Vulnerability Manager, Treasury
Summary
Thunderyard is seeking a Vulnerability Manager to support a federal customer in leading enterprise vulnerability management and continuous monitoring efforts across complex hybrid IT environments. This role is ideal for a cybersecurity professional who enjoys identifying security risks, driving remediation efforts, and partnering with technical teams to strengthen an organization's overall security posture.
As the Enterprise Vulnerability Manager, you will oversee vulnerability scanning, analysis, reporting, and remediation coordination across cloud and on-premises environments. You'll collaborate with cybersecurity engineers, infrastructure teams, application owners, vendors, and government stakeholders to ensure vulnerabilities are prioritized, tracked, and remediated in accordance with federal cybersecurity requirements and agency policies.
This role offers the opportunity to directly improve the security of mission-critical federal systems while supporting enterprise-wide cybersecurity modernization initiatives.
Key Responsibilities
Manage enterprise vulnerability management activities across cloud, hybrid, and on-premises environments.
Manage vulnerability scanning programs using enterprise security assessment tools.
Analyze vulnerability assessment results and prioritize remediation activities based on organizational risk.
Coordinate remediation efforts with infrastructure teams, application owners, cybersecurity engineers, vendors, and government stakeholders.
Develop and maintain Plans of Action and Milestones (POA&Ms) to track vulnerability remediation activities.
Monitor remediation progress and provide status updates to leadership and program stakeholders.
Develop dashboards, reports, and executive briefings that communicate enterprise vulnerability trends and remediation metrics.
Support troubleshooting sessions with vendors and internal technical teams to identify root causes and implement corrective actions.
Develop and maintain enterprise vulnerability management policies, procedures, and standards aligned with current federal cybersecurity guidance.
Ensure vulnerability management activities align with agency security requirements and continuous monitoring objectives.
Maintain technical documentation using Atlassian Jira and Confluence.
Basic Qualifications
Active Public Trust clearance is required.
U.S. Citizenship is required.
2+ years of experience supporting enterprise vulnerability management, cybersecurity operations, or information security programs within federal or enterprise environments.
Must have experience using Qualys and Tenable
Experience managing enterprise vulnerability scanning and assessment programs across hybrid technology environments.
Experience administering and utilizing enterprise vulnerability management tools, including:
Checkmarx
Prisma Cloud
Microsoft Defender for Endpoint
Experience creating, managing, and tracking Plans of Action and Milestones (POA&Ms) using ServiceNow Governance, Risk, and Compliance (GRC) or similar platforms.
Experience collaborating with technical teams and stakeholders to coordinate vulnerability remediation activities.
Experience facilitating troubleshooting sessions with vendors and internal technical teams to identify vulnerabilities and recommend remediation strategies.
Experience developing vulnerability reporting dashboards and executive-level security metrics.
Experience writing automation or reporting scripts to support vulnerability management and security reporting.
Experience developing and maintaining enterprise vulnerability management policies, procedures, and standards.
Knowledge of current federal cybersecurity guidance, including CISA Binding Operational Directives (BODs), Executive Orders, and vulnerability management best practices.
Experience supporting continuous monitoring (ConMon) and enterprise cybersecurity programs.
Strong analytical and risk assessment skills with the ability to prioritize vulnerabilities based on organizational impact.
Excellent written, verbal, and stakeholder communication skills.
Preferred Qualifications
Experience supporting the Department of the Treasury or other civilian federal agencies.
Knowledge of the NIST Risk Management Framework (RMF), NIST SP 800-53 Rev. 5, and FISMA requirements.
Experience with cloud security and vulnerability management across Microsoft Azure or hybrid cloud environments.
Experience supporting Security Operations Centers (SOC) or Security Information and Event Management (SIEM) platforms.
Relevant certifications such as:
CompTIA Security+
CySA+
CISSP
GSEC
GIAC Certified Vulnerability Assessor (GCVA)
Experience working within Agile or DevSecOps environments.
Compensation
This role is budgeted at an annual salary of $80,000-$90,000, plus benefits including medical, dental, vision coverage, PTO, and partial 401(k) match
Vetting
Candidates selected will be subject to a background investigation for clearance eligibility by our government client.
ThunderYard Solutions is proud to be an Equal Opportunity Employer. We don’t just accept difference – we celebrate it, we support it, and we thrive on it for the benefit of our employees, our community, and our customers. All applicants will be considered for employment without discrimination of race, color, religion, or belief, national, social, or ethnic origin, sex, age, physical, mental, or sensory disability, HIV status, sexual orientation, gender identity and/or expression, marital, civil union, or domestic partnership status, protected veteran status, family medical history or genetic information.
Pay: $80,000.00 - $90,000.00 per year
Benefits:
401(k)
401(k) matching
Dental insurance
Flexible spending account
Health insurance
Health savings account
Life insurance
Paid time off
Professional development assistance
Retirement plan
Vision insurance
Application Question(s):
*
Do you have an active security clearance or have you held an active security clearance in the past year?
Work Location: Remote