Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Vulnerability Management / CTEM Specialist to join an embedded security team supporting a large commercial enterprise's transition to a modern Continuous Threat Exposure Management (CTEM) program. This role will lead the implementation of a new CTEM platform, replacing a legacy vulnerability management tool, and will design the surrounding operational processes — from exploitability-based risk scoring and SLA frameworks to exception handling and escalation procedures. The ideal candidate brings 5+ years of experience in vulnerability management or CTEM platform delivery, hands-on integration work with ITSM tools, and the ability to translate technical processes into clear documentation for both technical and executive audiences.
This is a contract position involving a large commercial enterprise in the Financial Services industry. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Responsibilities:
- Lead the implementation of a CTEM platform, migrating from a legacy vulnerability management tool
- Design and configure connectors, scoring/exploitability models, and consolidation logic across scanners and source systems
- Validate data ingestion fidelity across vulnerability scanners and source systems
- Design SLA and exploitability/risk-scoring frameworks
- Build exception and risk-acceptance workflows
- Perform asset/vulnerability de-duplication and inventory reconciliation
- Stand up critical/high-priority vulnerability escalation processes
- Build and validate API-based integrations between the CTEM platform and downstream systems (e.g., ServiceNow)
- Write Python scripts/automation for data tagging, gap analysis, and reporting
- Build role-based dashboards and reporting for analysts, remediation owners, and CISO-level stakeholders
- Develop KPI/metrics frameworks for security operations
- Author platform configuration documentation, runbooks, and policy/SLA documentation
- Support business process mapping and current-state/future-state workflow design
- Develop Target Operating Model (TOM) documentation
Must-Have:
- Experience with Risk-Based Vulnerability Management (RBVM) / CTEM tools and platforms (e.g., Kenna, Zafran, Rapid7, Tenable, Qualys)
- Experience with vulnerability management platforms: connectors, scoring/exploitability models, consolidation logic, ticketing integration
- Experience validating data ingestion fidelity across scanners and source systems
- Experience designing SLA and exploitability/risk-scoring frameworks
- Experience with exception and risk-acceptance process design
- Experience with asset/vulnerability de-duplication and asset inventory reconciliation
- Experience standing up critical/high-priority vulnerability escalation processes
- 5+ years of relevant vulnerability management / cybersecurity consulting experience
- U.S. Citizenship or Permanent Residency; ability to work within the continental U.S.
Preferred / Nice-to-Have:
- API-based system integration and validation testing experience
- Scripting/automation experience (e.g., Python) for data tagging, gap analysis, reporting automation
- Experience with IT Service Management (ITSM) platforms (e.g., ServiceNow) — workflow design and ticket lifecycle automation
- Experience building role-based dashboards/reporting for technical and executive audiences
- Experience developing KPI/metrics frameworks for security operations
- Technical writing experience (platform configuration documentation, runbooks, policy/SLA documentation)
- Business process mapping and current-state/future-state workflow design
- Experience developing Target Operating Model (TOM) documentation
Technical Skills:
- RBVM/CTEM platforms (Zafran, Kenna, Rapid7, Tenable, Qualys)
- Vulnerability scanner integration and API-based connectors
- Exploitability/risk-scoring models
- ITSM platforms (ServiceNow)
- Python scripting/automation
- Dashboarding and reporting tools
Soft Skills:
- Cross-functional stakeholder communication (analysts through executives)
- Technical writing and documentation
- Process design and facilitation
- Ability to work independently within an embedded client team
- Medical — Multiple POS health plan options including an HSA-compatible plan
- Dental — PPO coverage for preventive, basic, and major services
- Vision — Annual exam, frames, lenses, and contact lens allowance
- 401(k) — Employer match up to 5% of eligible compensation
- Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
- PTO — 15–25 days annually based on tenure
- Paid Federal Holidays — All 11 federal holidays observed
Dragonfly AI London, England Office
8-14 Vine Hill, London, United Kingdom, EC1R 5DX



