1

Contract Vulnerability Scanning Jobs (NOW HIRING)

Vulnerability Management Lead

Washington, DC ยท On-site

$116K - $152K/yr

Job Type Contract Description K2United is an organization that houses two distinct, national ... This position converts scan output into risk-informed decisions, drives remediation to closure with ...

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Execute vulnerability assessments using industry-standard scanning tools across networks, systems ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Mid-Level Vulnerability Management Engineer

$80K - $105K/yr

  • Medical

  • Retirement

  • PTO

Bachelor's degree in a related field, or equivalent experience as allowed by company and contract policy. * Five or more years of hands-on enterprise vulnerability management and scanning experience.

Showing results 41-60

Contract Vulnerability Scanning information

See salary details

$12

$17

$22

How much do contract vulnerability scanning jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for contract vulnerability scanning in the United States is $17.25, according to ZipRecruiter salary data. Most workers in this role earn between $15.38 and $18.51 per hour, depending on experience, location, and employer.

What is contract vulnerability scanning?

Contract vulnerability scanning refers to the process of hiring third-party professionals or firms to assess and identify security weaknesses in an organization's systems, networks, or applications. The scanning is typically performed on a contractual basis, often as part of compliance requirements or routine security practices. These experts use automated tools and manual techniques to detect vulnerabilities that could be exploited by attackers, providing detailed reports and recommendations for remediation. This approach allows organizations to benefit from specialized expertise without maintaining a full-time, in-house vulnerability scanning team.

What are some common challenges faced by professionals in contract vulnerability scanning roles?

Professionals in Contract Vulnerability Scanning often encounter challenges such as managing tight deadlines, adapting to varied client environments, and ensuring clear communication of technical findings to non-technical stakeholders. They must stay updated with the latest vulnerabilities and scanning tools, as threats and technologies evolve rapidly. Additionally, balancing thoroughness with efficiency is crucial, as clients expect comprehensive reports without significant delays. Collaboration with IT, security, and management teams is also key to ensure that identified vulnerabilities are properly addressed.

What is the difference between Contract Vulnerability Scanning vs Penetration Tester?

AspectContract Vulnerability ScanningPenetration Tester
Primary FocusAutomated identification of security vulnerabilities in systemsManual and automated testing to exploit vulnerabilities and assess security
Tools & TechniquesVulnerability scanners, automated toolsCustom scripts, penetration tools, manual testing
Work EnvironmentTypically performed remotely or on client sites, within security teamsOften on-site, conducting simulated attacks
CertificationsCompTIA Security+, CISSP, CEHOSCP, CEH, GPEN

Contract Vulnerability Scanning involves automated tools to identify security weaknesses, while Penetration Testers perform manual and automated testing to exploit vulnerabilities. Both roles require security certifications but differ in approach and scope, with vulnerability scanning being more automated and penetration testing more hands-on.

What are the key skills and qualifications needed to thrive as a contract vulnerability scanning specialist, and why are they important?

To thrive as a Contract Vulnerability Scanning Specialist, you need expertise in network security, vulnerability assessment methodologies, and a solid understanding of operating systems and protocols, often supported by certifications like CompTIA Security+ or CEH. Proficiency with vulnerability scanning tools such as Nessus, OpenVAS, or Qualys, and familiarity with ticketing and reporting systems are typically required. Attention to detail, analytical thinking, and clear communication are essential soft skills for identifying risks and conveying findings to non-technical stakeholders. These capabilities ensure the accurate detection of security weaknesses and effective risk mitigation for clients or organizations.
More about Contract Vulnerability Scanning jobs

What cities are hiring for Contract Vulnerability Scanning jobs?

Cities with the most Contract Vulnerability Scanning job openings:

What are the most commonly searched types of Vulnerability Scanning jobs?

The most popular types of Vulnerability Scanning jobs are:

What states have the most Contract Vulnerability Scanning jobs?

States with the most job openings for Contract Vulnerability Scanning jobs include:

What job categories do people searching Contract Vulnerability Scanning jobs look for?

The top searched job categories for Contract Vulnerability Scanning jobs are:

Infographic showing various Contract Vulnerability Scanning job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 16% Part Time, 1% Temporary, and 7% Contract. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution, with an average salary of $35,880 per year, or $17.2 per hour.

Vulnerability Management Lead

K2United LLC

Washington, DC โ€ข On-site

$116K - $152K/yr

Contractor

Posted 10 days ago


Job description

Job Type
Contract
Description
K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.
Our four core values define how we show up every day:
  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients' mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.
Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.
Position Summary
Own enterprise vulnerability management as a sustained program function - tracking, analysis, prioritization, remediation coordination, and trend reporting across systems, applications, devices, and other in-scope assets. This position converts scan output into risk-informed decisions, drives remediation to closure with system and business stakeholders, and integrates vulnerability data into the broader risk and compliance picture.
Key Responsibilities
  • Operate vulnerability management as a sustained enterprise function: identification, documentation, prioritization, monitoring, and closure across all in-scope assets.
  • Analyze vulnerability data, scan results, remediation status, and related security findings to enable risk-based decision making.
  • Coordinate remediation with system owners and stakeholders; assist in evaluating remediation actions, timelines, and residual risk.
  • Identify aging vulnerabilities and recurring or systemic issues; recommend process improvements and risk-reduction measures.
  • Lead recurring vulnerability review meetings with applicable stakeholders to review status and support remediation planning.
  • Produce periodic reporting covering severity, age, trend, and system-level status.
  • Provide monthly vulnerability reporting and an accompanying risk mitigation plan. Escalate critical and high vulnerabilities to the client's Chief Information Officer and Chief Information Security Officer and drive remediation as rapidly as possible, with POA&Ms established and prioritized by the risks implicated.
  • Integrate vulnerability management activity into overall risk and compliance support, feeding the POA&M workflow and authorization-boundary tracking maintained by the ISSO/ISCM Lead.
  • Support risk identification, analysis, tracking, and mitigation related to vulnerabilities, control gaps, and system changes.

Requirements
  • Bachelor's degree in cybersecurity, information technology, or a related field. Equivalent experience considered in lieu of degree.
  • Six or more years in vulnerability management, including at least two years leading or coordinating an enterprise vulnerability program.
  • Hands-on proficiency with enterprise vulnerability scanning and management platforms - Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or equivalent.
  • Demonstrated ability to apply risk-based prioritization beyond raw CVSS, incorporating exploitability, the CISA Known Exploited Vulnerabilities catalog, asset criticality, and compensating controls.
  • Experience driving remediation across organizational boundaries with system owners who do not report to the vulnerability function.
  • Experience producing executive-facing vulnerability trend reporting and defensible remediation timelines aligned to federal expectations.
  • Working knowledge of POA&M processes and NIST vulnerability management controls.

Preferred Qualifications
  • Cloud and container vulnerability management experience - Azure and Microsoft 365, AWS, container image scanning.
  • Experience correlating vulnerability data with SIEM and EDR telemetry to support threat-hunting hypotheses.
  • Experience with SBOM analysis and the vulnerability implications of supply chain risk.

Required Certifications
A relevant cybersecurity certification demonstrating competence in vulnerability management, risk, or operations support. Acceptable examples include CompTIA CySA+, GIAC GEVA or GCIH, a Tenable or Qualys vendor certification, CISSP, or CRISC.
Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process.
The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.
K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.
This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice.