Source Job

$93,000–$128,000/yr
US

  • Conduct and manage regular security vulnerability scans of IAM systems using industry-standard tools, analyzing results and developing remediation plans.
  • Support federal compliance assessments including FISMA, A-123, BOD, and Safeguards reviews, developing corrective action plans and tracking remediation efforts.
  • Maintain and update Plans of Action and Milestones (POA&M) in CSAM, monitor CDM scan results, and ensure adherence to NIST guidance and federal cybersecurity standards.

16 jobs similar to Vulnerability Mgmt / Scan Operator

Jobs ranked by similarity.

US 3w PTO

  • Lead the enterprise Vulnerability Management and CDM program, directing scanning and prioritization strategies.
  • Coordinate remediation activities across system owners, engineering teams, and ISSOs to reduce cyber risk.
  • Develop executive metrics, dashboards, and reports to communicate vulnerability posture and operational risk trends.

True Zero Technologies is a veteran-owned small business that focuses on purposeful enablement of people and technology. Recognized as a Best Places to Work in 2023 and 2025, and listed on the Inc. 5000 fastest-growing companies, the company emphasizes a people-first culture and dedication to excellence.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

$155,000–$160,000/yr
US

  • Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets and AI/LLM application stacks.
  • Leverage ACAS (Tenable.sc) and AWS security tools to evaluate threat vectors and ensure compliance with DISA STIG benchmarks.
  • Translate complex technical findings into actionable remediation guidance and executive briefings for government stakeholders.

Dark Wolf is a cybersecurity firm specializing in vulnerability management and cloud security for federal and DoD systems. The company maintains a collaborative, mission-focused culture with a team of cybersecurity professionals.

US

  • Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
  • Oversee preparation and execution of external compliance audits, including facilitating security assessments.
  • Support mapping of compliance requirements to security control implementation using agile development processes.

Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.

US

  • Oversee the enterprise vulnerability management program, including administering Tenable platforms and conducting regular assessments.
  • Monitor and respond to MDR alerts, investigate security incidents, and coordinate remediation efforts.
  • Review and approve cybersecurity-related change requests, ensuring security risks are communicated and mitigated.

Loenbro is a trusted, long-term construction lifecycle partner serving thousands of customers across the U.S. They have a national presence with a local approach, and build careers grounded in integrity, teamwork, excellence, and purpose.

US Unlimited PTO

  • Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
  • Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
  • Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.

Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.

$120,000–$170,000/yr
US

  • Manage and conduct penetration testing, antivirus scanning, and SIEM tooling to ensure system security.
  • Assess software systems for security posture and maintain compliance frameworks like SOC2, NIST, and CJIS.
  • Respond to security questionnaires, manage training programs, and improve Business Continuity and Disaster Recovery plans.

GovWorx helps public safety agencies address the loss of experience through its AI-powered platform, CommsCoach. It is a growing technology company with a high-performing team focused on AI, engineering, product, and data science.

US

  • Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
  • Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
  • Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.

Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.

$105,000–$155,000/yr
US

  • Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
  • Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
  • Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.

The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.

US 3w PTO

  • Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
  • Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
  • Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.

Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

Global

  • Assist in monitoring compliance with frameworks like ISO 27001, SOC 2, and Cyber Essentials.
  • Maintain the central Risk Register and track remediation progress across departments.
  • Support policy management and compliance training across the organization.

We are a global Physical AI company using data and AI to improve critical industries like healthcare, water, energy, and telecom. Our teams are ambitious, curious, and practical, with colleagues across Africa, Europe, the UK, and the US.

US

  • Execute NIST SP 800-53 control mappings and implement security baselines.
  • Develop and maintain SSPs, POA&Ms, and authorization documentation.
  • Support continuous monitoring and gap assessments for ATO and FedRAMP.

This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.

$128,445–$183,450/yr
US Unlimited PTO

  • Own and administer Salesforce Government Cloud, ensuring compliance with FedRAMP and CUI handling.
  • Manage user access, profiles, and permission sets under least-privilege standards.
  • Build enhancements using declarative tools and maintain reports for federal stakeholders.

IonQ is the world's leading quantum platform and merchant supplier, delivering integrated quantum solutions across computing, networking, sensing, and security. Headquartered in College Park, MD, IonQ has operations across the US and globally, and fosters a culture of autonomy and respect.

$80,000–$130,000/yr
US

  • You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
  • You will run the vulnerability management program and remediate security findings across AWS.
  • You will support security incident response, fraud investigations, and third-party risk assessments.

We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.