Vulnerability Management Lead

Posted Yesterday
Be an Early Applicant
Washington, DC, USA
In-Office
Senior level
Information Technology • Professional Services • Cybersecurity • Defense
The Role
Lead and operate an enterprise vulnerability management program: analyze scan results, prioritize risks, coordinate remediation across stakeholders, produce executive reporting, integrate findings into POA&M and compliance workflows, and drive closure of critical vulnerabilities.
Summary Generated by Built In

Description

  

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.

Our four core values define how we show up every day:

  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients' mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.

Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.

Position Summary 

Own enterprise vulnerability management as a sustained program function — tracking, analysis, prioritization, remediation coordination, and trend reporting across systems, applications, devices, and other in-scope assets. This position converts scan output into risk-informed decisions, drives remediation to closure with system and business stakeholders, and integrates vulnerability data into the broader risk and compliance picture. 

Key Responsibilities 

  • Operate vulnerability management as a sustained enterprise function: identification, documentation, prioritization, monitoring, and closure across all in-scope assets. 
  • Analyze vulnerability data, scan results, remediation status, and related security findings to enable risk-based decision making. 
  • Coordinate remediation with system owners and stakeholders; assist in evaluating remediation actions, timelines, and residual risk. 
  • Identify aging vulnerabilities and recurring or systemic issues; recommend process improvements and risk-reduction measures. 
  • Lead recurring vulnerability review meetings with applicable stakeholders to review status and support remediation planning. 
  • Produce periodic reporting covering severity, age, trend, and system-level status. 
  • Provide monthly vulnerability reporting and an accompanying risk mitigation plan.  Escalate critical and high vulnerabilities to the client's Chief Information Officer and Chief Information Security Officer and drive remediation as rapidly as possible, with POA&Ms established and prioritized by the risks implicated. 
  • Integrate vulnerability management activity into overall risk and compliance support, feeding the POA&M workflow and authorization-boundary tracking maintained by the ISSO/ISCM Lead. 
  • Support risk identification, analysis, tracking, and mitigation related to vulnerabilities, control gaps, and system changes. 

Requirements

  

  • Bachelor's degree in cybersecurity, information technology, or a related field. Equivalent experience considered in lieu of degree. 
  • Six or more years in vulnerability management, including at least two years leading or coordinating an enterprise vulnerability program. 
  • Hands-on proficiency with enterprise vulnerability scanning and management platforms — Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent. 
  • Demonstrated ability to apply risk-based prioritization beyond raw CVSS, incorporating exploitability, the CISA Known Exploited Vulnerabilities catalog, asset criticality, and compensating controls. 
  • Experience driving remediation across organizational boundaries with system owners who do not report to the vulnerability function. 
  • Experience producing executive-facing vulnerability trend reporting and defensible remediation timelines aligned to federal expectations. 
  • Working knowledge of POA&M processes and NIST vulnerability management controls. 

Preferred Qualifications 

  • Cloud and container vulnerability management experience — Azure and Microsoft 365, AWS, container image scanning. 
  • Experience correlating vulnerability data with SIEM and EDR telemetry to support threat-hunting hypotheses. 
  • Experience with SBOM analysis and the vulnerability implications of supply chain risk. 

Required Certifications 

A relevant cybersecurity certification demonstrating competence in vulnerability management, risk, or operations support. Acceptable examples include CompTIA CySA+, GIAC GEVA or GCIH, a Tenable or Qualys vendor certification, CISSP, or CRISC. 

Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process. 

The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.
 

K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.
 

This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice. 

Skills Required

  • Bachelor's degree in cybersecurity, information technology, or related field (or equivalent experience)
  • Six or more years in vulnerability management, including at least two years leading or coordinating an enterprise vulnerability program
  • Hands-on proficiency with enterprise vulnerability scanning and management platforms (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent)
  • Ability to apply risk-based prioritization beyond CVSS, incorporating exploitability, CISA KEV, asset criticality, and compensating controls
  • Experience driving remediation across organizational boundaries with system owners
  • Experience producing executive-facing vulnerability trend reporting and defensible remediation timelines aligned to federal expectations
  • Working knowledge of POA&M processes and NIST vulnerability management controls
  • Relevant cybersecurity certification (examples: CompTIA CySA+, GIAC GEVA or GCIH, Tenable/Qualys vendor certification, CISSP, or CRISC)
  • Willingness to take a drug test and submit to credit and background investigation
  • Cloud and container vulnerability management experience (Azure, Microsoft 365, AWS, container image scanning)
  • Experience correlating vulnerability data with SIEM and EDR telemetry for threat-hunting
  • Experience with SBOM analysis and supply chain vulnerability implications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
96 Employees
Year Founded: 2000

What We Do

K2Share, LLC is a certified HUBZone and Veteran Owned Small Business that serves as a technology services provider for the federal government. Operating as a cybersecurity consultancy and managed Security Services Provider (MSSP), the company delivers data-driven solutions to simplify risk management, cybersecurity program maturity, and security awareness training. It specializes in strategy, policy guidance, and mission visualization to operationalize cybersecurity for federal agencies.

Similar Jobs

HiBob Logo HiBob

Sales Engineer

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
90K-120K Annually

HiBob Logo HiBob

Sales Engineer

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
United States
1350 Employees
108K-145K Annually

Enverus Logo Enverus

Contract Energy Examiner - 26313

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
2 Locations
1800 Employees
58K-63K Annually

Wells Fargo Logo Wells Fargo

Branch Manager DC Proper District

Fintech • Financial Services
Hybrid
Washington, DC, USA
205000 Employees
43K-67K Hourly

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account