1

Contract Vulnerability Scanning Jobs (NOW HIRING)

This role is responsible for conducting vulnerability scanning and analysis, supporting remediation ... May be requested to work evenings and weekends to meet program and contract needs. Working at SOSi ...

This role is responsible for conducting vulnerability scanning and analysis, supporting remediation ... May be requested to work evenings and weekends to meet program and contract needs. Working at SOSi ...

This role is responsible for conducting vulnerability scanning and analysis, supporting remediation ... May be requested to work evenings and weekends to meet program and contract needs. Working at SOSi ...

Demonstrated experience in supporting vulnerability scanning technologies as an engineer is ... customers contracts. * Complete basic safety and security training to meet the customer ...

... Fixed Term Contract We have an exciting opportunity for a Vulnerability Manager to join a ... Operate and optimise vulnerability scanning platforms (e.g Microsoft Defender Vulnerability ...

SOC Vulnerability Management AESS Lead - Senior

Fairfax, VA · On-site

$105.70K - $143.40K/yr

... upon contract award. Responsibilities * Lead AESS endpoint security scanning and validation ... Ensure vulnerability management activities align with STIGs, IAVMs, RMF requirements, and ...

New

SOC Vulnerability Management ACAS Lead - Senior

Fairfax, VA · On-site

$105.70K - $143.40K/yr

This position is contingent upon contract award. Responsibilities * Lead ACAS scanning operations ... Validate vulnerability findings against STIGs, IAVMs, RMF requirements, and applicable DoD and ARNG ...

New

Senior Vulnerability Engineer W2 Hiring

Columbus, OH

$97.60K - $134.10K/yr

Contract Interview: Phone/Skype The Senior Vulnerability Engineer is a hands-on role responsible ... Experience with vulnerability scanning and exposure management tools (e.g., Rapid7, Wiz) and ...

Senior Vulnerability Engineer W2 Hiring

Dallas, TX

$103.80K - $142.60K/yr

Contract Interview: Phone/Skype The Senior Vulnerability Engineer is a hands-on role responsible ... Experience with vulnerability scanning and exposure management tools (e.g., Rapid7, Wiz) and ...

Risk and Vulnerability Analyst

Chandler, AZ · On-site

$80K - $128K/yr

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Risk and Vulnerability Analyst

Chandler, AZ · On-site

$80K - $128K/yr

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Risk and Vulnerability Analyst

Chandler, AZ · On-site

$80K - $128K/yr

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

next page

Showing results 1-20

Contract Vulnerability Scanning information

See salary details

$12

$17

$22

How much do contract vulnerability scanning jobs pay per hour?

As of Jun 1, 2026, the average hourly pay for contract vulnerability scanning in the United States is $17.25, according to ZipRecruiter salary data. Most workers in this role earn between $15.38 and $18.51 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Contract Vulnerability Scanning Specialist, and why are they important?

To thrive as a Contract Vulnerability Scanning Specialist, you need expertise in network security, vulnerability assessment methodologies, and a solid understanding of operating systems and protocols, often supported by certifications like CompTIA Security+ or CEH. Proficiency with vulnerability scanning tools such as Nessus, OpenVAS, or Qualys, and familiarity with ticketing and reporting systems are typically required. Attention to detail, analytical thinking, and clear communication are essential soft skills for identifying risks and conveying findings to non-technical stakeholders. These capabilities ensure the accurate detection of security weaknesses and effective risk mitigation for clients or organizations.

What are some common challenges faced by professionals in Contract Vulnerability Scanning roles?

Professionals in Contract Vulnerability Scanning often encounter challenges such as managing tight deadlines, adapting to varied client environments, and ensuring clear communication of technical findings to non-technical stakeholders. They must stay updated with the latest vulnerabilities and scanning tools, as threats and technologies evolve rapidly. Additionally, balancing thoroughness with efficiency is crucial, as clients expect comprehensive reports without significant delays. Collaboration with IT, security, and management teams is also key to ensure that identified vulnerabilities are properly addressed.

What is contract vulnerability scanning?

Contract vulnerability scanning refers to the process of hiring third-party professionals or firms to assess and identify security weaknesses in an organization's systems, networks, or applications. The scanning is typically performed on a contractual basis, often as part of compliance requirements or routine security practices. These experts use automated tools and manual techniques to detect vulnerabilities that could be exploited by attackers, providing detailed reports and recommendations for remediation. This approach allows organizations to benefit from specialized expertise without maintaining a full-time, in-house vulnerability scanning team.

What is the difference between Contract Vulnerability Scanning vs Penetration Tester?

AspectContract Vulnerability ScanningPenetration Tester
Primary FocusAutomated identification of security vulnerabilities in systemsManual and automated testing to exploit vulnerabilities and assess security
Tools & TechniquesVulnerability scanners, automated toolsCustom scripts, penetration tools, manual testing
Work EnvironmentTypically performed remotely or on client sites, within security teamsOften on-site, conducting simulated attacks
CertificationsCompTIA Security+, CISSP, CEHOSCP, CEH, GPEN

Contract Vulnerability Scanning involves automated tools to identify security weaknesses, while Penetration Testers perform manual and automated testing to exploit vulnerabilities. Both roles require security certifications but differ in approach and scope, with vulnerability scanning being more automated and penetration testing more hands-on.

More about Contract Vulnerability Scanning jobs
What cities are hiring for Contract Vulnerability Scanning jobs? Cities with the most Contract Vulnerability Scanning job openings:
What are the most commonly searched types of Vulnerability Scanning jobs? The most popular types of Vulnerability Scanning jobs are:
What states have the most Contract Vulnerability Scanning jobs? States with the most job openings for Contract Vulnerability Scanning jobs include:
What job categories do people searching Contract Vulnerability Scanning jobs look for? The top searched job categories for Contract Vulnerability Scanning jobs are:
Infographic showing various Contract Vulnerability Scanning job openings in the United States as of May 2026, with employment types broken down into 2% As Needed, 96% Full Time, and 2% Contract. Highlights an 86% Physical, 13% Hybrid, and 1% Remote job distribution, with an average salary of $35,880 per year, or $17.2 per hour.

Risk and Vulnerability Analyst II

SOSi

Washington, DC

Full-time

Posted 10 days ago


Job description

Company Description

Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Job Description

Overview
SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible for conducting vulnerability scanning and analysis, supporting remediation efforts, maintaining scan operations, and helping improve enterprise visibility into security weaknesses and cyber risk.
 

Responsibilities

  Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure

  Analyze vulnerabilities and support development of remediation recommendations

  Support cloud compliance scans and assessment activities

  Troubleshoot scan issues and support maintenance of vulnerability scanning tools, consoles, and configurations

  Support automated and scheduled scanning activities, including scan planning, execution, and reporting

  Support ad hoc or emergency vulnerability scanning in support of incident investigation and response activities

  Create and maintain scan reports, data feeds, scan policies, repositories, and user access/roles for assessment tools

  Support API discovery and scanning, and integration of assessment data into third-party tools

  Coordinate with cyber defense engineering and system teams to support tool operations, testing, and vulnerability management activities

Qualifications

  Experience:

  • Three (3) to five (5) years of security-related experience
  • Experience with operating system, database, and web application vulnerability scanning
  • Experience supporting cloud compliance scanning
  • Experience troubleshooting vulnerability scan tools and scan configurations
  • Experience with automation supporting vulnerability assessment operations
  • Experience supporting Information System Vulnerability Management (ISVM) scans and compliance activities
  • Experience with API discovery and security scanning

  Education:

  • Bachelor's Degree
  • Clearance/Suitability: Secret (eligible)
Additional Information

Work Environment

  • Normal office conditions with potential to perform duties in deployed locations.
  • Core hours of operation are Monday through Friday, 0600 - 1700.
  • May be requested to work evenings and weekends to meet program and contract needs.

Working at SOSi

All interested individuals will receive consideration and will not be discriminated against for any reason.