Vulnerability Manager Lead

Darkwolfsolutions

Herndon (VA)

Hybrid

USD 155,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dark Wolf is seeking a Vulnerability Management Lead to guide end-to-end vulnerability lifecycle across a large-scale cloud government system. You will work with cross-functional teams to detect, triage, and remediate vulnerabilities in AWS, hybrid, and AI/LLM stacks.

This leadership role emphasizes risk-based decision making and performance reporting. Ideal candidates have 6+ years in federal vulnerability management, ACAS experience, and DoD IAT II certification with a Top Secret clearance.

Qualifications

  • 6+ years of experience in Cybersecurity, Vulnerability Management, or Systems Administration supporting federal or DoD information systems.
  • Direct, hands‑on experience utilizing ACAS (Tenable.sc) to filter, analyze, and report on enterprise vulnerabilities.
  • Operational understanding of the Security Content Automation Protocol (SCAP) ecosystem and how automated configuration audit files translate into compliance metrics.
  • Understanding of Splunk Enterprise Security and Trellix (ESS) correlation with vulnerability monitoring.
  • Practical experience writing SQL queries for reporting and analytics.
  • Proficiency using Jira to track and manage technical workflows.
  • Strong communication skills for translating vulnerabilities to remediation steps.
  • Solid understanding of AWS services (EC2, VPC, Security Groups, IAM).
  • Active DoD 8570/8140 IAT Level II certification (e.g., Security+, CySA+).
  • U.S. Citizenship with an active Top Secret security clearance.

Responsibilities

  • Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets, hybrid infrastructure, and AI/LLM stacks.
  • Evaluate raw vulnerability data from ACAS and AWS tools to determine true threat vectors based on compensating controls and cloud architecture.
  • Use ACAS and DISA STIG benchmarks to verify configuration compliance and detect drift across cloud assets.
  • Track end-to-end remediation lifecycle and document progress.
  • Create and manage vulnerability tickets in Jira to maintain audit trails from detection to closure.
  • Serve as primary contact for IT staff and engineers, communicating remediation steps and prioritizing patches.
  • Translate high-risk vulnerabilities into POA&Ms with clear milestones and business impact.
  • Convert complex findings and AI security risks into actionable remediation guidance for platform and DevOps teams.
  • Correlate exploit intelligence with active vulnerabilities to refine risk prioritization.
  • Prepare vulnerability posture reports, metrics dashboards, and executive briefings for stakeholders.
  • Mentor mid-level analysts on triage methods, AI threat vectors, and automation.

Skills

Vulnerability Management
DoD/Government Systems
AWS Security
SQL Queries
Jira
DoD IAT II
Top Secret Clearance
ACAS/Tenable.sc
SCAP/DISA STIG
Communication Skills

Tools

ACAS (Tenable.sc)
Splunk Enterprise Security
Trellix ESS
Jira
REST APIs
SQL

Job description

Dark Wolf is seeking aVulnerability Management Lead to oversee technical vulnerability operations, modern AI workload security, and compliance baselines across a large-scale, multi-tenant cloud government system. Working closely with cross-functional engineering teams, system administrators, and program leadership, the Lead will drive the end-to-end vulnerability lifecycle from initial detection through final remediation.

We are seeking a collaborative cybersecurity professional with a solid foundation in federal or DoD vulnerability management, cloud environments, and technical risk assessment. This position offers the opportunity to lead operational workflows, leverage data analysis (SQL) and tool integrations (REST APIs) to automate reporting, and help shape security strategies for modern platforms—including emerging AI/LLM workloads.

Whether you are an experienced Lead or a Senior Vulnerability/Systems Analyst ready to take the next step in leadership, this role provides an impactful platform to guide technical risk decisions across a mission-critical system. This position is based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include:

Key Responsibilities

  • Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets, traditional hybrid infrastructure, and AI/LLM application stacks.
  • Evaluate raw vulnerability data generated by ACAS (Tenable.sc) and AWS security tools to determine its actual threat vector; identify true contextual risk based on compensating controls, network exposure, and the system's specific cloud architecture.
  • Leverage ACAS to execute and analyze SCAP-compliant configuration audits, verifying system alignment with established DISA STIG security benchmarks and identifying configuration drift across cloud assets.
  • Monitor, document, and track the end-to-end lifecycle of technical remediation efforts.
  • Establish and manage cybersecurity vulnerability tickets within Jira to maintain a clear audit trail from identification to closure.
  • Serve as a primary point of contact for hands-on IT support, system administrators, and engineers; clearly communicate the technical details of vulnerabilities, outline required remediation steps, and assist in prioritizing patches.
  • Translate un-remediated, high-true-risk vulnerabilities into actionable Plan of Action and Milestones (POA&Ms), clearly detailing the technical milestones and business impacts.
  • Translate complex technical findings and AI-specific security risks into concrete, step-by-step remediation guidance for platform, data science, and DevOps engineering teams.
  • Collaborate with the team to cross-reference active exploit intelligence against known system vulnerabilities, refining true risk prioritizations based on active real-world threats.
  • Compile and deliver vulnerability posture reports, metrics dashboards, and executive briefings for government stakeholders.
  • Mentor mid-level analysts on triage methodologies, emerging AI threat vectors, technical writing, and workflow automation.
Required Qualifications
  • 6+ years of experience in Cybersecurity, Vulnerability Management, or Systems Administration supporting federal or DoD information systems.
  • Direct, hands‑on experience utilizing ACAS (Tenable.sc) to filter, analyze, and report on enterprise vulnerabilities.
  • Operational understanding of the Security Content Automation Protocol (SCAP) ecosystem, including how automated configuration audit files translate into compliance metrics within vulnerability scanners.
  • Comprehensive understanding of how Splunk Enterprise Security and Trellix (ESS) correlate with vulnerability monitoring activities
  • Practical experience writing SQL queries for reporting and/or analytics
  • Proven proficiency utilizing Jira (or equivalent enterprise ticketing infrastructure) to track, update, and manage technical workflows through completion.
  • Excellent interpersonal and written communication skills, with a demonstrated ability to translate complex security vulnerabilities into actionable guidance for IT personnel.
  • Solid understanding of core AWS services (EC2, VPC, Security Groups, IAM) and how vulnerabilities manifest within a cloud‑native environment.
  • Must hold an active DoD 8570/8140 IAT Level II certification (e.g., Security+, CySA+).
  • U.S. Citizenship with an active Top Secret security clearance
Desired Qualifications
  • Possess a valid DISA certification for ACAS, Trellix, or Splunk issued or renewed within the last three years, or demonstrate the capability to successfully obtain the required DISA certification upon hire.
  • Familiarity with tracking vulnerabilities across containerized microservices (Docker/Kubernetes) or modern data platforms like Databricks.
  • Ability to identify and evaluate vulnerabilities unique to AI/LLM environments, including model training/inference pipelines, API endpoints, microservices, and AI framework dependencies (e.g., PyTorch, LangChain, Hugging Face) using frameworks like the OWASP Top 10 for LLM Applications.

The salary range for this position is estimated to be between $155,000.00 - $160,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Manager Lead
Vulnerability Manager Lead

Dark Wolf Solutions, LLC • Arlington (VA)

Hybrid
USD 155,000 - 160,000
Vulnerability Manager Lead
Vulnerability Manager Lead

Dark Wolf Solutions, LLC • Herndon (VA)

Hybrid
USD 155,000 - 160,000
Vulnerability Manager Lead, Cloud & AI Security
Vulnerability Manager Lead, Cloud & AI Security

Darkwolfsolutions • Herndon (VA)

Hybrid
USD 155,000 - 160,000
Vulnerability Operations Lead - Cloud & AI Security
Vulnerability Operations Lead - Cloud & AI Security

Dark Wolf Solutions, LLC • Herndon (VA)

Hybrid
USD 155,000 - 160,000
Vulnerability & Cloud Security Lead (Hybrid/Remote)
Vulnerability & Cloud Security Lead (Hybrid/Remote)

Dark Wolf Solutions, LLC • Arlington (VA)

Hybrid
USD 155,000 - 160,000
Security Control Assessor/Representatives
Security Control Assessor/Representatives

Dark Wolf • Washington

Hybrid
USD 135,000 - 150,000
Security Control Assessor/Representatives
Security Control Assessor/Representatives

Dark Wolf Solutions, LLC • Arlington (VA)

Hybrid
USD 135,000 - 150,000
Hybrid/remote opportunities
EEO/AA employer
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Security Control Assessor/Representatives
Security Control Assessor/Representatives

Dark Wolf Solutions, LLC • Washington

Hybrid
USD 135,000 - 150,000
Security Control Assessor/RepresentativesWashington DC Metro Area
Security Control Assessor/RepresentativesWashington DC Metro Area

BuddoBot Inc. • Washington

Hybrid
USD 135,000 - 150,000