1

Cyber Security Vulnerability Analyst Jobs (NOW HIRING)

Responsibilities This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government and is responsible for reviewing and vetting security ...

Responsibilities This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government and is responsible for reviewing and vetting security ...

Responsibilities This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government and is responsible for reviewing and vetting security ...

The Cyber Security Program Office is seeking a full-time Vulnerability Analyst. Contract Position: Full Time, 40 hour work week Period of Performance: 1 Year Scope: This is an opportunity for a ...

Vulnerability Analyst

Washington, DC · On-site

$99K - $225K/yr

Vulnerability Analyst The Opportunity: As a vulnerability analyst, you're in the middle of the ... You'll use your cyber security skills to: * Lead the enterprise vulnerability management process in ...

next page

Showing results 1-20

Cyber Security Vulnerability Analyst information

See salary details

$43K

$99.4K

$150K

How much do cyber security vulnerability analyst jobs pay per year?

As of Jun 10, 2026, the average yearly pay for cyber security vulnerability analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Security Vulnerability Analyst, and why are they important?

To thrive as a Cyber Security Vulnerability Analyst, you need a solid understanding of network security, vulnerability assessment methodologies, and a background in information technology or computer science. Familiarity with tools like Nessus, Qualys, and Metasploit, as well as certifications such as CompTIA Security+ or CEH, is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify risks and convey findings to both technical and non-technical stakeholders. These skills ensure vulnerabilities are accurately discovered, prioritized, and addressed to protect organizational assets from cyber threats.

What is the difference between Cyber Security Vulnerability Analyst vs Penetration Tester?

AspectCyber Security Vulnerability AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, CISSPOSCP, CEH, GPEN
Work EnvironmentAnalyzes systems for vulnerabilities, reports findingsSimulates attacks to test security defenses
Employer & Industry UsageCommon in IT security teams across various industriesOften hired for security assessments and audits

While both roles focus on cybersecurity, a Cyber Security Vulnerability Analyst primarily identifies and reports vulnerabilities, whereas a Penetration Tester actively exploits weaknesses to test security measures. The analyst's role is more about assessment and documentation, while the tester simulates real-world attacks to evaluate defenses.

What does a Cyber Security Vulnerability Analyst do?

A Cyber Security Vulnerability Analyst is responsible for identifying, assessing, and prioritizing security vulnerabilities in computer systems, networks, and software. They use specialized tools to scan for weaknesses, analyze security risks, and recommend mitigation strategies to protect against cyber threats. Their work is crucial in helping organizations prevent data breaches and maintain strong security postures by proactively addressing potential points of exploitation.

What are some common challenges faced by Cyber Security Vulnerability Analysts when prioritizing vulnerabilities for remediation?

Cyber Security Vulnerability Analysts often face the challenge of balancing limited resources with the need to address a high volume of vulnerabilities. Prioritization must consider factors like the severity of the vulnerability, the criticality of affected systems, and potential business impact. Analysts work closely with IT and development teams to ensure patches and mitigations are deployed effectively, often under tight deadlines and with evolving threat landscapes. Communication and collaboration skills are essential, as conveying risk to non-technical stakeholders is a key part of the role.
More about Cyber Security Vulnerability Analyst jobs
What cities are hiring for Cyber Security Vulnerability Analyst jobs? Cities with the most Cyber Security Vulnerability Analyst job openings:
Infographic showing various Cyber Security Vulnerability Analyst job openings in the United States as of June 2026, with employment types broken down into 2% Locum Tenens, 93% Full Time, and 5% Contract. Highlights an 80% Physical, 6% Hybrid, and 14% Remote job distribution, with an average salary of $99,400 per year, or $47.8 per hour.
Cybersecurity Vulnerability Analyst

Cybersecurity Vulnerability Analyst

Peraton

Linthicum, MD • On-site

$104K - $166K/yr

Full-time

Posted 16 days ago


Peraton rating

8.3

Company rating: 8.3 out of 10

Based on 52 frontline employees who took The Breakroom Quiz

38th of 204 rated it services


Job description

Responsibilities

This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) within the federal government and is responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from outside hackers. The Analyst will evaluate the reports to ensure the vulnerability is reproducible and therefore valuable to the customer. They will assess each vulnerability for severity and assign an associated risk statement. The HackerOne Triage console tool will be utilized to assist in assigning and prioritizing reports. It will also assist the Analyst in helping identify duplicate submissions. Valid reports will be written in a DoD approved format and sent to the Vulnerability Management Analyst team for system owner coordination and mitigation. The Vulnerability Analyst will be a VDP liaison with the hacker community.

The Vulnerability Analyst will also:

  • Utilize offensive toolsets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments for the customer.
  • Identify and investigate vulnerabilities, asses exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems.
  • Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, using tools such as Burp Suite and open-source toolsets.
  • Utilize a variety of industry standard security tools to conduct automated scans against systems and applications.
  • Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities, utilizing various web exploitation methods.

This position is fully on-site M-F in the Baltimore-Metropolitan area.

#DC3bonus

#DC3bonus

Qualifications

Required Qualifications:

  • Education: Bachelor's degree and 5+ years of experience, or Master's and 3+ years of experience, or PhD and 0+ years of experience. A degree in one of the following fields of study is highly desired: Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science. An additional 4 years of relevant experience or specialized training may be considered in lieu of Bachelor's degree.
  • Security Clearance: Active Secret clearance.
  • Certifications: Active IAT Level II certification (CompTIA Security+ preferred).
  • In-depth understanding of information security principles and practices.
  • Pentesting experience.
  • Utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact.
  • In-depth understanding of web exploitation concepts and techniques.
  • Knowledge and understanding of the Open Web Application Security Project (OWASP) top 10.
  • Experience operating in a professional IT or cybersecurity environment.
  • Experience investigating security events, threats and/or vulnerabilities.
  • Understand information security principles, technologies and practices.
  • Excellent customer service skills.

Preferred Additional Skills:

  • CEH, CCNA-Security, CySA+, OSCP (or equivalent), PenTest+ or similar certification a plus.
  • Completed multiple Hack-The-Box penetration testing labs and challenges, developing handson expertise in vulnerability enumeration, exploitation, privilege escalation, and postexploitation techniques within realistic, adversarial environments.
  • Must possess an in-depth understanding of penetration testing methodology, including recon, exploit, persistence, etc.
  • Must have a solid understanding of networking protocols, their uses, and their potential misuses.
  • Programming experience in one or more languages, experience in HTLM/CSS or SQL.
  • Experience with one or more scripting languages such as PowerShell, Bash, Python or Perl.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.Employment Type: FULL_TIME

What Peraton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Peraton logo

About Peraton

Sourced by ZipRecruiter

At Peraton, we re at the forefront of delivering the next big thing every day. We re the partner of choice to help solve some of the world s most daunting challenges, delivering bold, new solutions to keep people around the world safer and more secure.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Herndon, VA, US

Year founded

2017