Vulnerability Management

VSG Business Solutions LLC

Springfield (VA)

On-site

USD 120,000 - 160,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

AltaGas is seeking a Contractor, Vulnerability Management to support its enterprise vulnerability program. You will identify, assess, prioritize, report, and remediate vulnerabilities across IT, cloud, and digital environments, working with project teams, infrastructure groups, and third-party providers.

Key duties include deploying and optimizing BAS capabilities, coordinating remediation activities, and producing executive reports while aligning with cybersecurity standards and regulatory

Qualifications

  • 7+ years of cyber security, vulnerability management, or security operations experience.
  • Demonstrated experience managing enterprise vulnerability remediation programs.
  • Hands-on experience with Qualys Vulnerability Management.
  • Experience with Breach and Attack Simulation (BAS) technologies.
  • Experience with Microsoft security technologies, including Defender, CSPM, Azure, and ADO.
  • Experience with ServiceNow workflow management and reporting.
  • Experience supporting cloud security and vulnerability management initiatives.
  • Experience working in large enterprise environments with diverse tech ecosystems.
  • Strong understanding of vulnerability prioritization methodologies and risk-based remediation.

Responsibilities

  • Support the execution and continuous improvement of the enterprise Vulnerability Management Program.
  • Assist in developing vulnerability management standards, procedures, metrics, and reporting processes.
  • Work with cybersecurity architecture and engineering teams to identify systemic security gaps and remediation strategies.
  • Provide subject matter expertise to project teams to address vulnerabilities during lifecycles.
  • Participate in risk discussions and provide remediation prioritization recommendations.
  • Support deployment and optimization of vulnerability management tech and BAS capabilities.
  • Collaborate with cloud, infrastructure, and application teams to improve security posture and visibility.
  • Conduct vulnerability assessments across infrastructure, cloud, and apps.
  • Analyze, validate, and prioritize vulnerabilities based on risk and threat intel.
  • Coordinate remediation activities with teams, MSPs, and vendors.
  • Track remediation progress and elevate high-risk issues.
  • Utilize ServiceNow to manage workflows and reporting.
  • Generate operational and executive vulnerability trend reports.
  • Support audits, assessments, and regulatory reviews related to cyber controls.

Skills

Cybersecurity
Vulnerability management
BAS platforms
Qualys
Microsoft Defender
Azure
Azure DevOps
ServiceNow
Risk assessment
Stakeholder communication

Education

Bachelor's degree in CS/IT/CIS

Tools

Qualys
BAS
ServiceNow
Azure DevOps
Microsoft Defender
CSPM

Job description

Why the role is open: Standing up an internial AI practice.
Job Title: Contractor, Vulnerability Management
Reporting Relationship: Reports to the Practice Lead, Vulnerability Management
JOB SUMMARY

The Vulnerability Management Specialist Contractor is responsible for supporting AltaGas' enterprise vulnerability management program through the identification, assessment, prioritization, reporting, and remediation of cybersecurity vulnerabilities across corporate IT, cloud, and digital environments.
This role will work closely with project teams, infrastructure teams, application owners, cybersecurity personnel, and third-party service providers to ensure vulnerabilities are addressed in a timely and risk-informed manner. The position requires strong technical expertise, collaboration skills, and the ability to influence remediation activities without direct authority.
The successful candidate will have hands‑on experience with vulnerability assessment technologies, Breach and Attack Simulation (BAS) platforms, Microsoft cloud security technologies, ServiceNow workflows, and enterprise remediation programs. The individual must be capable of translating technical findings into actionable business outcomes while maintaining alignment with cybersecurity standards, regulatory obligations, and project delivery timelines.

PRIMARY DUTIES
Strategy & Planning

Support the execution and continuous improvement of the enterprise Vulnerability Management Program.

Assist in developing vulnerability management standards, procedures, metrics, and reporting processes.

Work with cybersecurity architecture and engineering teams to identify systemic security gaps and recommend remediation strategies.

Provide subject matter expertise to project teams throughout project lifecycles to ensure security vulnerabilities are appropriately addressed.

Participate in risk discussions and provide recommendations regarding remediation prioritization and compensating controls.

Acquisition & Deployment

Support deployment, configuration, and optimization of vulnerability management and security assessment technologies.

Assist with onboarding new environments, applications, and cloud services into the vulnerability management program.

Support implementation and operation of Breach and Attack Simulation (BAS) capabilities to validate security controls and identify opportunities for improvement.

Collaborate with cloud, infrastructure, and application teams to improve security posture and vulnerability visibility.

Operational Management

Conduct vulnerability assessments across infrastructure, cloud, and application environments.

Analyze, validate, and prioritize vulnerabilities based on risk, exploitability, business impact, and threat intelligence.

Coordinate remediation activities with project teams, technical teams, managed service providers, and third-party vendors.

Track remediation progress and elevate high-risk issues as required.

Facilitate vulnerability review meetings and drive accountability for remediation commitments.

Utilize ServiceNow to manage workflows, remediation tracking, exception management, and reporting activities.

Generate operational and executive reporting that communicates vulnerability trends, risk exposure, remediation performance, and program effectiveness.

Support audits, assessments, penetration tests, and regulatory reviews related to cyber security controls.

Collaborate with Cyber Operations, Cyber Risk Management, Architecture, Infrastructure, and Application Delivery teams to ensure vulnerabilities are addressed in a manner that balances security, operational reliability, and project delivery objectives.

Assist in validating remediation efforts and confirming closure of identified vulnerabilities.

Support continuous improvement initiatives aimed at reducing organizational risk and improving security posture.

QUALIFICATIONS, SKILLS & ABILITIES
Technical Attributes
Required Experience

7+ years of cyber security, vulnerability management, or security operations experience.

Demonstrated experience managing enterprise vulnerability remediation programs.

Hands‑on experience with Qualys Vulnerability Management.

Experience with Breach and Attack Simulation (BAS) technologies.

Experience with Microsoft security technologies, including:

Microsoft Defender

Microsoft Cloud Security Posture Management (CSPM)

Azure

Azure DevOps (ADO)

Experience with ServiceNow workflow management and reporting.

Experience supporting cloud security and vulnerability management initiatives.

Experience working within large enterprise environments with diverse technology ecosystems.

Strong understanding of vulnerability prioritization methodologies and risk-based remediation approaches.

Knowledge of cybersecurity frameworks and industry best practices, including NIST.

Preferred Experience

Experience supporting utility, critical infrastructure, energy, or industrial organizations.

Experience leveraging threat intelligence to prioritize remediation activities.

Experience supporting security assessments, penetration testing, and audit remediation programs.

Familiarity with security operations, incident response, and defensive security technologies.

Personal Attributes

Strong relationship‑building and stakeholder engagement skills.

Ability to work collaboratively with business, technical, and third‑party teams.

Capable of influencing and driving remediation activities without direct authority.

Strong analytical and problem‑solving abilities.

Excellent verbal, written, and presentation skills.

Ability to communicate technical security issues in business‑friendly language.

Strong organizational skills with the ability to manage multiple priorities simultaneously.

Highly self‑motivated with strong attention to detail.

Team‑oriented and committed to supporting enterprise objectives while maintaining security requirements.

EDUCATION

Bachelor's degree in Computer Science, Information Technology, Cyber Security, Engineering, or a related field preferred.

Equivalent combination of education and relevant professional experience will be considered.

WORK EXPERIENCE

Minimum 7 years of experience in Cyber Security, Vulnerability Management, Security Operations, Infrastructure Security, or a related discipline.

Demonstrated experience working with project delivery teams and enterprise technology stakeholders.

Experience producing executive‑level metrics, dashboards, and program reporting.

CERTIFICATIONS (Preferred)

One or more of the following:

CISSP

GIAC Vulnerability Management (if held)

GIAC Security Essentials (GSEC)

GIAC Continuous Monitoring Certification (GMON)

Certified Information Security Manager (CISM)

Microsoft Security Certifications

Microsoft Azure Security Engineer Associate (AZ-500)

Qualys Certified Specialist certifications

Desired Candidate Profile

The ideal candidate is a hands‑on vulnerability management practitioner who can bridge the gap between cybersecurity requirements and project delivery. They are comfortable engaging with technical teams, project managers, vendors, and leaders to drive remediation efforts, improve security posture, provide meaningful reporting, and ensure vulnerabilities are addressed without unnecessarily impacting business objectives.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Info Security Analyst for Vulnerability Remediation - locals only
Info Security Analyst for Vulnerability Remediation - locals only

Value Innovation Labs • San Antonio (TX)

On-site
USD 90,000 - 120,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Vulnerability management Consultant
Vulnerability management Consultant

Tata Consultancy Services • Charlotte (NC)

On-site
USD 110,000 - 150,000
Discretionary Annual Incentive
Medical Coverage
Parental Leaves
+2
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Compunnel, Inc. • Irving (TX)

On-site
USD 100,000 - 130,000
Vulnerability Engineer
Vulnerability Engineer

CBTS • United States

On-site
USD 80,000 - 85,000
Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

Community Health Systems • United States

On-site
USD 120,000 - 150,000
Data Privacy and Compliance Analyst
Data Privacy and Compliance Analyst

Comtech LLC • Atlanta (GA)

On-site
USD 80,000 - 100,000
Vulnerability Management Technical Lead
Vulnerability Management Technical Lead

Jobtailor • San Francisco (CA)

On-site
USD 180,000 - 230,000
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000