior level
Food • Software
Own GTM performance analytics, KPI and target setting, reporting, forecasting, compensation planning, and performance reviews across Sales and Post-Sales. Identify anomalies and optimization opportunities involving conversion, churn, productivity, pricing, packaging, segmentation, channel economics, and customer quality. Partner with Finance and GTM leaders to develop recommendations, lead strategic initiatives, and ensure data integrity while translating analysis into actionable business decisions.
Top Skills: GongHubspotOutreachSalesforceSQL

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account