1

Contract Vulnerability Analyst Jobs (NOW HIRING)

This position is contingent upon contract award *** Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our ...

This position is contingent upon contract award *** Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our ...

Showing results 21-40

Contract Vulnerability Analyst information

See salary details

$31K

$73.3K

$130K

How much do contract vulnerability analyst jobs pay per year?

As of Sep 6, 2026, the average yearly pay for contract vulnerability analyst in the United States is $73,261.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,500.00 and $87,000.00 per year, depending on experience, location, and employer.

What is a contract vulnerability analyst?

A Contract Vulnerability Analyst is a cybersecurity professional who is hired on a contractual basis to identify, assess, and report security vulnerabilities within an organization's systems, networks, or applications. Their main role is to help companies find and address security weaknesses before attackers can exploit them. They often use various tools and methodologies to conduct vulnerability assessments, penetration testing, and security audits. Contract Vulnerability Analysts typically work for a set period or on a specific project, providing expert guidance to enhance the organization's security posture.

What are the key skills and qualifications needed to thrive as a contract vulnerability analyst, and why are they important?

To thrive as a Contract Vulnerability Analyst, you need a strong background in cybersecurity principles, vulnerability assessment methodologies, and relevant certifications such as CEH or CompTIA Security+. Familiarity with vulnerability scanning tools like Nessus, Qualys, or OpenVAS, as well as experience with common operating systems and network protocols, is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts effectively identify, prioritize, and report vulnerabilities to stakeholders. These skills are crucial for ensuring organizational security and compliance while minimizing risk in dynamic contract-based environments.

What are some common challenges faced by contract vulnerability analysts, and how can they overcome them?

Contract Vulnerability Analysts often face challenges such as rapidly changing threat landscapes and the need to quickly adapt to new security vulnerabilities in client environments. They must balance multiple client projects and prioritize tasks based on risk and impact. Success in this role requires strong communication skills to clearly explain technical findings to non-technical stakeholders and collaborate with both internal security teams and client IT departments. Building efficient workflows, staying updated with the latest security tools, and participating in regular training can help analysts stay ahead of threats and deliver impactful results.

What is the difference between Contract Vulnerability Analyst vs Security Analyst?

AspectContract Vulnerability AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA
Work EnvironmentContract-based, project-specific roles, often remote or on-siteFull-time, in-house or remote security teams within organizations
Industry UsageIT security firms, consulting companies, tech organizationsCorporate, government, financial institutions
Search & Comparison IntentFocus on vulnerability assessment, penetration testing, security gapsBroader security management, incident response, policy enforcement

The Contract Vulnerability Analyst primarily focuses on identifying and mitigating security vulnerabilities through assessments and testing, often working on a contractual basis. In contrast, a Security Analyst typically handles ongoing security monitoring, incident response, and policy implementation within an organization. While both roles require similar certifications and work in the cybersecurity field, their scope and employment structure differ significantly.

More about Contract Vulnerability Analyst jobs

What cities are hiring for Contract Vulnerability Analyst jobs?

Cities with the most Contract Vulnerability Analyst job openings:

What are the most commonly searched types of Vulnerability Analyst jobs?

The most popular types of Vulnerability Analyst jobs are:

What states have the most Contract Vulnerability Analyst jobs?

States with the most job openings for Contract Vulnerability Analyst jobs include:

Infographic showing various Contract Vulnerability Analyst job openings in the United States as of August 2026, with employment types broken down into 40% Full Time, and 60% Contract. Highlights an 100% In-person job distribution, with an average salary of $73,261 per year, or $35.2 per hour.

Senior Security Vulnerability Analyst

Edgewater Federal Solutions, Inc.

Washington, DC โ€ข On-site

$138K - $141K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 11 days ago


Job description

Overview

We are seeking up to two (2) Security Vulnerability Analysts with experience implementing artificial intelligence (AI) for vulnerability scanning, patch management, risk management, and threat modeling. The ideal candidate will have deep expertise with traditional vulnerability management practices, activities, and technologies. The ideal candidate will also have experience working with a variety of AI technologies and models for vulnerability management. This position will require the development and delivery of AI-enabled vulnerability management processes, tools, and capabilities.

Responsibilities
  • Implement AI-enabled solutions for vulnerability management and adapt existing processes to integrate emerging AI capabilities into standard operations.
  • Provide key requirements, observations, design suggestions, and artifacts to inform the development of AI technologies that will support the adoption of AI technology into the existing vulnerability management program.
  • Analyze the output of AI models designed to detect vulnerabilities in hardware, software and cloud-resident systems and suggest remediation strategies to reduce risk and close gaps.
  • Create, configure, and execute vulnerability scans of Board workstations, servers, and network devices and identify and deliver solutions to integrate AI into existing processes.
  • Abide by all governance and standards as defined by the Board or levied by external entities to remain compliant with all requirements when implementing AI solutions.
  • Develop analytic products and reports that demonstrate the effectiveness of AI-enabled vulnerability management practices to include metrics and technical vulnerability analysis reports.
Qualifications
  • 7+ years of hands-on vulnerability management experience that includes use of technologies such as Tenable Nessus, GitLab vulnerability scanning features, Fortify, Invicti, Mandiant MSV, etc.
  • 5+ years of hands-on vulnerability management experience that includes cloud resident technologies in Amazon Web Services, Microsoft Azure, Service Now, etc.
  • Hands on experience implementing AI solutions for vulnerability management.
  • Experience analyzing data and software to identify vulnerabilities.
  • Experience collaborating with key stakeholders to assess, prioritize, and develop actionable plans to address the discovered gaps.

Preferred Qualifications

  • Experience building consensus around vulnerability management policies and procedures.
  • Demonstrated experience implementing AI-enabled vulnerability management solutions in a hybrid environment.
  • Experience operating in government environments that follow NIST, FISMA, FedRAMP, and OMB guidance.
  • Strong problem-solving and analytical skills
  • Excellent communication and documentation skills

Contract Details

  • Period of Performance: September-December 2026 (with possible extension)
  • Location: On-site at Federal Reserve Board, Washington DC Metro Campus
  • Schedule: Monday-Friday during standard business hours

Salary: $138,811 - $141,896

Additional benefits include:ย 

  • Paid Time Off & Holiday Pay
  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Disability, Life Insurance, and AD&D
  • Flexible Spending Accounts
  • Pre-Tax 401K and/or After-Tax Roth IRA (with employer matching contribution)
  • Tuition and Technical Training Reimbursement
  • Exercise Reimbursement
  • Computer Reimbursement
  • Employee Assistance Program

Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • While performing the duties of this job, the employee may be regularly required to stand, sit, talk, hear, reach, stoop, kneel, and use hands and fingers to operate a computer, telephone, keyboard, and standard office equipment
  • Specific vision abilities required by this job include close vision requirements due to computer work
  • The employee must occasionally lift and/or move up to 15 pounds
  • Fine hand manipulation (keyboarding)

Work Environment:ย  The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job.ย  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Exposure to general office conditions while conducting office duties
  • Moderate noise (i.e., business office with computers, phone, and printers, light traffic)
  • Ability to work in a confined area
  • Ability to sit at a computer terminal for an extended period

Working at Edgewater Federal Solutions:

Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. The company was founded in 2002 with the vision of being highly recognized and admired for supporting customer missions through employee empowerment, exceptional services, and timely delivery. Edgewater Federal Solutions is ISO 9001, 20000-1, 270001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Small Companies since 2018.

ย 

EdgewaterFederal Solutions is an Equal Opportunity Employer. It has been and continues to be our policy to provide equal employment to all employees and applicants for employment without regard to race, color, religion, gender, national origin, age, disability, marital status, veteran status and/or other status protected by applicable law.ย 

Employment Type: FULL_TIME