CybersecurityJobs.io
← Back to all jobs

Job Description

August Schell is seeking an IT Vulnerability Management Lead / Senior Security Analyst to drive the vulnerability management lifecycle for NLM IT programs and help ensure ongoing compliance with federal security requirements. This onsite role in Bethesda, MD coordinates closely with the NLM ISSO and NIH teams in a hybrid operating environment.

What you’ll do

  • Lead the agency’s vulnerability management lifecycle using Tenable.sc, Tenable.io, Nessus Manager, and Nessus scanners across on-prem and cloud environments.
  • Analyze, prioritize, and track vulnerability remediation efforts in coordination with IT operations and system owners.
  • Maintain scan schedules and asset groups, manage scan policies, dashboards, repositories, and reporting tailored to agency infrastructure.
  • Communicate risk posture and remediation progress to relevant infrastructure and application teams to support timely fixes.
  • Define scanner and security center architecture, refine data flows, and tune scanning configurations to minimize false positives while maximizing coverage.
  • Develop and maintain documentation covering system setup, operational procedures, vulnerability management processes, exceptions, and remediation tracking.
  • Support security projects that require alignment with applicable government policies or standards.
  • Serve as the SME for vulnerability management tools and processes, including updating and monitoring workflows to meet NIH mandates.
  • Ensure NLM IT systems and practices comply with FISMA and FedRAMP related Security Assessment and Authorization (SA&A) requirements.
  • Assist NLM with coordination, implementation, communication, and enforcement of NIH IT security policies.
  • Support NLM’s incident response workflow and coordinate with NIH teams.

Qualifications

  • 5+ years of IT security experience, including at least 3 years focused on vulnerability management and related platforms.
  • Expert knowledge of IT security vulnerabilities and risk assessments, with the ability to translate complex technical risk into actionable impacts for executive and technical audiences.
  • Strong knowledge of the vulnerability management lifecycle, patch management processes, and risk scoring models such as CVSS2 in a federal environment.
  • Familiarity with securing AWS and GCP cloud platforms and hybrid environments.
  • Understanding of hardening for Windows, Linux/Unix, and network devices.
  • Ability to work across program staff, executives, security application vendors, and technology teams to meet IT security goals.
  • Demonstrated experience administering enterprise-class vulnerability management platforms (for example, Tenable/Nessus) to support accurate discovery, repository management, scanning, and reporting.
  • Excellent experience applying FISMA and FedRAMP processes and policies, including maintaining Assessment and Authorization documentation for large federal systems.
  • Skilled at bridging technical, security, and business stakeholders, including aligning program staff, executives, technology teams, and external security vendors.
  • Bachelor’s degree in computer science, cybersecurity, information technology, or a related technical field (or equivalent practical experience).
  • CISSP certification (or ability to obtain within 6 months).

Technologies you’ll work with

  • Tenable.sc, Tenable.io, Nessus Manager, Nessus
  • AWS, GCP
  • Windows, Linux/Unix
  • Python, PowerShell
  • CVSS2, CISSP
  • FISMA, FedRAMP, Security Assessment and Authorization (SA&A)
  • NIH

Additional desired qualifications

  • Experience with scripting and automation (for example, Python and PowerShell) to automate scanning tasks, reporting, and API integrations; administration and operation of Nessus-based vulnerability management platforms.
  • Deep expertise integrating vulnerability data into enterprise monitoring and working with SIEM platforms.
  • Understanding of the Secure Software Development Life Cycle.
  • Master’s degree or additional security or cloud certifications (for example, CISM).

Role details

  • Location: Bethesda, MD (Onsite, 3–5 days per week)
  • Employment type: Full-time

Similar Jobs