Security Engineer - Vulnerability Manager
osition Type: OnsiteLocation: 1200 New Jersey Avenue, Washington, DC 20590, USA (DOT Headquarters)Work Authorization: U.S. Citizen or Green Card Holder with a minimum of 3 years U.S. residencySecurity Clearance: Public Trust (required prior to start)Duration: 07/06/2026 – 08/24/2026Potential for Conversion: YesSchedule: 8 hours/day, 40 hours/weekProgram: DOTPrime Contractor: SAICRole SummaryThe Security Engineer – Vulnerability Management will support the Department of Transportation's cybersecurity mission by identifying, assessing, tracking, and coordinating remediation of vulnerabilities across enterprise systems and infrastructure. This role works closely with federal leadership, system administrators, and cybersecurity teams to improve DOT's overall security posture and ensure compliance with federal cybersecurity standards and frameworks.Key ResponsibilitiesPerform endpoint vulnerability management activities across DOT enterprise environments.Utilize vulnerability scanning platforms, specifically Tenable Nessus, to identify and assess security risks.Coordinate remediation activities with system owners, application teams, and infrastructure administrators to meet required remediation timelines.Develop and maintain vulnerability tracking, reporting, and metrics dashboards.Present vulnerability trends, remediation status, and cyber risk findings to federal leadership and stakeholders.Troubleshoot issues related to endpoint vulnerability scanning and reporting.Manage cybersecurity-related ITSM tickets within ServiceNow through resolution.Participate in Cybersecurity and Security Operations (SecOps) meetings and initiatives.Collaborate with cross-functional teams to improve DOT cybersecurity solutions and processes.Provide guidance and education regarding vulnerability management concepts to technical and non-technical stakeholders.Required Technical SkillsMinimum of 6 years of experience in Cybersecurity or related Information Technology fields.Experience with endpoint vulnerability scanning solutions, specifically Tenable Nessus.Strong experience in:Vulnerability management lifecycleRisk assessment and mitigationRemediation planning and executionExperience with federal cybersecurity requirements and standards including:FISMANIST 800 SeriesNIST Risk Management Framework (RMF)NIST Cybersecurity Framework (CSF)Experience using ITSM platforms such as ServiceNow.Knowledge of:Operating systemsDatabasesNetworkingFirewallsCloud-based systemsData Loss Prevention (DLP)Endpoint Security solutionsIDS/IPS technologiesHost-based security technologiesAbility to develop vulnerability reports, dashboards, and risk metrics.Strong collaboration and communication skills across technical and business teams.Preferred / Nice-to-Have SkillsSecurity certifications such as:Security+CISSPCISMCISAGCIHOSCPCEHExperience supporting federal agencies and government cybersecurity programs.Experience presenting cybersecurity findings to executive leadership.Familiarity with cloud security practices and hybrid infrastructure environments.Qualifications & ExperienceBachelor's degree with 5+ years of cybersecurity experience; orMaster's degree with 4+ years of cybersecurity experience; orEquivalent combination of education and experience totaling at least 6 years in cybersecurity or related IT disciplines.Candidate must be eligible to obtain and maintain a Public Trust clearance prior to starting.Candidate must be a U.S. Citizen or Green Card Holder who has resided in the United States for at least three years.About the Team / CompanyThis position supports the Department of Transportation's cybersecurity mission focused on protecting information systems that support critical national infrastructure including highways, bridges, roads, and transportation systems.