We are seeking a Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability management, security metrics, remediation tracking, and dashboard reporting in a federal ...
We are seeking a Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability management, security metrics, remediation tracking, and dashboard reporting in a federal ...
We are seeking a Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability management, security metrics, remediation tracking, and dashboard reporting in a federal ...
We are seeking a Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability management, security metrics, remediation tracking, and dashboard reporting in a federal ...
SYSTEMS ENGINEER (NESSUS) - REMOTE ARC Group has an immediate opportunity for a Systems Engineer with strong experience working with vulnerability scanning tools! This position is 100% remote working ...
Quick apply
SYSTEMS ENGINEER (NESSUS) - REMOTE ARC Group has an immediate opportunity for a Systems Engineer with strong experience working with vulnerability scanning tools! This position is 100% remote working ...
Desktop Technician [Must Vulnerability assessment, Nessus, MECM, and Intune] - Herndon, VA/On-S
Herndon, VA · On-site
$20.75 - $26.50/hr
Familiarity with security tools such as Nessus, MECM, and Intune. Strong problem-solving skills and attention to detail. Ability to work independently and as part of a team. Strong communication and ...
Desktop Technician [Must Vulnerability assessment, Nessus, MECM, and Intune] - Herndon, VA/On-S
Herndon, VA · On-site
$20.75 - $26.50/hr
Familiarity with security tools such as Nessus, MECM, and Intune. Strong problem-solving skills and attention to detail. Ability to work independently and as part of a team. Strong communication and ...
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
$150K - $160K/yr
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
Quick apply
$150K - $160K/yr
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
Network Computer System Administrator
Mclean, VA · On-site
$137K - $164K/yr
One (1) year Nessus Attack Scripting Language experience. * One (1) year operations center/call center, or technical helpdesk experience. * SME on policy Development, implementation, and reporting of ...
Network Computer System Administrator
Mclean, VA · On-site
$137K - $164K/yr
One (1) year Nessus Attack Scripting Language experience. * One (1) year operations center/call center, or technical helpdesk experience. * SME on policy Development, implementation, and reporting of ...
ACAS Engineer
Fort George G Meade, MD · On-site
$140K - $156K/yr
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Fort George G Meade, MD · On-site
$140K - $156K/yr
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Quantico, VA · Hybrid
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Quantico, VA · Hybrid
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Fort George G Meade, MD · Hybrid
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Fort George G Meade, MD · Hybrid
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
ACAS Engineer
Quantico, VA · On-site
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Quantico, VA · On-site
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
Security Engineer
Manassas, VA · On-site
Customization of configuration compliance verification tools (eg CIS cis-cat, tenable Nessus) / min 5 Years *Customization of Security configuration standards (like CIS benchmarks) for Operating ...
Security Engineer
Manassas, VA · On-site
Customization of configuration compliance verification tools (eg CIS cis-cat, tenable Nessus) / min 5 Years *Customization of Security configuration standards (like CIS benchmarks) for Operating ...
$150K - $160K/yr
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
Quick apply
$150K - $160K/yr
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). * Security+ or other relevant cybersecurity certifications. * Experience with scripting languages such as ...
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Fort George G Meade, MD · Hybrid
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
ACAS Engineer
Fort George G Meade, MD · Hybrid
Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, Nessus Manager and Nessus Agent) is required. * Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
$90K - $175K/yr
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). Security+ or other relevant cybersecurity certifications. Experience with scripting languages such as ...
$90K - $175K/yr
Experience with the Tenable ACAS suite (Nessus, Security Center/Tenable.sc, NNM/Tenable.asm). Security+ or other relevant cybersecurity certifications. Experience with scripting languages such as ...
Nessus Manager, Nessus Network Monitor, Tenable Security Center). • Splunk Enterprise (experience with migrating systems to a new Splunk server, configuring forwarders for different systems/IoTs ...
Nessus Manager, Nessus Network Monitor, Tenable Security Center). • Splunk Enterprise (experience with migrating systems to a new Splunk server, configuring forwarders for different systems/IoTs ...
Network Computer System Administrator
$137K - $164K/yr
One (1) year Nessus Attack Scripting Language experience. * One (1) year operations center/call center, or technical helpdesk experience. * SME on policy Development, implementation, and reporting of ...
Network Computer System Administrator
$137K - $164K/yr
One (1) year Nessus Attack Scripting Language experience. * One (1) year operations center/call center, or technical helpdesk experience. * SME on policy Development, implementation, and reporting of ...
Nessus information
See salary details
$33.5K - $46.3K
1% of jobs
$46.3K - $59K
0% of jobs
$59K - $71.8K
0% of jobs
$71.8K - $84.6K
0% of jobs
$84.6K - $97.4K
4% of jobs
$109.3K is the 25th percentile. Wages below this are outliers.
$97.4K - $110.1K
21% of jobs
$110.1K - $122.9K
15% of jobs
The median wage is $132.8K / yr.
$122.9K - $135.7K
12% of jobs
$135.7K - $148.5K
14% of jobs
$148.5K - $161.2K
7% of jobs
$161.9K is the 75th percentile. Wages above this are outliers.
$161.2K - $174K
26% of jobs
$33.5K
$137.7K
$174K
How much do nessus jobs pay per year?
Can I make $200,000 a year in cyber security?
What is a Tenable job?
What is a Nessus job?
A Nessus job typically involves using Tenable's Nessus vulnerability scanner to assess network security by identifying weaknesses, misconfigurations, and vulnerabilities in systems. Security professionals in this role configure and run scans, analyze results, and provide remediation recommendations to improve cybersecurity posture. Nessus jobs are commonly held by penetration testers, security analysts, and IT administrators responsible for maintaining secure environments.
What does Nessus do?
What are the key skills and qualifications needed to thrive in the Nessus position, and why are they important?
To thrive as a Nessus Vulnerability Analyst, you need a strong foundation in cybersecurity principles, vulnerability assessment, and network security protocols, often demonstrated by a degree in computer science or a related field. Experience with the Nessus vulnerability scanner, familiarity with security frameworks (like CIS or NIST), and relevant certifications such as CompTIA Security+ or CEH are highly valued. Attention to detail, analytical thinking, and strong written communication are important soft skills for accurately reporting findings and collaborating with IT teams. These competencies are crucial for effectively identifying, analyzing, and mitigating security risks within an organization.
What company owns Nessus?
What does a typical day look like for someone working as a Nessus Vulnerability Analyst?
As a Nessus Vulnerability Analyst, your day typically involves conducting vulnerability scans across various network assets, interpreting the resulting reports, and prioritizing the remediation of identified risks. You’ll collaborate closely with IT and security teams to follow up on critical findings, document remediation steps, and ensure compliance with organizational policies. Regular communication with stakeholders is essential, as you’ll provide updates and recommendations based on current threat landscapes. This role offers the opportunity to continuously learn about emerging security threats and technologies while directly contributing to your organization’s cyber defense posture.

Full-time
Posted 15 days ago
Job description
We are seeking a Vulnerability Management, Tenable/Nessus & Metrics Analyst to support vulnerability management, security metrics, remediation tracking, and dashboard reporting in a federal technology environment. This role is designed for an analyst with approximately 1-3 years of relevant experience who can work hands-on with Tenable/Nessus data, Excel, Power BI, iPost exports, ticketing records, and remediation evidence. The analyst will help identify affected systems, validate findings, track remediation ownership, monitor KEVs and Critical/High vulnerabilities, reconcile data across sources, and support leadership reporting. The role should be positioned as an execution and coordination role. The analyst will not be expected to own enterprise security operations, perform all production patch deployments, or act as the ISSO. The analyst will support TIOCA Security and product/application teams by making vulnerability data accurate, actionable, and reportable.
Primary Responsibilities:
- Tenable/Nessus Vulnerability Analysis, Ad Hoc Scanning, and Native Dashboards
- Perform and Review Tenable/Nessus scan exports and dashboards to identify affected assets, plugins, CVEs, severity, first-seen dates, last-seen dates, plugin output, vulnerability age, and remediation guidance.
- Run approved ad hoc Tenable/Nessus scans when requested by TIOCA Security, product teams, ISSO, or leadership, using approved scan templates, credentialed scan profiles, scan windows, and target lists.
- Create and maintain Tenable/Nessus native dashboards, saved views, reports, filters, asset groups/tags where permitted, and recurring exports for KEVs, Critical/High findings, stale findings, aging, ownership, and validation status.
- Monitor scan jobs, confirm scan completion, export results, identify scan failures or credential issues, and escalate scan coverage or authentication problems to senior security staff or platform administrators.
- Help validate whether findings are true positives, duplicates, stale/residual artifacts, configuration issues, missing patches, unsupported software, or application dependencies.
- Track KEV status, Critical/High vulnerabilities, exploitable findings, internet-facing risk indicators if available, and vulnerabilities tied to DOS or federal remediation timelines.
- Use Tenable/Nessus evidence to support ownership assignment, remediation planning, retest validation, and closure evidence.
- Reconcile Tenable/Nessus data against iPost, ServiceNow/CA ServiceDesk, Jira, POA&M trackers, Excel files, SharePoint trackers, and remediation evidence.
- Escalate unclear Tenable/Nessus findings to senior security staff, system owners, application teams, SO/Windows Services, infrastructure, database teams, or ISSO stakeholders for ownership decisions.
- Operate within approved rules of engagement. The role may run authorized ad hoc scans and build Tenable reports, but is not expected to be the enterprise Tenable platform administrator or final approver for scan policy changes.
- Vulnerability Management Lifecycle Support
- Support the vulnerability lifecycle: intake, triage, validation, ownership assignment, prioritization, remediation tracking, retest support, closure evidence collection, and recurrence monitoring.
- Track KEVs, Critical/High vulnerabilities, EOL/EOS software, iPost findings, POA&M-related findings, patch findings, application-impacting vulnerabilities, and blocked remediation items.
- Identify remediation path options such as patching, software upgrade, dependency upgrade, configuration change, file removal, compensating control, risk acceptance, or decommissioning.
- Document blockers, stale findings, aging risk, unclear ownership, cross-team dependencies, and evidence gaps.
- Help maintain action trackers with owners, due dates, next steps, escalation status, and evidence status.
- Support weekly vulnerability review meetings, Critical/High/KEV response sessions, POA&M reviews, and monthly reporting cycles.
- Metrics, Reporting, and Power BI Dashboarding
- Build and maintain basic to intermediate Power BI dashboards and Excel-based reports for vulnerability posture, Tenable/Nessus findings, iPost/Tenable reconciliation, patch compliance, aging, ownership, and closure evidence.
- Build Tenable/Nessus-native dashboards and reports in addition to Power BI, including saved filters/views for KEVs, Critical/High findings, assets by owner, scan coverage, authentication failures, stale findings, aging, and remediation validation.
- Create report views for open findings by severity, KEV status, application/system, owner/team, age, due date, remediation status, and blocked status.
- Support recurring reports for KEVs, Critical/High findings, EOL/EOS software, Tenable/iPost mismatches, findings awaiting validation, overdue findings, closure trends, and executive summary snapshots.
- Use Power Query, data cleaning steps, relationships, filters, slicers, basic DAX measures, and refresh procedures to make reports repeatable.
- Document KPI definitions, data sources, refresh cadence, report assumptions, ownership rules, and known data-quality limitations.
- Convert technical vulnerability data into clear status reporting that shows risk, owner, due date, blocker, evidence, and decision needed.
- Coordination and Evidence Support
- Coordinate with TIOCA Security, TIOCA Dev/Product teams, SO/Windows Services, production infrastructure, database teams, cloud teams, ISSO teams, and government stakeholders to track remediation through closure.
- Collect and organize closure evidence such as rescans, version checks, ticket notes, screenshots, deployment records, release notes, POA&M artifacts, iPost/Tenable updates, and ISSO validation evidence.
- Help distinguish between product/application responsibilities and production/server-level responsibilities so findings are assigned to the correct owner.
- Support tracking where SO or shared infrastructure owns deployment but TIOCA needs application validation, evidence, or product-owner input.
- Help maintain SOPs, RACI notes, dashboard metric definitions, and remediation workflow documentation.
Required Qualifications:
- 1-3 years of experience in cybersecurity operations, vulnerability management, security operations, cyber GRC, IT operations, application support, or related technical/security work.
- Hands-on exposure to Tenable/Nessus vulnerability data, including plugins, CVEs, severity, affected assets, plugin output, first-seen/last-seen dates, and remediation guidance.
- Ability to run authorized ad hoc Tenable/Nessus scans using approved scan templates, target lists, credentials, scan windows, and documented rules of engagement.
- Ability to create or maintain Tenable/Nessus dashboards, saved filters, reports, and exports for vulnerability review and remediation tracking.
- Ability to work with vulnerability exports from Tenable/Nessus and organize findings in Excel, Power BI, SharePoint, Jira, ServiceNow/CA ServiceDesk, or similar tools.
- Working understanding of vulnerability management concepts such as severity, KEV, CVE, false positive, remediation evidence, rescan validation, aging, ownership, dependencies, risk acceptance, and due dates.
- Intermediate Power BI or reporting experience, including data imports, transformations, tables, charts, filters, slicers, and dashboard maintenance.
- Strong Excel skills, including filtering, lookups, pivots, conditional formatting, data cleanup, and comparison across exports.
- Ability to communicate clearly with technical teams and non-technical stakeholders about finding status, blockers, evidence, and next steps.
- Strong attention to detail and willingness to reconcile messy data across multiple sources.
- Familiarity with iPost, Tenable/Nessus, ServiceNow, Jira, ServiceDesk, SharePoint, Power BI, Splunk, or similar reporting/security tools.
- Exposure to application development, product teams, DevSecOps, SAST, SCA, DAST, container scanning, secrets scanning, or SBOM tooling.
- Experience tracking EOL/EOS software, patch compliance, POA&M aging, remediation exceptions, risk acceptance, or closure evidence.
Preferred Qualifications
- Experience supporting federal government cybersecurity programs or regulated environments.
- Familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M tracking, CISA KEV, BOD 22-01, FedRAMP, or federal vulnerability remediation expectations.
- Exposure to application development, product teams, DevSecOps, SAST, SCA, DAST, container scanning, secrets scanning, or SBOM tooling.
- Basic understanding of Windows Server, Windows workstation, .NET Framework, Java JRE, SQL Server, browser updates, endpoint agents, and common enterprise patching concepts.
About InstantServe
Sourced by ZipRecruiter
InstantServe provides a one-stop solution to all Healthcare, IT/Non-IT Staffing needs. Established in 2016, InstantServe is a strong workforce of over 100+ go-getters with a demonstrated background in IT/Non-IT service. We are a nationally certified SBE from the Department of Administration (State of PA). As a proud Minority Woman Owned Small Business Enterprise (M/WBE), InstantServe boasts of a strong team of professionals who have extensive experience catering to several Federal, Public, Commercial, and Healthcare Clients which includes 26 States and 46 government agencies. InstantServe is a client-centric organization that offers cost-effective and reliable solutions. Client satisfaction is sacrosanct! Our team strives to provide the best staffing and IT solutions to take your business to the next level.
Industry
Recruiting and staffing services
Company size
11 - 50 Employees
Headquarters location
Wayne, PA, US
Year founded
2016