CybersecurityJobs.io
← Back to all jobs

Job Description

Cherokee Federal is seeking a Cybersecurity Vulnerability Management Team Lead to support the NSF Cybersecurity Program. This onsite role in Almont, CO provides technical authority to modernize vulnerability management into a threat-informed exposure management capability and to lead enterprise vulnerability operations.

Key Responsibilities

  • Lead and mature NSF’s vulnerability management capability across enterprise, cloud, containerized, application, and hybrid environments.
  • Provide technical leadership to a team of vulnerability analysts and establish a culture of accountability, ownership, collaboration, and continuous improvement.
  • Develop and maintain a vulnerability management roadmap aligned with evolving threats and organizational priorities.
  • Operationalize modern vulnerability prioritization techniques using CISA Known Exploited Vulnerabilities (KEV), EPSS, threat intelligence feeds, asset criticality scoring, internet-facing asset identification, attack path analysis, and MITRE ATT&CK mapping.
  • Evaluate and recommend emerging technologies to improve vulnerability validation, attack surface visibility, and exposure management.
  • Own end-to-end vulnerability management processes: Discovery, Validation, Prioritization, Remediation coordination, Exception handling, Verification, and Executive reporting.
  • Operate and optimize enterprise scanning platforms, including Tenable.sc, Tenable.io, and Nessus.
  • Improve scan coverage, credential management, accuracy, and false-positive reduction.
  • Integrate findings from cloud-native security capabilities: AWS Inspector, Security Hub, GuardDuty, Wiz, Prisma Cloud, and Microsoft Defender for Cloud.
  • Partner with Application Security and DevSecOps teams to support AppScan, DAST, SAST, CI/CD integrations, and container image scanning.
  • Mature ServiceNow Vulnerability Response capabilities, including CMDB enrichment, automated ticket creation, SLA tracking, ownership assignment, and escalation workflows.
  • Develop automation opportunities using APIs, Python, PowerShell, and orchestration capabilities.
  • Build executive dashboards and metrics including MTTR, SLA adherence, vulnerability aging, exposure trends, scan coverage, and remediation effectiveness.
  • Brief cybersecurity leadership on emerging risks, remediation progress, and program maturity initiatives.

Required Qualifications

  • 8+ years of cybersecurity experience.
  • 4+ years of direct vulnerability management experience in a federal or large enterprise environment.
  • 3+ years leading vulnerability analysts, remediation programs, or enterprise VM initiatives.
  • Deep hands-on expertise with Tenable.sc, Tenable.io, and Nessus.
  • Experience implementing or significantly improving a vulnerability management or exposure management capability.
  • Experience with ServiceNow Vulnerability Response and CMDB integrations.
  • Experience applying modern vulnerability prioritization methodologies including CISA KEV, EPSS, threat intelligence, asset criticality, and attack path analysis.
  • Experience supporting AWS, Azure, or hybrid cloud environments.
  • Experience collaborating with Security Operations and Incident Response teams to identify and rapidly remediate actively exploited vulnerabilities.
  • Experience briefing technical teams, executives, and federal stakeholders.

Technologies

  • Tenable.sc, Tenable.io, Nessus
  • CISA Known Exploited Vulnerabilities (KEV), EPSS, Threat intelligence feeds, MITRE ATT&CK
  • AWS Inspector, Security Hub, GuardDuty, Wiz, Prisma Cloud, Microsoft Defender for Cloud
  • AppScan, DAST, SAST, CI/CD integrations, Container image scanning
  • ServiceNow Vulnerability Response, CMDB enrichment, APIs, Python, PowerShell, orchestration capabilities
  • ServiceNow Vulnerability Response and CMDB integrations

Highly Desired Experience

  • SafeBreach
  • AttackIQ
  • Pentera
  • XM Cyber
  • Wiz
  • Prisma Cloud
  • AppScan
  • Breach and Attack Simulation (BAS)
  • Continuous Control Validation (CCV)
  • External Attack Surface Management (EASM)
  • Kubernetes Security
  • Detection Engineering

Preferred Certifications

  • CISSP
  • GCIH
  • CySA+
  • Security+
  • Tenable Certified Professional
  • AWS Security Specialty
  • ServiceNow Vulnerability Response Certification

Similar Jobs