Vulnerability Management Lead

Saronic Saronic · Defense · Austin, TX · Software

Lead Vulnerability Management program for a defense technology company, focusing on end-to-end lifecycle management, automation, and compliance with CMMC.

What you'd actually do

  1. Own end-to-end vulnerability lifecycle: discovery, validation, prioritization, remediation tracking, exception management, and verification across cloud, on-prem, container, and embedded Linux environments
  2. Operate and optimize enterprise vulnerability scanning platforms for continuous credentialed scanning across servers, endpoints, network devices, containers, and cloud assets; maintain coverage, schedules, and configuration audit policies
  3. Integrate vulnerability scanning into CI/CD pipelines to harden build workflows, enforce least-privilege controls, and surface supply chain risks before they reach production
  4. Leverage AI-assisted scanning and graph-based enrichment pipelines to accelerate triage, map lateral exposure paths, and prioritize findings by exploitability and mission impact
  5. Apply CVSS, CISA KEV, exploit maturity, and asset exposure context — including internet-facing systems, privileged access paths, and classified adjacency — to drive risk-based SLAs and remediation sequencing

Skills

Required

  • Vulnerability management
  • Cybersecurity
  • Vulnerability scanning platforms
  • CI/CD security
  • Supply chain risk management
  • Risk-based SLAs
  • CMMC
  • NIST SP 800-171
  • NIST RMF
  • Communication

Nice to have

  • AI-assisted vulnerability tooling
  • Graph-based asset and exposure analysis
  • Automated enrichment pipelines
  • CI/CD pipeline security hardening platforms
  • Classified or air-gapped environments
  • Python
  • PowerShell
  • Bash
  • Container and cloud-native vulnerability management
  • NIST SP 800-218
  • CISSP
  • CySA+
  • GCSA
  • GCPN
  • Security+

What the JD emphasized

  • own Saronic's VM program end-to-end
  • build and run the program
  • drive accountability across engineering teams
  • shape the long-term VM posture
  • hands-on
  • individual contributor role with significant operational and strategic ownership
  • strong opinions about how VM should work
  • push for remediation ownership
  • automation as the path to scale
  • drive timely remediation
  • own escalation paths
  • lead critical CVE response
  • align the VM program to CMMC Level 2/3 requirements
  • produce audit-ready evidence
  • support CMMC assessments and audits
  • build and mature automation
  • evaluate and recommend tooling improvements
  • mentor and support analysts
  • 3+ years of hands-on vulnerability management ownership
  • Proven track record driving remediation accountability across engineering teams
  • Experience aligning VM programs to federal or defense compliance frameworks
  • CMMC, NIST SP 800-171, or NIST RMF experience strongly preferred