Vulnerability Mgmt / Scan Operator

PingWind, Inc.

Northern (KY)

Hybrid

USD 93,000 - 128,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Eleven federal holidays
Paid time off
Parental leave
401k with matching
Education assistance
Medical, dental, vision

Job summary

PingWind, Inc. is seeking a skilled Vulnerability Management / Scan Operator to support vulnerability identification, remediation, and security compliance for a federal IAM program within the Department of Education's FSA. Remote-based role with strong emphasis on FISMA/NIST guidance and CDM/CSAM processes.

The ideal candidate has 8+ years of experience, holds a Bachelor's degree, and can coordinate with security teams and CSAM to track findings and remediation across the program.

Qualifications

  • Conduct and manage regular security vulnerability scans of IAM systems, applications, and databases using industry‑standard scanning tools.
  • Support federal compliance assessments including FISMA, A-123, BOD directives, and Safeguards reviews.
  • Review CDM scan results and respond to CVE data calls within required timeframes.
  • Maintain POA&M in CSAM and track security findings from identification to resolution.
  • Monitor CSF Scorecard ratings and provide remediation recommendations.
  • Manage IAM security control inheritance statements for reuse by other FSA systems.
  • Support SEIM and log management; coordinate with Security Operations Centers for real‑time data.
  • Verify encryption standards (AES-256, SHA-256, TLS, FIPS 140).
  • Track privileged access and PIV card issuance; maintain records of approved system access.
  • Ensure compliance with records management, PII protection, 508 accessibility, and TBM reporting.

Responsibilities

  • Conduct and manage regular vulnerability scans of IAM systems and databases; analyze results and plan remediation.
  • Develop corrective action plans and track remediation efforts for federal compliance assessments.
  • Review CDM scan results and respond to CVE data calls within required timeframes.
  • Maintain and update POA&M in CSAM for security findings from identification to resolution.
  • Monitor CSF Scorecard ratings and notify about compliance gaps with remediation recommendations.
  • Coordinate with security teams and CSAM users to ensure proper configuration of inheritable controls.
  • Support SEIM and log management; work with FSA SOCs for data collection and monitoring.
  • Verify data‑at‑rest and data‑in‑transit encryption compliance (AES‑256, SHA‑256, TLS, FIPS 140).
  • Report on privileged access, PIV status, and clearance compliance with proper records.
  • Ensure compliance with federal records management and TBM reporting requirements.

Skills

Vulnerability Scanning
Security Compliance
Remediation Planning
FISMA/NIST Knowledge
CDM/CSAM Experience
Security Operations Coordination

Education

Bachelor's degree

Tools

Vulnerability scanning tools
CSAM tooling

Job description

Location: Remote
Required Clearance: Public Trust
Required Education: Bachelors
Required Experience: 8 years

Position Description

We are seeking a skilled and security‑focused Vulnerability Management / Scan Operator to support vulnerability identification, remediation, and security compliance efforts for a complex, mission‑critical federal Identity and Access Management (IAM) program within the U.S. Department of Education’s Federal Student Aid (FSA) office. The ideal candidate brings strong expertise in security scanning, vulnerability assessment, remediation planning, and federal cybersecurity compliance frameworks.

Responsibilities

This position plays a pivotal role in maintaining the security posture and compliance status of FSA's IAM systems. The Vulnerability Management / Scan Operator works closely with security teams, system administrators, and compliance officers to identify security findings, develop remediation strategies, and ensure adherence to federal cybersecurity standards including FISMA, CISA BOD directives, and NIST guidance.

Required Qualifications
  • Conduct and manage regular security vulnerability scans of IAM systems, applications, and databases using industry‑standard scanning tools; analyze results and develop remediation plans.
  • Support federal compliance assessments including FISMA, A-123, Binding Operational Directives (BOD), and Safeguards reviews; develop corrective action plans and track remediation efforts.
  • Review and manage Continuous Diagnostics and Monitoring (CDM) scan results; respond to Common Vulnerabilities and Exposures (CVE) data calls within required timeframes.
  • Maintain and update Plans of Action and Milestones (POA&M) in Cyber Security Assessment and Management (CSAM); ensure security findings are accurately tracked from identification through resolution.
  • Monitor and maintain IAM Cybersecurity Framework Risk (CSF) Scorecard rating; notify FSA of any compliance gaps and provide remediation recommendations.
  • Manage IAM security control inheritance statements and ensure Inheritable Controls are properly configured in CSAM for use by other FSA systems.
  • Support Security Event and Incident Management (SEIM) and log management processes; coordinate with FSA Security Operations Centers to ensure proper data collection and real‑time monitoring.
  • Verify encryption standards compliance for data‑at‑rest and data‑in‑transit, including AES-256, SHA-256, TLS protocols, and FIPS 140 requirements.
  • Track and report on privileged user access, including PIV card issuance, status changes, and security clearance compliance; maintain records of personnel with approved system access.
  • Ensure compliance with federal records management, PII protection, Section 508 accessibility standards, and Technology Business Management (TBM) reporting requirements.
About PingWind

PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity, development, IT infrastructure, supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service‑Disabled Veteran‑Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL.

www.PingWind.com

Our benefits include:

  • Eleven Federal Holidays
  • Paid Time Off accrued each pay period
  • Parental Leave
  • Three medical plan choices with generous employer contribution
  • Dental and Vision Insurance
  • Company paid Short‑Term and Long‑Term Disability
  • Company paid Life and AD&D Insurance
  • 401k with competitive matching and vesting schedule
  • Continuing education assistance
  • Short Term / Long Term Disability & Life Insurance
  • Medical, Dependent Care and Commuter Flexible Spending Accounts
  • Employee Assistance Program
  • Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)
  • 529 College Savings Plan
  • Legal Insurance
  • Pet Insurance
Salary Range

$93K-$128K

The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities, education, certifications, experience, as well as internal equity mapping and alignment with market data, or other applicable laws.

PingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Mgmt / Scan Operator
Vulnerability Mgmt / Scan Operator

PingWind • United States

Remote
USD 93,000 - 128,000
Exceptional health benefits
Paid time off
Federal holidays
+4
Remote IAM Vulnerability & Security Compliance Lead
Remote IAM Vulnerability & Security Compliance Lead

PingWind • United States

Remote
USD 93,000 - 128,000
Exceptional health benefits
Paid time off
Federal holidays
+4
QA / Test Automation Engineer
QA / Test Automation Engineer

PingWind, Inc. • Northern (KY)

Hybrid
USD 54,000 - 74,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+8
Remote Vulnerability Scan & Remediation Lead
Remote Vulnerability Scan & Remediation Lead

Socket.dev • United States

Remote
USD 93,000 - 128,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+5
Remote Vulnerability Management & Scan Operator
Remote Vulnerability Management & Scan Operator

PingWind, Inc. • Northern (KY)

Hybrid
USD 93,000 - 128,000
Eleven federal holidays
Paid time off
Parental leave
+3
Help Desk Support Agent (Mid)
Help Desk Support Agent (Mid)

PingWind, Inc. • Northern (KY)

Hybrid
USD 66,000 - 92,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+7
Security Engineer (SIEM / EL3 Logging)
Security Engineer (SIEM / EL3 Logging)

PingWind • Huntsville (AL)

Hybrid
USD 93,000 - 128,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+3
Security Engineer (SIEM / EL3 Logging)
Security Engineer (SIEM / EL3 Logging)

PingWind • United States

On-site
USD 93,000 - 128,000
Paid time off
Parental leave
Medical plan - 3 options
+7
QA / Test Automation Engineer
QA / Test Automation Engineer

PingWind • United States

On-site
USD 54,000 - 74,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+11
DevSecOps Engineer
DevSecOps Engineer

PingWind • United States

On-site
USD 93,000 - 128,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+11