1

Network Vulnerability Analyst Jobs in Virginia (NOW HIRING)

Network Security Analyst LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this ... Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ...

Network Security Analyst LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this ... Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ...

Network Security Analyst LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this ... Familiarity with vulnerability scanning tools DESIRED SKILLS * Experience with advanced threat ...

next page

Showing results 1-20

Network Vulnerability Analyst information

See Virginia salary details

$16

$37

$58

How much do network vulnerability analyst jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for network vulnerability analyst in Virginia is $37.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.95 and $43.03 per hour, depending on experience, location, and employer.

What are some typical challenges faced by network vulnerability analysts when identifying and prioritizing security risks?

Network Vulnerability Analysts often encounter the challenge of managing a high volume of vulnerabilities across complex network environments. Prioritizing which vulnerabilities to address first requires balancing factors such as potential impact, exploitability, and business criticality. Analysts must also stay current with emerging threats and coordinate closely with IT and security teams to ensure remediation efforts are effective and timely. This role demands strong analytical skills, attention to detail, and the ability to communicate technical findings to both technical and non-technical stakeholders.

What are the key skills and qualifications needed to thrive as a network vulnerability analyst?

To thrive as a Network Vulnerability Analyst, you need a solid understanding of network protocols, cybersecurity principles, and vulnerability assessment methodologies, often supported by a degree in computer science or a related field. Familiarity with tools like Nessus, Qualys, Nmap, and relevant certifications such as CompTIA Security+ or CEH is highly valuable. Attention to detail, analytical thinking, and effective communication are vital soft skills for identifying threats and reporting findings clearly. These competencies ensure accurate identification and remediation of network vulnerabilities, helping to protect organizations from security breaches.

What is the difference between Network Vulnerability Analyst vs Network Security Analyst?

AspectNetwork Vulnerability AnalystNetwork Security Analyst
CertificationsCompTIA Security+, CEH, CISSPCompTIA Security+, CISSP, CISA
Work EnvironmentFocuses on identifying vulnerabilities in networks and systemsBroader security measures, including monitoring and incident response
Employer & Industry UsageIT security firms, corporate IT departmentsOrganizations with extensive network infrastructure

While both roles involve cybersecurity, a Network Vulnerability Analyst primarily identifies and assesses network weaknesses, whereas a Network Security Analyst implements security measures and monitors overall network health. The roles often overlap but differ in focus and scope.

What is a network vulnerability analyst?

Network Vulnerability Analysts are cybersecurity professionals who identify, assess, and help mitigate vulnerabilities within an organization's computer networks. They use specialized tools to scan for weaknesses, analyze network traffic, and evaluate the effectiveness of existing security measures. Their work helps prevent cyberattacks by ensuring that vulnerabilities are addressed before they can be exploited by hackers. Network Vulnerability Analysts also often generate reports and recommend solutions for improving network security.
What are popular job titles related to Network Vulnerability Analyst jobs in Virginia? For Network Vulnerability Analyst jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Network Vulnerability Analyst jobs in Virginia look for? The top searched job categories for Network Vulnerability Analyst jobs in Virginia are:
What cities in Virginia are hiring for Network Vulnerability Analyst jobs? Cities in Virginia with the most Network Vulnerability Analyst job openings:
Infographic showing various Network Vulnerability Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 11% Part Time, and 6% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $77,970 per year, or $37.5 per hour.

Network Security Specialist

Data Systems Analysts, Inc.

Charlottesville, VA

$103K - $141K/yr

Full-time

Posted 6 days ago


Job description

Description

Data Systems Analysts, Inc. (DSA) is seeking a TS/SCI cleared Network Security Specialist to secure, engineer, and defend enterprise network systems in a secure DoD environment. The Network Security Specialist will perform hands-on security configuration, boundary defense engineering, vulnerability remediation, and device hardening for Cisco based network infrastructure.

The Network Security Specialist will work closely with network engineers, cybersecurity staff, security administrators, and mission partners to ensure network systems remain secure, hardened, resilient, and operationally effective. This role is suited for a highly technical security professional with hands-on experience in Cisco network infrastructure, firewall management, ports and protocols, packet-level analysis, and active network defense.

This position is onsite in Charlottesville, VA.

Responsibilities

  • Configure and review firewall rules, access control lists, ports, protocols, services, VPN connections, network flows, and boundary protection controls.
  • Configure, validate, and audit security configurations for Cisco routers, switches, firewalls, and related network infrastructure.
  • Support active network security operations, boundary defense engineering, and continuous hardening for enterprise network systems.
  • Support incident response activities by performing technical analysis of network related alerts, logs, firewall events, syslog data, and authentication events.
  • Support change control reviews by assessing proposed network changes for cybersecurity impacts, configuration vulnerabilities, and security architecture alignment.
  • Monitor network security posture through syslog alerts, configuration management tools, and packet-level analysis.
  • Conduct, analyze, and remediate vulnerability scans using ACAS, Tenable Nessus, STIG Viewer, and other approved DoD tools.
  • Analyze vulnerability findings, identify false positives, engineer technical workarounds, and execute remediation actions across network devices.
  • Implement and validate DISA STIG compliance, SCAP benchmarks, security baselines, and device hardening requirements.
  • Develop and maintain technical network security documentation including device hardening procedures, network diagrams, and Ports, Protocols, and Services (PPS) listings.
  • Support technical engineering assessments and security reviews to maintain authorization sustainment activities.
  • Prepare technical security status updates, vulnerability remediation roadmaps, and network security risk briefings for engineering teams and stakeholders.

Required Education, Certifications and Security Clearance

  • BS degree in Engineering, Computer Science, or related field
    • Experience may be substituted for degree.
  • TS/SCI Clearance
  • DoD 8140 (8570) IAT Level II Certification
  • CCNA certification

Requirements Experience/Qualifications

  • Minimum 4 years of experience supporting network security engineering, secure network operations, boundary defense, or hands-on network administration.
  • Working knowledge of Cisco routers, switches, firewalls, Cisco ASA, Cisco Firepower, Cisco Secure Firewall, Cisco ISE, Catalyst, Nexus, ISR, or ASR platforms.
  • Working knowledge of routing, switching, VLANs, ACLs, firewall policies, ports, protocols, VPNs, IPsec, NAT, DNS, DHCP, subnetting, logging, and boundary protection.
  • Ability to design and review network diagrams, firewall rule sets, data flows, ports and protocols, and system interconnections for security vulnerabilities.
  • Demonstrated understanding of network hardening practices, secure protocols, network security architecture, and boundary defense concepts.
  • Experience coordinating with network engineers, systems administrators, security analysts, and mission partners to resolve technical security findings.
  • Hands on experience with ACAS, Tenable Nessus, STIG Viewer, SCAP, and network vulnerability remediation processes.
  • Experience applying, validating, or remediating vulnerability findings and DISA STIGs for network devices.
  • Experience developing or maintaining technical configuration standards, ports and protocols lists, network topology diagrams, and device configuration baselines.
  • Familiarity with applying and verifying security controls on network hardware to support technical authorization maintenance.
  • Experience supporting network security activities within the DoD, Intelligence Community, or other secure enterprise environment.
  • Knowledge of NIST SP 800-53 security controls (specifically Network/Access Control families), DISA Network Infrastructure STIGs, and secure network design practices.
  • Strong technical documentation, communication, analytical, and troubleshooting skills.

Preferred Experience/Qualifications

  • Experience securing, assessing, and engineering Cisco ASA, Cisco Firepower, Cisco Secure Firewall, Cisco ISE, Catalyst, Nexus, ISR, or ASR platforms in a production environment.
  • Experience writing and auditing firewall rules, access control policies, route tables, network diagrams, ports and protocols, and VPN configurations.
  • Experience with Splunk, Elastic, ELK Stack, OpenSearch, SolarWinds, Wireshark, NetFlow, syslog, firewall logs, or other tools used to support monitoring and packet-level analysis.
  • Familiarity with network automation or scripting tools such as Ansible, Python, PowerShell, Terraform, or Cisco Catalyst Center to automate security baselines.
  • Familiarity with Zero Trust principles, micro-segmentation, identity-based access control, and modern DoD cybersecurity architecture.
  • CCNP, CCNP Security, Cisco CyberOps, or equivalent network security certification.
  • CISSP, CEH, PenTest+, CySA+, CASP+, SecurityX, or equivalent cybersecurity certification.
  • Knowledge of continuous monitoring, active threat hunting, and automated configuration compliance.

Applicable Military Backgrounds

  • Army: 17C, 25B, 25D, 25H, 255A, 255N, 255S
  • Navy: IT, ITS, ITN, ITR, CWT, 1820, 1880
  • Air Force: 1B4X1, 1D7X1, 1D7X1A, 1D7X5, 17D, 17S
  • Marine Corps: 0631, 0671, 0681, 1702, 1721
  • Space Force: 5C0X1, 17X
  • Coast Guard: IT, CMS, CMM, C5I

#DSA209

#LI-KE1