Skip to main content
U.S. flag
Back to results
 

National Vulnerability Database Program Manager

Department of Commerce
National Institute of Standards and Technology
Information Technology Laboratory

Summary

Join NIST as the National Vulnerability Database (NVD) Program Manager! You'll lead teams and software infrastructure while collaborating with global stakeholders to evolve vulnerability management standards. Identify ecosystem gaps and develop new technical guidelines and capabilities to strengthen our national cybersecurity posture.

This notice is issued under direct-hire authority to recruit new talent to occupations for which NIST has a severe shortage of candidates.

Overview

Help
Accepting applications
Open & closing dates
05/07/2026 to 05/13/2026
Salary
$121,785 - $187,093 per year

For ZP-V: $169,279.00 to $197,200.00

Pay scale & grade
ZP 4 - 5
Location
1 vacancy in the following location:
Gaithersburg, MD
Remote job
No
Telework eligible
Yes—as determined by the agency policy.
Travel Required
25% or less - Occasional travel to attend domestic and international conferences, engage in scientific collaborations, participate in facility sharing, and attend professional training.
Relocation expenses reimbursed
No
Appointment type
Permanent
Work schedule
Full-time
Service
Competitive
Promotion potential
5
Job family (Series)
Supervisory status
No
Security clearance
Not Required
Drug test
No
Position sensitivity and risk
Non-sensitive (NS)/Low Risk
Trust determination process
Financial disclosure
No
Bargaining unit status
No
Announcement number
ITL-773-26-12953248-DH
Control number
868077100

Videos

Duties

Help

ZP-IV: National Vulnerability Database Program Manager:

As the National Vulnerability Database (NVD) Program Manager, you will lead information security projects and technical teams with limited oversight to support NIST's cybersecurity mission.

  • Manage the NVD and its associated software infrastructure, overseeing project lifecycles and technical teams to ensure operational excellence.
  • Interact with relevant stakeholder groups to anticipate and determine the needs of end users, planning and implementing new capabilities as required.
  • Support the ongoing development of global standards, including CVSS, CVE, and CPE, through active participation in international standards organizations.
  • Identify deficiencies in the existing vulnerability management ecosystem to suggest and develop new capabilities and technical guidelines.

ZP-V: National Vulnerability Database Program Manager:

As the National Vulnerability Database (NVD) Program Manager, you will provide expert leadership and strategic direction for the NVD portfolio and serve as a primary authority on vulnerability management standards.
  • Define program goals and exercise wide latitude to influence the national security posture and the broader vulnerability management portfolio.
  • Coordinate with high-level stakeholders to identify complex end-user requirements and plan the integration of next-generation capabilities.
  • Influence and drive the development of standards (e.g., CVSS, CVE, CPE) through leadership roles and high-impact contributions within standards-developing organizations.
  • Architect new NIST-developed guidelines and national-level capabilities by identifying and addressing critical gaps in the vulnerability management ecosystem.

Requirements

Help

Conditions of employment

  • U.S. citizenship
  • Males born after 12-31-59 must be registered for Selective Service
  • Suitable for Federal employment
  • Bargaining Unit Position: No

Qualifications

Basic Requirements:
Bachelor's degree in computer science or bachelor's degree with 30 semester hours in a combination of mathematics, statistics, and computer science. At least 15 of the 30 semester hours must have included any combination of statistics and mathematics that includes differential and integral calculus. All academic degrees and coursework must be from accredited or pre-accredited institutions.

For the ZP-IV: In addition to the above basic requirements, all applicants must have one year (52 weeks) of specialized experience equivalent to at least the GS-12 level (ZP-III at NIST). The specialized experience is defined as:

  • Experience working with vulnerability management identifiers and specifications such as CVE, CVSS, CPE, and CWE.
  • Experience with CPE, Product-URL, SBOM, SWID, or different mechanisms of representing or modeling vulnerability information.
  • Experience working with or in standards development to produce standards.

For the ZP-V: In addition to the above basic requirements, all applicants must have one year (52 weeks) of specialized experience equivalent to at least the GS-14 level (ZP-IV at NIST). The specialized experience is defined as:
  • Experience managing software projects.
  • Experience leading the implementation of vulnerability identifiers and specifications (e.g., CVE, CVSS, CPE, CWE).
  • Experience leading and implementing the use of SBOM, CPE, SWID, Product-URL, or other vulnerability information modeling mechanisms based on a critical evaluation of their benefits and limitations.
  • Experience spearheading initiatives within standards development to produce and ratify new standards.

Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional, philanthropic, religious, spiritual, community, student, social). Volunteer work helps build critical competencies, knowledge, and skills, and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.

The qualification requirements in this vacancy announcement are based on the U.S. Office of Personnel Management (OPM) Qualification Standards Handbook.

If requesting reconsideration of your qualification determination, please refer to the following site: Applicant Reconsideration

Education

This position has an education requirement. Transcripts must be submitted to validate that the education requirement has been met. Unofficial transcripts will be accepted in the application package. However, an official copy will be required before a final offer of employment.

Use of foreign education for qualifications. An accredited organization must evaluate education completed outside of the U.S. to ensure that it is comparable to education received in accredited institutions in the U.S. Click here to view a listing of accredited organizations from the Department of Education's website. A copy of the foreign education evaluation (containing the results with a course-by-course listing) is required with your application.

Additional information

This position is covered under NIST's Alternative Personnel Management System (APMS), a pay-for-performance system with excellent HR flexibilities to help NIST recruit and retain top talent. Learn more about the APMS here!

  • We may share your application package with other selecting officials. Additional selections may be made through this vacancy.
  • Click all links in this vacancy announcement to view additional information or instructions.
  • You MUST select at least ONE ELIGIBILITY to be considered for this position.
  • All documents submitted for this announcement must be legible to make qualification or eligibility determinations.
  • A probationary period may be required.
NIST strives to build a flexible and encouraging work environment to bring out the best in our employees. To help our employees balance responsibilities at home and at work, NIST offers a variety of work-life flexibilities. For more information, please visit our Careers website.

Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.

How you will be evaluated

You will be evaluated for this job based on how well you meet the qualifications above.

Please prepare a resume that is no longer than two pages; only the first two pages will be considered during the review process. Ensure your font is 11 points or larger and upload your resume as a .pdf document. This helps ensure your formatting looks exactly the way you intended.

How you will be evaluated: You will be evaluated for this job based on how well you meet the qualifications above. Once the announcement has closed, a review of your resume and supporting documentation will be used to determine whether you meet the qualification requirements listed in this announcement. Overstating your qualifications and/or experience in your application materials or application questionnaire may result in your removal from consideration.

Subject Matter Experts (SMEs) may be used to review your resume to determine your technical qualifications for this position based on the required specialized experience. SMEs will review ONLY two (2) pages of your resume. SMEs will not review additional information beyond your resume.

Applications will be assessed on the following competencies:

  • Oral Communication
  • Project Management
  • Requirements Analysis
  • Vulnerabilities Assessment
  • Written Communication


Referral: All applicants may be referred to the selecting official for consideration. Under Direct Hire Authority, applicants are not rated and ranked, and veteran preference does not apply.

CTAP or ICTAP eligibility: If you are a displaced or surplus Federal employee eligible for the Career Transition Assistance Plan (CTAP) or Interagency Career Transition Assistance Plan (ICTAP), you must be determined eligible and rated as well-qualified to receive special selection priority. "Well Qualified" means that, in addition to meeting the minimum qualification requirements and selective placement factor(s), if applicable, you must receive a score of 85 or higher. Please review the following site regarding required documents to support CTAP or ICTAP eligibility and additional information regarding this authority - Section 8: Hiring Paths at NIST | NIST

National Institute of Standards and Technology

NIST works with industry and science to advance innovation and improve quality of life.

Agency contact information

Tiffani Brown
Email
tiffani.brown@nist.gov
Address
Computer Security Division
100 Bureau Drive
Gaithersburg, MD 20899
US

Visit our careers page

Learn more about what it's like to work at National Institute of Standards and Technology, what the agency does, and about the types of careers this agency offers.

https://www.nist.gov/careers

Your session is about to expire!

Your USAJOBS session will expire due to inactivity in 8 minutes. Any unsaved data will be lost if you allow the session to expire. Click the button below to continue your session.