1

Contract Vulnerability Analyst Jobs in Rochester, NY

Cyber Security Tutor

Rochester, NY · Remote

$18 - $40/hr

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...

Contract Vulnerability Analyst information

See Rochester, NY salary details

$30.6K

$72.3K

$128.3K

How much do contract vulnerability analyst jobs pay per year?

As of Aug 30, 2026, the average yearly pay for contract vulnerability analyst in Rochester, NY is $72,284.00, according to ZipRecruiter salary data. Most workers in this role earn between $51,800.00 and $85,800.00 per year, depending on experience, location, and employer.

What is a contract vulnerability analyst?

A Contract Vulnerability Analyst is a cybersecurity professional who is hired on a contractual basis to identify, assess, and report security vulnerabilities within an organization's systems, networks, or applications. Their main role is to help companies find and address security weaknesses before attackers can exploit them. They often use various tools and methodologies to conduct vulnerability assessments, penetration testing, and security audits. Contract Vulnerability Analysts typically work for a set period or on a specific project, providing expert guidance to enhance the organization's security posture.

What are the key skills and qualifications needed to thrive as a contract vulnerability analyst, and why are they important?

To thrive as a Contract Vulnerability Analyst, you need a strong background in cybersecurity principles, vulnerability assessment methodologies, and relevant certifications such as CEH or CompTIA Security+. Familiarity with vulnerability scanning tools like Nessus, Qualys, or OpenVAS, as well as experience with common operating systems and network protocols, is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts effectively identify, prioritize, and report vulnerabilities to stakeholders. These skills are crucial for ensuring organizational security and compliance while minimizing risk in dynamic contract-based environments.

What are some common challenges faced by contract vulnerability analysts, and how can they overcome them?

Contract Vulnerability Analysts often face challenges such as rapidly changing threat landscapes and the need to quickly adapt to new security vulnerabilities in client environments. They must balance multiple client projects and prioritize tasks based on risk and impact. Success in this role requires strong communication skills to clearly explain technical findings to non-technical stakeholders and collaborate with both internal security teams and client IT departments. Building efficient workflows, staying updated with the latest security tools, and participating in regular training can help analysts stay ahead of threats and deliver impactful results.

What is the difference between Contract Vulnerability Analyst vs Security Analyst?

AspectContract Vulnerability AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA
Work EnvironmentContract-based, project-specific roles, often remote or on-siteFull-time, in-house or remote security teams within organizations
Industry UsageIT security firms, consulting companies, tech organizationsCorporate, government, financial institutions
Search & Comparison IntentFocus on vulnerability assessment, penetration testing, security gapsBroader security management, incident response, policy enforcement

The Contract Vulnerability Analyst primarily focuses on identifying and mitigating security vulnerabilities through assessments and testing, often working on a contractual basis. In contrast, a Security Analyst typically handles ongoing security monitoring, incident response, and policy implementation within an organization. While both roles require similar certifications and work in the cybersecurity field, their scope and employment structure differ significantly.

What are the most commonly searched types of Vulnerability Analyst jobs in Rochester, NY?

The most popular types of Vulnerability Analyst jobs in Rochester, NY are:

What are popular job titles related to Contract Vulnerability Analyst jobs in Rochester, NY?

For Contract Vulnerability Analyst jobs in Rochester, NY, the most frequently searched job titles are:

What job categories do people searching Contract Vulnerability Analyst jobs in Rochester, NY look for?

The top searched job categories for Contract Vulnerability Analyst jobs in Rochester, NY are:

What cities near Rochester, NY are hiring for Contract Vulnerability Analyst jobs?

Cities near Rochester, NY with the most Contract Vulnerability Analyst job openings:

Infrastructure Systems Administrator (NOT REMOTE) - Fairport NY

Datrose, Inc

Fairport, NY

$36 - $43/hr

Contractor

Posted 11 days ago


Job description

**This is a Hybrid position based out of the Fairport, New York Office**

Position Summary:

The Infrastructure Systems Administrator is responsible for supporting, securing, and continuously improving the company's hybrid technology environment, including server, cloud, endpoint, telephony, and data protection platforms. Working under the direction of the Assistant VP, Network Operations, this position helps ensure the availability, reliability, scalability, security, and recoverability of the company's Information Technology infrastructure.
LOCATION: Fairport, NY office IN-PERSON at first (hybrid once trained)
SHIFT: Day time schedule, with possible on-call coverage rotation
DURATION: Contract to Hire potential (contract could be up to 1 yr) W-2 Only, no 1099 permitted.
PAY RANGE: $36-43/hr - depending on experience

Essential Duties & Responsibilities:
*    Install, configure, administer, secure, and optimize network, server, storage, endpoint, application, cloud, collaboration, and IP telephony systems across on-premises and cloud-hosted environments
*    Administer and support modern identity, access, and collaboration platforms, including Active Directory, Microsoft 365, Microsoft Entra ID
*    Support hybrid cloud infrastructure, including virtual machines, storage, networking, backups, and monitoring
*    Identify, prioritize, troubleshoot, and resolve reported problems including voice, network, identity, endpoint, server, cloud, security, application, and service desk issues
*    Apply modern cybersecurity practices, including vulnerability remediation, patch management, endpoint protection, logging, alerting, security monitoring, privileged access controls, and incident response support
*    Evaluate, recommend, and implement enhancements and operating procedures that optimize network and system reliability, performance, scalability, recoverability, and survivability
*    Assist in the design, planning, and implementation of information systems, network growth, cloud adoption, hybrid connectivity, wireless infrastructure, and secure remote access solutions
*    Configure, maintain, test, and document backup, restoration, snapshot, imaging, replication, and disaster recovery procedures
*    Assist with tier I and II service desk coverage, escalation support, incident resolution, and user enablement
*    Prepare and maintain accurate documentation
*    Adhere to the company's Professional Practices Management System (PPMS), Code of Conduct, Compliance Program, information security requirements, and applicable client or regulatory obligations
Education:
*    High School Diploma or GED
*    Bachelor's Degree in IT, Computer Science or related field or equivalent combination of education and IT experience
Skills/Requirements:
*    Five+ (5) years of IT infrastructure, network, systems, cloud, or security administration experience
*    Three+ (3) years of Network and Systems Administration experience supporting enterprise or regulated environments
*    Demonstrated ability to administer Windows-based networks, Windows Server, Active Directory, Group Policy, DNS, DHCP, file/print services, certificate services, and related enterprise services
*    Working knowledge of Microsoft 365, Microsoft Entra ID/Azure Active Directory, Exchange Online, SharePoint/OneDrive
*    Experience with virtualization, storage, backups, replication, snapshots, disaster recovery, and business continuity technologies
*    Knowledge of cybersecurity best practices including vulnerability management, patch management, endpoint protection, logging, alerting, incident response support, and security hardening
*    Ability to multitask and collaborate effectively with IT, security, compliance, vendors, and business stakeholders while maintaining a strong focus on results and service quality
*    Ability to act independently to resolve problems, perform root cause analysis, document findings, and recommend preventive action
*    Must be able to provide on-call support on a rotating basis
*    Must be able to work IN-PERSON at the office location 3-5 days a week, hybrid may be an option once training is completed.
*    Ability to travel between the company's offices as needed
*    U.S. Citizenship or lawful Permanent Resident alien with three or more years as a permanent resident in the United States.
*    Ability to obtain and maintain Government Security Clearance
*    No conflicts of interest with the company or its Clients
Datrose is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, pregnancy, status as a parent, age, protected veteran status, family medical history or genetic information, political affiliation, status as a qualified individual with disability, or other non-merit-based factors.
 
U.S. Citizenship or lawful Permanent Resident alien with three or more years as a permanent resident in the United States is a requirement for this position.