Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Vulnerability Management / CTEM Specialist to join an embedded security team supporting a large commercial enterprise's transition to a modern Continuous Threat Exposure Management (CTEM) program. This role will lead the implementation of a new CTEM platform, replacing a legacy vulnerability management tool, and will design the surrounding operational processes — from exploitability-based risk scoring and SLA frameworks to exception handling and escalation procedures. The ideal candidate brings 5+ years of experience in vulnerability management or CTEM platform delivery, hands-on integration work with ITSM tools, and the ability to translate technical processes into clear documentation for both technical and executive audiences.
This is a contract position involving a large commercial enterprise in the Financial Services industry. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Responsibilities:
Lead the implementation of a CTEM platform, migrating from a legacy vulnerability management tool
Design and configure connectors, scoring/exploitability models, and consolidation logic across scanners and source systems
Validate data ingestion fidelity across vulnerability scanners and source systems
Design SLA and exploitability/risk-scoring frameworks
Build exception and risk-acceptance workflows
Perform asset/vulnerability de-duplication and inventory reconciliation
Stand up critical/high-priority vulnerability escalation processes
Build and validate API-based integrations between the CTEM platform and downstream systems (e.g., ServiceNow)
Write Python scripts/automation for data tagging, gap analysis, and reporting
Build role-based dashboards and reporting for analysts, remediation owners, and CISO-level stakeholders
Develop KPI/metrics frameworks for security operations
Author platform configuration documentation, runbooks, and policy/SLA documentation
Support business process mapping and current-state/future-state workflow design
Develop Target Operating Model (TOM) documentation
Must-Have:
Experience with Risk-Based Vulnerability Management (RBVM) / CTEM tools and platforms (e.g., Kenna, Zafran, Rapid7, Tenable, Qualys)
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the US.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast!
Find the best jobs in the US, apply in 1 click and get a job today!