1

Apprentice Qualys Vulnerability Management Jobs in Reston, VA

Vulnerability Management Lead

Washington, DC · On-site

$116K - $152K/yr

Hands-on proficiency with enterprise vulnerability scanning and management platforms - Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent. * Demonstrated ability to ...

CDM Tech Lead

Bethesda, MD · On-site +1

$140K - $170K/yr

Vulnerability Management (VUL) Tenable Nessus / Tenable.io • Qualys Vulnerability Management (VMDR) • Rapid7 InsightVM • McAfee Vulnerability Manager • OpenVAS (Greenbone) * The CDM Task Lead ...

VULNERABILITY MGMT ANALYST

Falls Church, VA · On-site

$66K - $87K/yr

Working knowledge of vulnerability scanning products such as Rapid7 (preferred), Tenable Security Center/Nessus (ACAS), or Qualys. * Experience with patch management tools such as PDQ Deploy, SCCM ...

New

next page

Showing results 1-20

Apprentice Qualys Vulnerability Management information

See Reston, VA salary details

$12

$22

$38

How much do apprentice qualys vulnerability management jobs pay per hour?

As of Aug 27, 2026, the average hourly pay for apprentice qualys vulnerability management in Reston, VA is $22.91, according to ZipRecruiter salary data. Most workers in this role earn between $18.03 and $25.00 per hour, depending on experience, location, and employer.

What is an apprentice Qualys Vulnerability Management?

An Apprentice Qualys Vulnerability Management professional is someone in an entry-level or learning position focused on identifying, assessing, and managing cybersecurity vulnerabilities using the Qualys platform. They typically assist with scanning IT systems, analyzing vulnerability reports, and collaborating with IT and security teams to help remediate threats. The apprentice role is designed to build foundational skills in vulnerability management, security analysis, and the use of Qualys tools under the guidance of experienced professionals.

What are the key skills and qualifications needed to thrive as an apprentice Qualys Vulnerability Management?

To thrive as an Apprentice Qualys Vulnerability Management, you need a foundational understanding of cybersecurity principles, IT networking, and basic vulnerability assessment, often supported by relevant coursework or certifications like CompTIA Security+. Familiarity with vulnerability management platforms (especially Qualys), ticketing systems, and common operating systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify threats and collaborate with team members. These skills are crucial for accurately detecting vulnerabilities, prioritizing remediation efforts, and supporting the organization's overall security posture.

What are some common challenges faced by an apprentice in Qualys Vulnerability Management, and how can they be addressed?

As an Apprentice in Qualys Vulnerability Management, one common challenge is quickly becoming proficient with the Qualys platform and understanding its various modules. You may also find it challenging to interpret scan results and prioritize remediation efforts while balancing multiple tasks. To address these challenges, actively seek mentorship from experienced team members, participate in formal training sessions, and practice using the platform in a test environment. Regular communication with IT, security, and operations teams will also help you understand business priorities and improve your vulnerability management process.

What is the difference between Apprentice Qualys Vulnerability Management vs Security Analyst?

AspectApprentice Qualys Vulnerability ManagementSecurity Analyst
CertificationsBasic security or vulnerability management certifications, on-the-job trainingAdvanced certifications like CompTIA Security+, CISSP often preferred
Work EnvironmentEntry-level, hands-on with vulnerability scanning tools, supervisedMore independent, analyzing security data, incident response
Industry UsageUsed in organizations with vulnerability management programs, entry-level roleBroader security responsibilities, including threat analysis and policy enforcement

The Apprentice Qualys Vulnerability Management role focuses on learning and executing vulnerability scans using Qualys tools under supervision. In contrast, a Security Analyst has a broader scope, analyzing security threats, managing incidents, and implementing security measures. While both roles require foundational security knowledge, Security Analysts typically hold more advanced certifications and work independently on complex security issues.

What are popular job titles related to Apprentice Qualys Vulnerability Management jobs in Reston, VA?

For Apprentice Qualys Vulnerability Management jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Apprentice Qualys Vulnerability Management jobs in Reston, VA look for?

The top searched job categories for Apprentice Qualys Vulnerability Management jobs in Reston, VA are:

What cities near Reston, VA are hiring for Apprentice Qualys Vulnerability Management jobs?

Cities near Reston, VA with the most Apprentice Qualys Vulnerability Management job openings:

Infographic showing various Apprentice Qualys Vulnerability Management job openings in Reston, VA as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 82% Physical, 2% Hybrid, and 16% Remote job distribution, with an average salary of $47,654 per year, or $22.9 per hour.

Vulnerability Management Lead

K2Share LLC

Washington, DC • On-site

Full-time

Posted 19 days ago


Job description

Description

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.


Our four core values define how we show up every day:

  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients' mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.


Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.


Position Summary 

Own enterprise vulnerability management as a sustained program function - tracking, analysis, prioritization, remediation coordination, and trend reporting across systems, applications, devices, and other in-scope assets. This position converts scan output into risk-informed decisions, drives remediation to closure with system and business stakeholders, and integrates vulnerability data into the broader risk and compliance picture. 


Key Responsibilities 

  • Operate vulnerability management as a sustained enterprise function: identification, documentation, prioritization, monitoring, and closure across all in-scope assets. 
  • Analyze vulnerability data, scan results, remediation status, and related security findings to enable risk-based decision making. 
  • Coordinate remediation with system owners and stakeholders; assist in evaluating remediation actions, timelines, and residual risk. 
  • Identify aging vulnerabilities and recurring or systemic issues; recommend process improvements and risk-reduction measures. 
  • Lead recurring vulnerability review meetings with applicable stakeholders to review status and support remediation planning. 
  • Produce periodic reporting covering severity, age, trend, and system-level status. 
  • Provide monthly vulnerability reporting and an accompanying risk mitigation plan.  Escalate critical and high vulnerabilities to the client's Chief Information Officer and Chief Information Security Officer and drive remediation as rapidly as possible, with POA&Ms established and prioritized by the risks implicated. 
  • Integrate vulnerability management activity into overall risk and compliance support, feeding the POA&M workflow and authorization-boundary tracking maintained by the ISSO/ISCM Lead. 
  • Support risk identification, analysis, tracking, and mitigation related to vulnerabilities, control gaps, and system changes. 

Requirements

  • Bachelor's degree in cybersecurity, information technology, or a related field. Equivalent experience considered in lieu of degree. 
  • Six or more years in vulnerability management, including at least two years leading or coordinating an enterprise vulnerability program. 
  • Hands-on proficiency with enterprise vulnerability scanning and management platforms - Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent. 
  • Demonstrated ability to apply risk-based prioritization beyond raw CVSS, incorporating exploitability, the CISA Known Exploited Vulnerabilities catalog, asset criticality, and compensating controls. 
  • Experience driving remediation across organizational boundaries with system owners who do not report to the vulnerability function. 
  • Experience producing executive-facing vulnerability trend reporting and defensible remediation timelines aligned to federal expectations. 
  • Working knowledge of POA&M processes and NIST vulnerability management controls. 

Preferred Qualifications 

  • Cloud and container vulnerability management experience - Azure and Microsoft 365, AWS, container image scanning. 
  • Experience correlating vulnerability data with SIEM and EDR telemetry to support threat-hunting hypotheses. 
  • Experience with SBOM analysis and the vulnerability implications of supply chain risk. 

Required Certifications 

A relevant cybersecurity certification demonstrating competence in vulnerability management, risk, or operations support. Acceptable examples include CompTIA CySA+, GIAC GEVA or GCIH, a Tenable or Qualys vendor certification, CISSP, or CRISC. 


Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process. 


The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.
 

K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.
 

This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice.