1

Cyber Security Vulnerability Analyst Jobs (NOW HIRING)

Oversee analysis of vulnerability outputs (ACAS, Forescout, STIG findings, etc.) to adjudicate risk ... Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems ...

Senior Vulnerability Analyst

Arlington, VA ยท On-site

$131K - $237K/yr

Leidos has an immediate need for an experienced Vulnerability Assessor for a new customer on a highly-visible and strategic Cybersecurity Task Order. The VAT Analyst will need to be a self-starter ...

Leidos has an immediate need for an experienced Vulnerability Assessor for a new customer on a highly-visible and strategic Cybersecurity Task Order. The VAT Analyst will need to be a self-starter ...

Be Seen First

Research, analyze, and interpret cybersecurity threats, vulnerabilities, CVEs, CVSS scores, attack vectors, and mitigation strategies. * Configure, manage, and optimize vulnerability management ...

Vulnerability Analyst, Senior

Herndon, VA ยท On-site

$104K - $166K/yr

Oversee analysis of vulnerability outputs (ACAS, Forescout, STIG findings, etc.) to adjudicate risk ... Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems ...

Vulnerability Analyst, Senior

Herndon, VA ยท On-site

$104K - $166K/yr

Oversee analysis of vulnerability outputs (ACAS, Forescout, STIG findings, etc.) to adjudicate risk ... Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems ...

Vulnerability Analyst, Journeyman

Herndon, VA ยท On-site

$80K - $128K/yr

Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems ... Vulnerability Assessment Analyst (Intermediate) Playlist; E3ABR1D731D00BB); OR * Relevant ...

next page

Showing results 1-20

Cyber Security Vulnerability Analyst information

See salary details

$43K

$99.4K

$150K

How much do cyber security vulnerability analyst jobs pay per year?

As of Jun 9, 2026, the average yearly pay for cyber security vulnerability analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Security Vulnerability Analyst, and why are they important?

To thrive as a Cyber Security Vulnerability Analyst, you need a solid understanding of network security, vulnerability assessment methodologies, and a background in information technology or computer science. Familiarity with tools like Nessus, Qualys, and Metasploit, as well as certifications such as CompTIA Security+ or CEH, is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify risks and convey findings to both technical and non-technical stakeholders. These skills ensure vulnerabilities are accurately discovered, prioritized, and addressed to protect organizational assets from cyber threats.

What is the difference between Cyber Security Vulnerability Analyst vs Penetration Tester?

AspectCyber Security Vulnerability AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, CISSPOSCP, CEH, GPEN
Work EnvironmentAnalyzes systems for vulnerabilities, reports findingsSimulates attacks to test security defenses
Employer & Industry UsageCommon in IT security teams across various industriesOften hired for security assessments and audits

While both roles focus on cybersecurity, a Cyber Security Vulnerability Analyst primarily identifies and reports vulnerabilities, whereas a Penetration Tester actively exploits weaknesses to test security measures. The analyst's role is more about assessment and documentation, while the tester simulates real-world attacks to evaluate defenses.

What does a Cyber Security Vulnerability Analyst do?

A Cyber Security Vulnerability Analyst is responsible for identifying, assessing, and prioritizing security vulnerabilities in computer systems, networks, and software. They use specialized tools to scan for weaknesses, analyze security risks, and recommend mitigation strategies to protect against cyber threats. Their work is crucial in helping organizations prevent data breaches and maintain strong security postures by proactively addressing potential points of exploitation.

What are some common challenges faced by Cyber Security Vulnerability Analysts when prioritizing vulnerabilities for remediation?

Cyber Security Vulnerability Analysts often face the challenge of balancing limited resources with the need to address a high volume of vulnerabilities. Prioritization must consider factors like the severity of the vulnerability, the criticality of affected systems, and potential business impact. Analysts work closely with IT and development teams to ensure patches and mitigations are deployed effectively, often under tight deadlines and with evolving threat landscapes. Communication and collaboration skills are essential, as conveying risk to non-technical stakeholders is a key part of the role.
More about Cyber Security Vulnerability Analyst jobs
What cities are hiring for Cyber Security Vulnerability Analyst jobs? Cities with the most Cyber Security Vulnerability Analyst job openings:
Senior Database Vulnerability Analyst

Senior Database Vulnerability Analyst

PD Inc

Fort George G Meade, MD โ€ข On-site

$95K - $120K/yr

Full-time

Medical, Retirement, PTO

Posted 27 days ago


Job description

Job Title:ย  Senior Database Vulnerability Analyst
Location:ย Fort Meade, MD 20755
Clearance Level: Active Secret Clearance
Job Type: Full-Time
Must be U.S. Citizen
PD Inc International is seeking an experienced and mission-driven Senior Database Vulnerability Analyst to provide Cybersecurity Management support in a U.S. government (DoD) environment.ย 
Education Requirement:
  • Bachelor's degree or equivalent work experience
Years of Experience:
  • Five + years of relevant/recent experience with Oracle, SQL, MySQL, or DB2 and cybersecurity.
Certification Requirements:
  • Current 8570/8140 requirement certification
Clearance Requirements:
  • Active Secret Clearance
Requirements:
  • Serve as an application technical specialist for assets connected to isolated environments, NIPRNet and SIPRNet to support cybersecurity and IT services.
  • Review, identify, and report problems with the installation and operations of application instances to include system options, software used and not used, default security controls that are enabled, disabled, or bypassed, and system wide options or parameters that may create security vulnerabilities.
  • Determine the impact and risk of submitted change requests prior to implementation and participate in change advisory board (CAB) meetings (up to daily) to provide cyber oversight for database changes that affect the level of risk.
  • Recommend security countermeasures to mitigate identified application risks.
Application Vulnerability Analysis:
  • Identify, monitor, analyze, report, and brief status of vulnerabilities.
  • Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated.
  • Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders. ย ย ย ย ย ย ย ย ย ย 
  • Create, maintain, and provide automated and customized vulnerability reports.
  • Analyze mission requirements and organizational feedback to improve vulnerability reports and processes.
  • Provide recommendations for application vulnerability analysis, guidance, deficiency resolution, and implementation suggestions to DISA customers and Mission Partners.
Application Compliance Validation and Support:
  • Assess, audit, review, analyze, validate, and report database Security Requirements Guide (SRG) and STIG vulnerabilities, and ensure security controls are implemented within databases IAW DoD, DISA and cybersecurity policies and procedures.
  • Evaluate discrepancies as they relate to policy, orders, and database SRG and/or STIGs, and document recommended additions, deletions, or changes.
  • Identify and report the need to add technical guidance for modification of policies and orders.
  • Review and validate the installation and configuration of cyber tools on assets, and report deficiencies.
  • Review database SRG and/or STIGs as updates are released, and report changes with the potential to have significant impact.
  • Determine the impact and risk of submitted change requests prior to implementation and participate in meetings to provide cyber oversight for web changes that affect the level of risk.
  • Recommend security countermeasures to mitigate identified web risks.
  • Participate in audits and provide documentation (up to daily).
Deliverables:
  • Daily/weekly/monthly/quarterly/annual vulnerability analysis reports
  • Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
~~~~~~~~~~~~~~~
About PD Inc International (PD Inc): PD Inc is a leading high-tech firm as well as an applied think tank and solutions provider.ย  Our team has been providing expertise and solutions to the US Government (Department of Defense, Department of State, Department of Homeland Security, Veterans Affairs, etc.) and to commercial clients for over 20-years.ย ย 
We perform software development and complex technical implementation daily.ย  We conduct R&D, prototyping, and develop hardware and software solutions for our clients.ย  Our qualified personnel--including engineers and technical managers--are capable of performing system integration, technology implementation, and services throughout the federal government and in the private sector.
We have a highly innovative environment, and we foster consistent learning and growth. We encourage our employees to innovate while teaching them discipline and principles.ย 
PD Inc benefits include highly competitive salary, 401K, health care, paid time off, no-limit Student loan forgiveness (merit based), and we sponsor new/qualified employees for Security Clearance.
Employees can also take advantage of casual dress code, free parking, corporate discounts, and gym memberships.

Powered by JazzHR

YyCZgvWcdz


PD logo

About PD

Sourced by ZipRecruiter

Industry

It services

Company size

1 - 10 Employees

Headquarters location

Baltimore, MD, US

Year founded

2001