1

Contract Vulnerability Scanning Jobs in Alabama (NOW HIRING)

... Fixed Term Contract We have an exciting opportunity for a Vulnerability Manager to join a ... Operate and optimise vulnerability scanning platforms (e.g Microsoft Defender Vulnerability ...

Contract to Hire Role Summary Cyber Security Engineer responsible for L2 security event/incident ... Conduct vulnerability scans using Tenable Nessus * Prioritize/analyze findings, coordinate ...

Contract to Hire Role Summary Cyber Security Engineer responsible for L2 security event/incident ... Conduct vulnerability scans using Tenable Nessus * Prioritize/analyze findings, coordinate ...

... contract award.* Duties & Responsibilities * Support planning, scheduling, and execution of cybersecurity assessments and inspections. * Conduct control validation and vulnerability scanning using ...

This requisition is contingent upon contract award.* Duties & Responsibilities * Lead planning ... Hands-on experience with RMF/ATO processes, continuous monitoring, and vulnerability scanning tools.

next page

Showing results 1-20

Contract Vulnerability Scanning information

What is contract vulnerability scanning?

Contract vulnerability scanning refers to the process of hiring third-party professionals or firms to assess and identify security weaknesses in an organization's systems, networks, or applications. The scanning is typically performed on a contractual basis, often as part of compliance requirements or routine security practices. These experts use automated tools and manual techniques to detect vulnerabilities that could be exploited by attackers, providing detailed reports and recommendations for remediation. This approach allows organizations to benefit from specialized expertise without maintaining a full-time, in-house vulnerability scanning team.

What are some common challenges faced by professionals in contract vulnerability scanning roles?

Professionals in Contract Vulnerability Scanning often encounter challenges such as managing tight deadlines, adapting to varied client environments, and ensuring clear communication of technical findings to non-technical stakeholders. They must stay updated with the latest vulnerabilities and scanning tools, as threats and technologies evolve rapidly. Additionally, balancing thoroughness with efficiency is crucial, as clients expect comprehensive reports without significant delays. Collaboration with IT, security, and management teams is also key to ensure that identified vulnerabilities are properly addressed.

What is the difference between Contract Vulnerability Scanning vs Penetration Tester?

AspectContract Vulnerability ScanningPenetration Tester
Primary FocusAutomated identification of security vulnerabilities in systemsManual and automated testing to exploit vulnerabilities and assess security
Tools & TechniquesVulnerability scanners, automated toolsCustom scripts, penetration tools, manual testing
Work EnvironmentTypically performed remotely or on client sites, within security teamsOften on-site, conducting simulated attacks
CertificationsCompTIA Security+, CISSP, CEHOSCP, CEH, GPEN

Contract Vulnerability Scanning involves automated tools to identify security weaknesses, while Penetration Testers perform manual and automated testing to exploit vulnerabilities. Both roles require security certifications but differ in approach and scope, with vulnerability scanning being more automated and penetration testing more hands-on.

What are the key skills and qualifications needed to thrive as a contract vulnerability scanning specialist, and why are they important?

To thrive as a Contract Vulnerability Scanning Specialist, you need expertise in network security, vulnerability assessment methodologies, and a solid understanding of operating systems and protocols, often supported by certifications like CompTIA Security+ or CEH. Proficiency with vulnerability scanning tools such as Nessus, OpenVAS, or Qualys, and familiarity with ticketing and reporting systems are typically required. Attention to detail, analytical thinking, and clear communication are essential soft skills for identifying risks and conveying findings to non-technical stakeholders. These capabilities ensure the accurate detection of security weaknesses and effective risk mitigation for clients or organizations.
What are the most commonly searched types of Vulnerability Scanning jobs in Alabama? The most popular types of Vulnerability Scanning jobs in Alabama are:
What are popular job titles related to Contract Vulnerability Scanning jobs in Alabama? For Contract Vulnerability Scanning jobs in Alabama, the most frequently searched job titles are:
What job categories do people searching Contract Vulnerability Scanning jobs in Alabama look for? The top searched job categories for Contract Vulnerability Scanning jobs in Alabama are:
What cities in Alabama are hiring for Contract Vulnerability Scanning jobs? Cities in Alabama with the most Contract Vulnerability Scanning job openings:
Infographic showing various Contract Vulnerability Scanning job openings in Alabama as of August 2026, with employment types broken down into 1% As Needed, 72% Full Time, 18% Part Time, 1% Temporary, and 8% Contract. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution.

Vulnerability Manager

Amtis

Birmingham, AL โ€ข Hybrid

Other

Re-posted yesterday


Job description

Job Description Vulnerability Manager Hybrid role - Birmingham on site 2-3 days per week 65,000 - 75,000 per annum (DOE) 12Month Fixed Term Contract We have an exciting opportunity for a Vulnerability Manager to join a highperforming Business Change and Technology function on a 12month fixed term salaried contract. Reporting into the Information Security Manager, you will be responsible for managing, maintaining, and continuously improving the vulnerability management programme across a complex enterprise technology estate. This includes the identification, assessment, prioritisation, and remediation tracking of security vulnerabilities across onpremises systems, cloud environments, networks, applications, and endpoint devices.

This role plays a critical part in ensuring the organisation's technology environment remains secure, resilient, and aligned with internal security policies, legal and regulatory requirements, and industry best practice. The Opportunity - Vulnerability Manager Vulnerability Management & Analysis Lead the endtoend vulnerability management lifecycle, including discovery, scanning, validation, prioritisation, reporting, and remediation tracking. Operate and optimise vulnerability scanning platforms (e.g

Microsoft Defender Vulnerability Management, Edgescan, or equivalent). Conduct regular internal and external vulnerability assessments across infrastructure, applications, and cloud environments. Validate and analyse vulnerability data to ensure findings are accurate, contextualised, and relevant to the organisation's operational environment.

Identify and assess critical vulnerabilities and zeroday threats, determining when expedited remediation is required. Assess vulnerability severity based on realworld exploitability, considering threat intelligence, exposure, asset criticality, and compensating controls. Maintain a defensible position on exploitable vs nonexploitable vulnerabilities, clearly documenting risk decisions and rationale.

Assess and articulate business risk based on exploitability, asset value, and threat intelligence. Remediation Coordination Work closely with internal technical teams and thirdparty partners to ensure vulnerabilities are remediated within agreed SLAs and risk tolerances. Develop remediation plans, monitor progress, and escalate highrisk issues where necessary.

Support patch governance activities, ensuring both routine and emergency patching meets security requirements. Security Governance & Compliance Ensure vulnerability management activities align with internal information security policies, standards, and procedures. Support compliance with relevant regulatory and security frameworks (e.g

GDPR, PCI DSS). Produce regular vulnerability risk reports, dashboards, and KPIs for senior stakeholders. Provide evidence and reporting to support audits, penetration tests, and regulatory reviews.

Threat Intelligence & Continuous Improvement Integrate threat intelligence to prioritise remediation of actively exploited or highrisk vulnerabilities. Recommend and drive improvements to tools, processes, automation, and reporting to enhance programme maturity. Stay current with emerging vulnerabilities, zeroday threats, and vendor advisories.

Support incident response activities where vulnerabilities are linked to potential security events. What You'll Bring Proven experience in vulnerability management, cyber security operations, or a related technical security role. Strong handson experience with vulnerability management tooling (e.g

Microsoft Defender Vulnerability Management, Edgescan, or similar). Solid understanding of cloud platforms (Azure), operating systems (Windows, Linux), networking, and enterprise technologies. Strong knowledge of CVSS scoring, exploit analysis, and riskbased prioritisation.

Experience working in large, complex enterprise environments. Familiarity with regulatory and compliance requirements relevant to vulnerability management. Knowledge of SIEM, SOAR, EDR, and associated security tooling.

Strong analytical skills with the ability to translate technical risk into clear, executivelevel reporting. Experience supporting incident response and investigations. Excellent stakeholder management skills, with the confidence to challenge and influence both technical and nontechnical teams.

Strong understanding of patch management processes and operational constraints in businesscritical environments. Able to manage multiple competing priorities and make pragmatic, riskbased decisions. Qualifications Proven handson experience in vulnerability management or cyber security operations.

Demonstrable understanding of security principles, standards, and methodologies. One or more of the following certifications preferred: CISM, CISSP, CEH, CompTIA Security+, CompTIA CySA+, GIAC GVMS


AMTIS logo

About AMTIS

Sourced by ZipRecruiter

Industry

Guided missile and space vehicle manufacturing

Company size

11 - 50 Employees

Headquarters location

Orlando, FL, US

Year founded

2007

Social media