1

Overnight Vulnerability Management Analyst Jobs (NOW HIRING)

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

Requirements โ€ข Minimum 6 years of experience in systems analysis, vulnerability management, information security, or a related IT infrastructure/security role. โ€ข Hands-on experience using Qualys ...

Showing results 21-40

Overnight Vulnerability Management Analyst information

See salary details

$35K

$75.5K

$131K

How much do overnight vulnerability management analyst jobs pay per year?

As of Aug 17, 2026, the average yearly pay for overnight vulnerability management analyst in the United States is $75,517.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,000.00 and $89,500.00 per year, depending on experience, location, and employer.

What does an overnight vulnerability management analyst do?

An Overnight Vulnerability Management Analyst is responsible for identifying, assessing, and managing security vulnerabilities within an organization's systems during overnight hours. They monitor security alerts, analyze threats, and ensure that vulnerabilities are documented and communicated to the appropriate teams for remediation. Their work helps to protect the organization from cyber threats by ensuring that vulnerabilities are addressed promptly, even outside of regular business hours.

What skills and qualifications are needed to thrive as an overnight vulnerability management analyst?

To thrive as an Overnight Vulnerability Management Analyst, a solid understanding of cybersecurity principles, knowledge of network and system vulnerabilities, and a relevant degree or certification such as CompTIA Security+ or CISSP are essential. Familiarity with vulnerability scanning tools like Nessus, Qualys, or Rapid7, as well as ticketing and SIEM systems, is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts prioritize threats and collaborate across teams, especially during off-hours. These skills are crucial to ensure timely identification and mitigation of security risks, maintaining organizational security around the clock.

What unique challenges do overnight vulnerability management analysts face, and how can they prepare for success?

Overnight Vulnerability Management Analysts often work independently or with a small team during less traditional hours, which means they need to be highly self-motivated and comfortable making decisions with limited immediate supervision. A key challenge is ensuring timely identification and escalation of critical vulnerabilities, even when support resources may be limited overnight. To succeed, analysts should develop strong communication skills for clear hand-offs with daytime teams and stay organized to manage multiple concurrent security alerts. Familiarity with a range of vulnerability assessment tools and the ability to document findings thoroughly are also essential for seamless collaboration and reporting.

What is the difference between Overnight Vulnerability Management Analyst vs Vulnerability Analyst?

AspectOvernight Vulnerability Management AnalystVulnerability Analyst
CertificationsCompTIA Security+, CISSP (preferred)CompTIA Security+, CISSP (preferred)
Work EnvironmentNight shifts, monitoring security tools overnightDay shifts, analyzing vulnerabilities during business hours
Employer & Industry UsageIT security teams in various industries, especially 24/7 operationsCybersecurity teams across multiple sectors, often during standard hours

Both roles focus on identifying and managing security vulnerabilities, with the Overnight Vulnerability Management Analyst working primarily during night shifts to ensure 24/7 security coverage. The main difference lies in work hours and shift timing, while required skills and certifications are largely similar.

What cities are hiring for Overnight Vulnerability Management Analyst jobs?

Cities with the most Overnight Vulnerability Management Analyst job openings:

What are the most commonly searched types of Vulnerability Management Analyst jobs?

The most popular types of Vulnerability Management Analyst jobs are:

What states have the most Overnight Vulnerability Management Analyst jobs?

States with the most job openings for Overnight Vulnerability Management Analyst jobs include:

Vulnerability Management Analyst

DANE LLC

Chantilly, VA โ€ข On-site

$70K - $85K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 4 days ago


Job description

Benefits:
  • Life/STD/LTD
  • FSA/DCA
  • 401(k)
  • Employee discounts
  • Paid time off
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Tuition assistance
  • Vision insurance

Description
Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.
Details:
Location: Hybrid - Onsite, Arlington, VA,1 day/week and as needed
Job Type: Full Time
Education: Minimum of a Bachelor’s degree in computer science or Equivalent
Experience: Minimum 1 year of relevant experience
Clearance: Must hold an Active DoD Secret Clearance or higher
Responsibilities
  • Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
  • Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
  • Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
  • Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
  • Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
  • Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
  • Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
  • Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements

  • 1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
  • Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
  • Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
  • Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
  • Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
  • Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications

  • Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
  • Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
  • Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
  • Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
  • Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.

DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Flexible work from home options available.