{"schemaVersion":"jobsearcher.job.v1","id":"1adfdf4ce879bed47e0b3cf1","url":"https://jobsearcher.com/jobs/1adfdf4ce879bed47e0b3cf1","canonicalUrl":"https://jobsearcher.com/jobs/1adfdf4ce879bed47e0b3cf1","title":"Vulnerability Manager, Treasury","description":"Summary\nThunderyard is seeking a Vulnerability Manager to support a federal customer in leading enterprise vulnerability management and continuous monitoring efforts across complex hybrid IT environments. This role is ideal for a cybersecurity professional who enjoys identifying security risks, driving remediation efforts, and partnering with technical teams to strengthen an organization's overall security posture.\nAs the Enterprise Vulnerability Manager, you will oversee vulnerability scanning, analysis, reporting, and remediation coordination across cloud and on-premises environments. You'll collaborate with cybersecurity engineers, infrastructure teams, application owners, vendors, and government stakeholders to ensure vulnerabilities are prioritized, tracked, and remediated in accordance with federal cybersecurity requirements and agency policies.\nThis role offers the opportunity to directly improve the security of mission-critical federal systems while supporting enterprise-wide cybersecurity modernization initiatives.\nKey Responsibilities\nManage enterprise vulnerability management activities across cloud, hybrid, and on-premises environments.\nManage vulnerability scanning programs using enterprise security assessment tools.\nAnalyze vulnerability assessment results and prioritize remediation activities based on organizational risk.\nCoordinate remediation efforts with infrastructure teams, application owners, cybersecurity engineers, vendors, and government stakeholders.\nDevelop and maintain Plans of Action and Milestones (POA&Ms) to track vulnerability remediation activities.\nMonitor remediation progress and provide status updates to leadership and program stakeholders.\nDevelop dashboards, reports, and executive briefings that communicate enterprise vulnerability trends and remediation metrics.\nSupport troubleshooting sessions with vendors and internal technical teams to identify root causes and implement corrective actions.\nDevelop and maintain enterprise vulnerability management policies, procedures, and standards aligned with current federal cybersecurity guidance.\nEnsure vulnerability management activities align with agency security requirements and continuous monitoring objectives.\nMaintain technical documentation using Atlassian Jira and Confluence.\nBasic Qualifications\nActive Public Trust clearance is required.\nU.S. Citizenship is required.\n2+ years of experience supporting enterprise vulnerability management, cybersecurity operations, or information security programs within federal or enterprise environments.\nMust have experience using Qualys and Tenable\nExperience managing enterprise vulnerability scanning and assessment programs across hybrid technology environments.\nExperience administering and utilizing enterprise vulnerability management tools, including:\nCheckmarx\nPrisma Cloud\nMicrosoft Defender for Endpoint\nExperience creating, managing, and tracking Plans of Action and Milestones (POA&Ms) using ServiceNow Governance, Risk, and Compliance (GRC) or similar platforms.\nExperience collaborating with technical teams and stakeholders to coordinate vulnerability remediation activities.\nExperience facilitating troubleshooting sessions with vendors and internal technical teams to identify vulnerabilities and recommend remediation strategies.\nExperience developing vulnerability reporting dashboards and executive-level security metrics.\nExperience writing automation or reporting scripts to support vulnerability management and security reporting.\nExperience developing and maintaining enterprise vulnerability management policies, procedures, and standards.\nKnowledge of current federal cybersecurity guidance, including CISA Binding Operational Directives (BODs), Executive Orders, and vulnerability management best practices.\nExperience supporting continuous monitoring (ConMon) and enterprise cybersecurity programs.\nStrong analytical and risk assessment skills with the ability to prioritize vulnerabilities based on organizational impact.\nExcellent written, verbal, and stakeholder communication skills.\nPreferred Qualifications\nExperience supporting the Department of the Treasury or other civilian federal agencies.\nKnowledge of the NIST Risk Management Framework (RMF), NIST SP 800-53 Rev. 5, and FISMA requirements.\nExperience with cloud security and vulnerability management across Microsoft Azure or hybrid cloud environments.\nExperience supporting Security Operations Centers (SOC) or Security Information and Event Management (SIEM) platforms.\nRelevant certifications such as:\nCompTIA Security+\nCySA+\nCISSP\nGSEC\nGIAC Certified Vulnerability Assessor (GCVA)\nExperience working within Agile or DevSecOps environments.\nCompensation\nThis role is budgeted at an annual salary of $80,000-$90,000, plus benefits including medical, dental, vision coverage, PTO, and partial 401(k) match\nVetting\nCandidates selected will be subject to a background investigation for clearance eligibility by our government client.\nThunderYard Solutions is proud to be an Equal Opportunity Employer. We don’t just accept difference – we celebrate it, we support it, and we thrive on it for the benefit of our employees, our community, and our customers. All applicants will be considered for employment without discrimination of race, color, religion, or belief, national, social, or ethnic origin, sex, age, physical, mental, or sensory disability, HIV status, sexual orientation, gender identity and/or expression, marital, civil union, or domestic partnership status, protected veteran status, family medical history or genetic information.\nPay: $80,000.00 - $90,000.00 per year\nBenefits:\n401(k)\n401(k) matching\nDental insurance\nFlexible spending account\nHealth insurance\nHealth savings account\nLife insurance\nPaid time off\nProfessional development assistance\nRetirement plan\nVision insurance\nApplication Question(s):\n*\nDo you have an active security clearance or have you held an active security clearance in the past year?\nWork Location: Remote","company":"Thunderyard Solutions","rawCompany":"thunderyard solutions","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-06T16:24:48.358Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"921190","title":"Other General Government Support","slug":"other-general-government-support"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Vulnerability Manager, Treasury","description":"Summary\nThunderyard is seeking a Vulnerability Manager to support a federal customer in leading enterprise vulnerability management and continuous monitoring efforts across complex hybrid IT environments. This role is ideal for a cybersecurity professional who enjoys identifying security risks, driving remediation efforts, and partnering with technical teams to strengthen an organization's overall security posture.\nAs the Enterprise Vulnerability Manager, you will oversee vulnerability scanning, analysis, reporting, and remediation coordination across cloud and on-premises environments. You'll collaborate with cybersecurity engineers, infrastructure teams, application owners, vendors, and government stakeholders to ensure vulnerabilities are prioritized, tracked, and remediated in accordance with federal cybersecurity requirements and agency policies.\nThis role offers the opportunity to directly improve the security of mission-critical federal systems while supporting enterprise-wide cybersecurity modernization initiatives.\nKey Responsibilities\nManage enterprise vulnerability management activities across cloud, hybrid, and on-premises environments.\nManage vulnerability scanning programs using enterprise security assessment tools.\nAnalyze vulnerability assessment results and prioritize remediation activities based on organizational risk.\nCoordinate remediation efforts with infrastructure teams, application owners, cybersecurity engineers, vendors, and government stakeholders.\nDevelop and maintain Plans of Action and Milestones (POA&Ms) to track vulnerability remediation activities.\nMonitor remediation progress and provide status updates to leadership and program stakeholders.\nDevelop dashboards, reports, and executive briefings that communicate enterprise vulnerability trends and remediation metrics.\nSupport troubleshooting sessions with vendors and internal technical teams to identify root causes and implement corrective actions.\nDevelop and maintain enterprise vulnerability management policies, procedures, and standards aligned with current federal cybersecurity guidance.\nEnsure vulnerability management activities align with agency security requirements and continuous monitoring objectives.\nMaintain technical documentation using Atlassian Jira and Confluence.\nBasic Qualifications\nActive Public Trust clearance is required.\nU.S. Citizenship is required.\n2+ years of experience supporting enterprise vulnerability management, cybersecurity operations, or information security programs within federal or enterprise environments.\nMust have experience using Qualys and Tenable\nExperience managing enterprise vulnerability scanning and assessment programs across hybrid technology environments.\nExperience administering and utilizing enterprise vulnerability management tools, including:\nCheckmarx\nPrisma Cloud\nMicrosoft Defender for Endpoint\nExperience creating, managing, and tracking Plans of Action and Milestones (POA&Ms) using ServiceNow Governance, Risk, and Compliance (GRC) or similar platforms.\nExperience collaborating with technical teams and stakeholders to coordinate vulnerability remediation activities.\nExperience facilitating troubleshooting sessions with vendors and internal technical teams to identify vulnerabilities and recommend remediation strategies.\nExperience developing vulnerability reporting dashboards and executive-level security metrics.\nExperience writing automation or reporting scripts to support vulnerability management and security reporting.\nExperience developing and maintaining enterprise vulnerability management policies, procedures, and standards.\nKnowledge of current federal cybersecurity guidance, including CISA Binding Operational Directives (BODs), Executive Orders, and vulnerability management best practices.\nExperience supporting continuous monitoring (ConMon) and enterprise cybersecurity programs.\nStrong analytical and risk assessment skills with the ability to prioritize vulnerabilities based on organizational impact.\nExcellent written, verbal, and stakeholder communication skills.\nPreferred Qualifications\nExperience supporting the Department of the Treasury or other civilian federal agencies.\nKnowledge of the NIST Risk Management Framework (RMF), NIST SP 800-53 Rev. 5, and FISMA requirements.\nExperience with cloud security and vulnerability management across Microsoft Azure or hybrid cloud environments.\nExperience supporting Security Operations Centers (SOC) or Security Information and Event Management (SIEM) platforms.\nRelevant certifications such as:\nCompTIA Security+\nCySA+\nCISSP\nGSEC\nGIAC Certified Vulnerability Assessor (GCVA)\nExperience working within Agile or DevSecOps environments.\nCompensation\nThis role is budgeted at an annual salary of $80,000-$90,000, plus benefits including medical, dental, vision coverage, PTO, and partial 401(k) match\nVetting\nCandidates selected will be subject to a background investigation for clearance eligibility by our government client.\nThunderYard Solutions is proud to be an Equal Opportunity Employer. We don’t just accept difference – we celebrate it, we support it, and we thrive on it for the benefit of our employees, our community, and our customers. All applicants will be considered for employment without discrimination of race, color, religion, or belief, national, social, or ethnic origin, sex, age, physical, mental, or sensory disability, HIV status, sexual orientation, gender identity and/or expression, marital, civil union, or domestic partnership status, protected veteran status, family medical history or genetic information.\nPay: $80,000.00 - $90,000.00 per year\nBenefits:\n401(k)\n401(k) matching\nDental insurance\nFlexible spending account\nHealth insurance\nHealth savings account\nLife insurance\nPaid time off\nProfessional development assistance\nRetirement plan\nVision insurance\nApplication Question(s):\n*\nDo you have an active security clearance or have you held an active security clearance in the past year?\nWork Location: Remote","datePosted":"2026-08-06T16:24:48.358Z","dateModified":"2026-08-06T16:24:48.358Z","hiringOrganization":{"@type":"Organization","name":"Thunderyard Solutions","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"1adfdf4ce879bed47e0b3cf1"},"url":"https://jobsearcher.com/jobs/1adfdf4ce879bed47e0b3cf1"}}