> Markdown version of [/jobs/ext/1215749-senior-vulnerability-management-engineer-tenable-active-secret-clearance](https://www.wearedevelopers.com/jobs/ext/1215749-senior-vulnerability-management-engineer-tenable-active-secret-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Vulnerability Management Engineer (Tenable) - Active Secret clearance - **Company:** THE PODMILSAK GROUP, INC. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $145,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Systems Engineering, JIRA, Microsoft Azure, Bash Shell, Ubuntu (Operating System), CentOS, Linux, Domain Name System (DNS), Python (Programming Language), Automation of Marketing, Windows Servers, Routing, Windows PowerShell, Red Hat Enterprise Linux, Security Information and Event Management, TCP/IP, Virtual Local Area Networks, VMware VSphere, Software Vulnerability Management, Cloud Platform System, Mttr, SC Clearance, Patch Management, Nessus, CIS Benchmarks, Api Design, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9bcae1fe2cf8142b ## About the Role * 7+ years of cybersecurity engineering, vulnerability management, or systems engineering experience. * Experience supporting Federal Government or DoD environments (5+ years preferred). * Active Secret Clearance (TS/SCI preferred). * Deep experience administering: * + Tenable.sc + Tenable Vulnerability Management + Nessus + Nessus Agents * Strong understanding of vulnerability management lifecycle and remediation processes. * Experience with: * + CVSS scoring + Known Exploited Vulnerabilities (KEV) + Patch management + STIG compliance scanning + False-positive validation * Working knowledge of: * + Windows Server + Linux (RHEL, CentOS, Ubuntu) + VMware vSphere + AWS and/or Azure + Enterprise networking (TCP/IP, DNS, VLANs, routing, switching) Compliance Experience Experience supporting one or more of the following: * NIST SP 800-53 * Risk Management Framework (RMF) * DISA STIGs and SRGs * CMMC * CIS Benchmarks * DoD 8570 / 8140 requirements Preferred Skills * PowerShell, Python, or Bash scripting * Tenable API development and automation * ServiceNow or Jira integration * SIEM and SOAR platforms * Executive reporting and security metrics * Experience improving vulnerability remediation processes and reducing MTTR ## Description PGTEK is seeking an experienced Senior Vulnerability Management Engineer to lead the engineering and administration of enterprise Tenable vulnerability management solutions supporting a large Department of Defense program. This is a hands-on engineering role responsible for designing, deploying, optimizing, and maintaining the full Tenable platform while driving vulnerability remediation efforts across enterprise and classified environments. You'll work closely with cybersecurity teams, system administrators, ISSOs, and government stakeholders to improve the organization's overall security posture. As the program grows, this position offers the opportunity to take on technical leadership responsibilities and mentor junior engineers. Responsibilities * Administer and optimize the full Tenable platform, including: * + Tenable.sc + Tenable Vulnerability Management (formerly Tenable.io) + Nessus + Nessus Agents * Perform authenticated and unauthenticated vulnerability scans across Windows, Linux, network, and cloud environments. * Analyze vulnerability data, validate findings, eliminate false positives, and prioritize remediation efforts based on risk. * Coordinate remediation activities with infrastructure, networking, and application teams through closure. * Manage scan schedules, repositories, credentials, scan zones, and agent deployments. * Troubleshoot scanning issues, credential failures, performance bottlenecks, and platform health. * Develop executive dashboards, compliance reports, and security metrics. * Support RMF continuous monitoring, POA&M management, and audit activities. * Integrate Tenable with ServiceNow, SIEM, asset management, and automation platforms. * Develop automation using PowerShell, Python, Bash, and Tenable APIs. * Recommend system hardening improvements and security best practices. * Provide technical mentorship to junior engineers and vulnerability analysts. * Support security investigations and incident response activities requiring vulnerability analysis. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)