1

Qualys Jobs in Virginia (NOW HIRING)

Responsibilities: • Perform continuous internal and external vulnerability scanning using Qualys. • Leverage and operate the existing Prolec Qualys environment and licensing. • Install and ...

Security Engineer - Junior

Herndon, VA · On-site +1

$60K - $110K/yr

Basic experience with vulnerability scanning tools (Tenable, Qualys, or equivalent) * Understanding of RBAC and least-privilege access principles * Bachelor's degree in Cybersecurity, Information ...

Cyber Security Engineer

Herndon, VA · On-site

$130K - $260K/yr

You'll support continuous monitoring, analyze critical findings using tools like Rapid7, Nessus, and Qualys, and manage POA&Ms to maintain compliance. Who We Are: We offer advanced services in data ...

Cyber Security Analyst

Herndon, VA · On-site

$130K - $260K/yr

You'll support continuous monitoring, analyze critical findings using tools like Rapid7, Nessus, and Qualys, and manage POA&Ms to maintain compliance. Who We Are: We offer advanced services in data ...

next page

Showing results 1-20

Qualys information

See Virginia salary details

$39

$66

$87

How much do qualys jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for qualys in Virginia is $66.49, according to ZipRecruiter salary data. Most workers in this role earn between $58.61 and $73.89 per hour, depending on experience, location, and employer.

What is a Qualys professional?

Qualys professionals are experts who specialize in deploying, managing, and optimizing the Qualys Cloud Platform—a suite of security and compliance solutions used by organizations to protect their IT infrastructure. They typically handle tasks like vulnerability management, policy compliance, asset discovery, and web application security. These professionals help organizations identify, assess, and remediate security risks in real time, ensuring compliance with industry standards. Their expertise is crucial for maintaining the security posture of businesses and preventing cyber threats.

What skills and qualifications are needed to thrive as a Qualys security engineer?

To thrive as a Qualys Security Engineer, you need a solid understanding of cybersecurity fundamentals, vulnerability management, and network protocols, typically supported by a degree in computer science or a related field. Proficiency in the Qualys Cloud Platform, relevant certifications such as Qualys Certified Specialist, and experience with SIEM tools are highly valuable. Strong analytical thinking, problem-solving abilities, and effective communication skills set standout professionals apart in this role. These combined skills ensure effective identification and mitigation of security risks, safeguarding organizational assets and maintaining compliance.

What are typical challenges faced by professionals working with Qualys in a cybersecurity team?

Professionals working with Qualys often face challenges such as managing large volumes of vulnerability data, ensuring accurate scanning across diverse environments, and prioritizing remediation efforts. Collaboration with IT and development teams is crucial to address vulnerabilities effectively and to minimize business disruption. Staying updated with the latest security threats and optimizing scan configurations for both on-premise and cloud assets are also key aspects of the role. Communication and coordination are essential, as findings need to be clearly reported and tracked for resolution.

What is the difference between Qualys vs Vulnerability Analyst?

AspectQualysVulnerability Analyst
CertificationsCertifications like CompTIA Security+, CISSP, or vendor-specific credentialsCertifications such as CompTIA Security+, GIAC, or CISSP
Work EnvironmentSecurity teams using vulnerability management tools, often in IT or cybersecurity departmentsSecurity or IT teams conducting vulnerability assessments and analysis
Employer & IndustryOrganizations using Qualys for vulnerability management across various industriesCompanies seeking vulnerability analysis and risk assessment services

Qualys is a vulnerability management platform used by organizations to scan and manage security vulnerabilities, while a Vulnerability Analyst is a professional who performs vulnerability assessments and analyzes security risks. Both roles often require similar certifications and work in cybersecurity environments, but Qualys refers to a specific tool, whereas Vulnerability Analyst describes a job function.

Infographic showing various Qualys job openings in Virginia as of August 2026, with employment types broken down into 84% Full Time, 10% Part Time, and 6% Contract. Highlights an 82% Physical, 8% Hybrid, and 10% Remote job distribution, with an average salary of $138,303 per year, or $66.5 per hour.

Vulnerability Management Analyst

KPMG LLP

Tysons, VA • On-site, Remote

Contractor

Posted 8 days ago


Job description

Responsibilities:
• Perform continuous internal and external vulnerability scanning using Qualys.
• Leverage and operate the existing Prolec Qualys environment and licensing.
• Install and manage Qualys agents on Prolec servers for authenticated scans.
• Deploy up to one additional Qualys scanning appliance per quarter.
• Maintain vulnerability scan coverage at or above 98% of known in-scope assets.
• Review vulnerability scan output and identify Critical and High vulnerabilities.
• Perform vulnerability ingestion and triage activities.
• Ensure Critical vulnerabilities are triaged and assigned within 1 business day.
• Ensure High vulnerabilities are triaged and assigned within 15 days.
• Ensure Medium vulnerabilities are triaged and assigned within 30 days.
• Monitor backlog levels and vulnerability volumes.
• Generate monthly vulnerability reports including backlog, visibility, and vulnerability management metrics.
• Act with integrity, professionalism, and personal responsibility to uphold the firm's respectful and courteous work environment.
Requirements
• Minimum 6 years of experience in systems analysis, vulnerability management, information security, or a related IT infrastructure/security role.
• Hands-on experience using Qualys or similar vulnerability scanning platforms, including authenticated scanning, agent deployment, and scanner appliance management.
• Strong understanding of vulnerability triage processes, including identifying, prioritizing, assigning, and tracking Critical, High, and Medium vulnerabilities against defined SLAs.
• Experience generating vulnerability management reports and metrics,, including backlog trends scan coverage, asset visibility, and remediation status.
• Bachelor's degree is preferred. Alternatively, candidates with at least 6 year experience in system analysis, vulnerability management, information security, or a related IT infrastructure/security role will be considered.
KPMG LLP ("KPMG") seeks a contractor in the United States to provide service to KPMG through one of our contracted employer/agency service providers. All applicants for any KPMG role are expected to act with integrity, professionalism, and personal responsibility to uphold the firm's respectful and courteous work environment. All applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).
Nothing herein shall be deemed to create an employer-employee relationship between contractor and KPMG, nor shall contractor be considered a representative or agent of KPMG.
KPMG LLP and its subsidiaries comply with all local/state regulations in regard to displaying pay rate ranges. The pay rate range(s) displayed is/are specifically for those contracted who will perform work in or reside in the location(s) listed, if selected for the role. Pay is determined based on a variety of factors including market data, ranges, applicant's skills and prior relevant experience, certain degrees and certifications (e.g. JD, technology), and specific location, for example. Additionally, applicants may be required to apply and become employed by a service provider utilized by KPMG, and final pay rate(s) and/or eligibility for additional benefits may be determined by such provider.
KPMG LLP, its subsidiaries, and its agency service providers (including, but not limited to, MBO Partners Inc., Magnit LLC, and TalentBurst Inc.) are equal opportunity employers/contractors. All qualified applicants are considered without regard to race, color, creed, religion, age, sex/gender, national origin, ancestry, citizenship status, marital status, sexual orientation, gender identity or expression, disability, physical or mental handicap unrelated to ability, pregnancy, veteran status, unfavorable discharge from military service, genetic information, or other legally protected status.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.