HimalayasHimalayas logo
LeidosLE

Vulnerability Management Engineer

Leidos is an American defense, aviation, information technology, and biomedical research company that provides scientific, engineering, systems integration, and technical services to government and commercial customers.

Leidos

Employee count: 5000+

Salary: 87k-157k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

The Vulnerability Management Engineer- Mid supports SEC ISS contractobjectivesbyidentifying, prioritizing, and driving remediation of security vulnerabilities across enterprise infrastructure and cloud-connected environments. This role strengthens SEC risk posture by aligning vulnerability management activities with NIST and FISMA requirements, including support for audit readiness and continuous monitoring outcomes. The engineer works across operations, engineering, and system owner teams to reduce exposure throughtimelypatching, hardening, and POA&M closure. This position also delivers clear reporting to leadership and contributes to incident response for vulnerability-related events.

PRIMARY RESPONSIBILITIES:

Vulnerability Assessment and Analysis

- Perform recurring vulnerability assessments across servers, endpoints, network devices, and relevant cloud-hosted assets using approved scanning tools.

- Analyze scan results for severity, exploitability, asset criticality, and business impact to prioritize remediation actions.

-Validatefindings byidentifyingfalse positives, duplicates, and exceptions tomaintainaccuraterisk data.

-Maintainvisibility of open vulnerabilities and aging risk across the enterprise environment.

-May require participation in on-call or surge support activities depending on operational needs.

Remediation Coordination and Risk Reduction

- Coordinate with system owners, engineering teams, and operations staff to executetimelyremediation plans.

- Track and manage Plans of Action and Milestones (POA&Ms) through resolution, including status updates and risk disposition.

- Support patch management and secure configuration hardening activities aligned to approved baselines and SOPs.

-Identifyrecurring root causes and recommend control improvements to reduce reintroduction of vulnerabilities.

Governance, Compliance, and Process Management

- Develop,maintain, and improve vulnerability management policies, procedures, and standard operating processes.

- Support risk management and compliance efforts by producing documentation and artifacts for FISMA-related reviews and audits.

- Ensure vulnerability and remediation activities are documented in approved ticketing/workflow systemsin accordance withservice management practices.

- Collaborate with stakeholders to align vulnerability operations with contract governance, reporting cadence, and controlobjectives.

Reporting and Incident Support

- Generate dashboards and reports for leadership on vulnerability trends, remediation progress, POA&M status, and compliance posture.

- Communicate technical findings and remediation priorities to both technical and non-technical stakeholders.

- Support incident response activities tied to discovered or exploited vulnerabilities, including triage and cross-team coordination.

- Provide metric-driven recommendations to improve continuous monitoring effectiveness and risk reduction outcomes.

REQUIRED QUALIFICATIONS:

  • This position is restricted to U.S. citizens only. Applicants must not hold dual citizenship with any other country to be eligible for work under this contract.

  • The ability to obtain andmaintainSEC Public Trust (or higher ifrequired).

  • Bachelor's degree with 4+ years of experience in vulnerability management and remediation within enterprise IT environments.

  • Strong understanding of security frameworks, risk assessment methodologies, and compliance standards, including NIST and FISMA.

  • Experience coordinating remediation with system owners and technical teams, including vulnerability tracking and POA&M closure.

  • Strong analytical, problem-solving, and technical communication skills for mixed technical and business audiences.

  • Vulnerability scanning and assessment platforms (e.g., Tenable Nessus, Qualys, Rapid7).

  • Patch management processes, configuration baselines, and secure system hardening practices.

  • Knowledge of enterprise infrastructure, operating systems, and cloud environments.

  • Familiarity with automation scripts for vulnerability remediation and reporting.

  • Reporting and dashboard development for compliance and leadership visibility.

PREFERRED QUALIFICATIONS:

  • Experience supporting federal civilian agency environments with FISMA/RMF continuous monitoring requirements.

  • Demonstratedsuccess reducing high-severity vulnerability backlog and improving closure timelines in large enterprises.

  • Experience integrating vulnerability management activities with SOC operations and incident response workflows.

  • Experience building automated remediation/reporting workflows using enterprise automation and analytics tools.

  • Advanced cybersecurity certification progression (e.g., CISSP, GIAC, or equivalent) beyond baseline requirements.

  • CompTIA Security+, CEH, CISSP Associate.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

April 23, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 87k-157k USD

Education

Bachelor degree

Experience

4 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About Leidos

Learn more about Leidos and their company culture.

View company profile

Leidos' story begins in 1969 when Dr. J. Robert Beyster, a visionary scientist, founded Science Applications Incorporated (SAI) in La Jolla, San Diego, California. With a modest investment and a powerful idea, Dr. Beyster embarked on a journey to apply scientific expertise to solve complex problems. The company's early days were marked by a focus on research and engineering, tackling challenges for various government and commercial clients. One of its initial significant projects involved studying radiation-based cancer therapy for the Los Alamos National Laboratory, which laid the groundwork for Leidos' future health business. SAI soon expanded its reach, opening an office in Albuquerque to support the Air Force Weapons Laboratory's work on electromagnetic phenomena, a precursor to the company's Physical Science Group.

Throughout the 1980s, the company, then known as Science Applications International Corporation (SAIC), strategically shifted its focus towards national security and defense, solidifying its position as a key government services provider. This era set the stage for substantial growth and diversification. The 1990s saw SAIC continue to expand its offerings and international presence, securing its first major global contract with the Kuwaiti Defense Forces. A pivotal moment arrived in 2013 when SAIC underwent a significant transformation, splitting into two independent, publicly traded companies: a new company retaining the SAIC name and the original company, which was rebranded as Leidos (a name derived from 'kaleidoscope'). Leidos, as the legal successor to the original SAIC, inherited its pre-2013 stock price and corporate filing history and established its new headquarters in Reston, Virginia. This strategic move allowed Leidos to sharpen its focus on national security, health, and engineering solutions. Another major milestone occurred in August 2016 when Leidos merged with Lockheed Martin's Information Systems & Global Solutions (IS&GS) business, a landmark transaction that created the defense industry's largest IT services provider and significantly expanded Leidos' capabilities and market share. Today, Leidos stands as a Fortune 500® global science and technology leader, employing approximately 47,000 people worldwide and generating billions in annual revenue, committed to making the world safer, healthier, and more efficient through innovation and technology.

Employee benefits

Learn about the employee benefits and perks provided at Leidos.

View benefits

Paid sick days

Leidos offers paid sick days.

Health Insurance

Leidos offers health insurance.

Dental Insurance

Leidos offers dental insurance.

Vision Insurance

Leidos offers vision insurance.

View Leidos's employee benefits
Claim this profileLeidos logoLE

Leidos

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

107 remote jobs at Leidos

Explore the variety of open remote roles at Leidos, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Leidos

Remote companies like Leidos

Find your next opportunity by exploring profiles of companies that are similar to Leidos. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan