Vulnerability Mgmt / Scan Operator

Pingwind
United States
Remote

Who this role is best for

Strong fit for mid-level cybersecurity professionals who manage federal compliance frameworks and conduct vulnerability scans.

Best fit for

  • Mid-level professionals with federal compliance and vulnerability scanning experience in IAM systems
    — “complex, mission-critical federal Identity and Access Management (IAM) program within the U.S. Department of Education’s Federal Student Aid (FSA) office
  • Candidates with a background in managing federal cybersecurity standards like FISMA and CISA BOD directives
    — “support federal compliance assessments including FISMA, A-123, Binding Operational Directives (BOD), and Safeguards reviews
  • Individuals who have experience with security scanning tools and POA&M tracking in CSAM
    — “Conduct and manage regular security vulnerability scans ... develop remediation plans

Things to consider

  • This role requires a bachelor's degree and 8 years of experience, which may be a barrier for less experienced candidates
    — “Required Education: Bachelors
  • The position involves managing federal compliance frameworks, which may require familiarity with government regulations
    — “ensure adherence to federal cybersecurity standards including FISMA, CISA BOD directives, and NIST guidance

How to stand out

  • Emphasize your ability to manage and interpret vulnerability scan results using industry-standard tools
    — “Conduct and manage regular security vulnerability scans of IAM systems, applications, and databases using industry-standard scanning tools
  • Demonstrate proficiency in maintaining and updating POA&M documents in CSAM
    — “Maintain and update Plans of Action and Milestones (POA&M) in Cyber Security Assessment and Management (CSAM)
  • Showcase your experience with encryption standards like AES-256, TLS, and FIPS 140-2
    — “Verify encryption standards compliance for data-at-rest and data-in-transit, including AES-256, SHA-256, TLS protocols, and FIPS 140 requirements
  • Demonstrate your ability to coordinate with security operations centers and track remediation efforts
    — “Support Security Event and Incident Management (SEIM) and log management processes; coordinate with FSA Security Operations Centers
Pace · SteadyCollaboration · HighAutonomy · MediumDecision Impact · TeamLevel · Mid Level

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • conduct and manage regular security vulnerability scans
  • develop remediation plans
  • support federal compliance assessments
  • track and report on privileged user access
  • ensure compliance with federal records management
Typical background
8 years of experience in security scanning, vulnerability assessment, remediation planning, and federal cybersecurity compliance frameworks

Skills & requirements

Required

Security ScanningVulnerability AssessmentRemediation PlanningFederal Cybersecurity Compliance FrameworksSecurity Event And Incident ManagementLog ManagementEncryption Standards CompliancePrivileged User Access ManagementFederal Records ManagementPII ProtectionSection 508 Accessibility StandardsTBM Reporting Requirements

Stack & domain

Security ScanningVulnerability AssessmentFismaCISA BODNISTCommunicationProblem-solvingTeamworkAttention To DetailCybersecurityFederal Compliance

About the role

Original posting from Pingwind via Lever

Location: Remote

Required Clearance: Public Trust 

Required Education: Bachelors

Required Experience: 8 years

Position Description

We are seeking a skilled and security‑focused Vulnerability Management / Scan Operator to support vulnerability identification, remediation, and security compliance efforts for a complex, mission‑critical federal Identity and Access Management (IAM) program within the U.S. Department of Education’s Federal Student Aid (FSA) office. The ideal candidate brings strong expertise in security scanning, vulnerability assessment, remediation planning, and federal cybersecurity compliance frameworks.

Responsibilities

This position plays a pivotal role in maintaining the security posture and compliance status of FSA's IAM systems. The Vulnerability Management / Scan Operator works closely with security teams, system administrators, and compliance officers to identify security findings, develop remediation strategies, and ensure adherence to federal cybersecurity standards including FISMA, CISA BOD directives, and NIST guidance.

Required Qualifications

  • Conduct and manage regular security vulnerability scans of IAM systems, applications, and databases using industry-standard scanning tools; analyze results and develop remediation plans.
  • Support federal compliance assessments including FISMA, A-123, Binding Operational Directives (BOD), and Safeguards reviews; develop corrective action plans and track remediation efforts.
  • Review and manage Continuous Diagnostics and Monitoring (CDM) scan results; respond to Common Vulnerabilities and Exposures (CVE) data calls within required timeframes.
  • Maintain and update Plans of Action and Milestones (POA&M) in Cyber Security Assessment and Management (CSAM); ensure security findings are accurately tracked from identification through resolution.
  • Monitor and maintain IAM Cybersecurity Framework Risk (CSF) Scorecard rating; notify FSA of any compliance gaps and provide remediation recommendations.
  • Manage IAM security control inheritance statements and ensure Inheritable Controls are properly configured in CSAM for use by other FSA systems.
  • Support Security Event and Incident Management (SEIM) and log management processes; coordinate with FSA Security Operations Centers to ensure proper data collection and real-time monitoring.
  • Verify encryption standards compliance for data-at-rest and data-in-transit, including AES-256, SHA-256, TLS protocols, and FIPS 140 requirements.
  • Track and report on privileged user access, including PIV card issuance, status changes, and security clearance compliance; maintain records of personnel with approved system access.
  • Ensure compliance with federal records management, PII protection, Section 508 accessibility standards, and Technology Business Management (TBM) reporting requirements.

About PingWind

PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity, development, IT infrastructure, supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL.

www.PingWind.com

Our benefits include:

·       Eleven Federal Holidays

·       Paid Time Off accrued each pay period

·       Parental Leave

·       Three medical plan choices with generous employer contribution

·       Dental and Vision Insurance

·       Company paid Short-Term and Long-Term Disability

·       Company paid Life and AD&D Insurance

·       401k with competitive matching and vesting schedule 

·       Continuing education assistance

·       Short Term / Long Term Disability & Life Insurance

·       Medical, Dependent Care and Commuter Flexible Spending Accounts

·       Employee Assistance Program 

·       Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)

·       529 College Savings Plan

·       Legal Insurance 

·       Pet Insurance

Salary Range

$93K-$128K

The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities, education, certifications, experience, as well as internal equity mapping and alignment with market data, or other applicable laws.

Veterans are encouraged to apply

PingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law.

Source: Pingwind careers (Lever)

Similar roles