1

Sr Risk And Vulnerability Analyst Jobs in Baltimore, MD

The Analyst will evaluate the reports to ensure the vulnerability is reproducible and therefore ... They will assess each vulnerability for severity and assign an associated risk statement. The ...

next page

Showing results 1-20

Sr Risk And Vulnerability Analyst information

See Baltimore, MD salary details

$53.2K

$109.1K

$141.6K

How much do sr risk and vulnerability analyst jobs pay per year?

As of Aug 26, 2026, the average yearly pay for sr risk and vulnerability analyst in Baltimore, MD is $109,147.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,900.00 and $136,100.00 per year, depending on experience, location, and employer.

What does a Sr Risk and Vulnerability Analyst do?

A Sr Risk and Vulnerability Analyst is responsible for identifying, assessing, and mitigating risks and vulnerabilities within an organization’s information systems and processes. They conduct security assessments, analyze potential threats, and recommend strategies to protect assets and data. Their role often involves collaborating with IT, compliance, and management teams to develop risk management policies and respond to emerging security issues. Additionally, they may lead vulnerability testing and ensure the organization meets regulatory and industry standards for cybersecurity.

What are the key skills and qualifications needed to thrive as a Sr Risk and Vulnerability Analyst, and why are they important?

To thrive as a Sr Risk and Vulnerability Analyst, you need in-depth knowledge of cybersecurity principles, risk assessment methodologies, and a relevant degree or certifications such as CISSP or CEH. Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys), SIEM systems, and risk management frameworks (like NIST or ISO 27001) is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex data and collaborate across teams. These competencies are vital for identifying threats, reducing organizational risk, and ensuring robust security defenses.

What are some common challenges faced by a Sr Risk and Vulnerability Analyst, and how can they be addressed?

Sr Risk and Vulnerability Analysts often encounter challenges such as staying updated with rapidly evolving threats, managing a large volume of vulnerabilities, and effectively communicating risks to non-technical stakeholders. Addressing these challenges involves continuous learning, leveraging automated tools for vulnerability management, and developing strong reporting and presentation skills to translate technical findings into actionable business insights. Collaboration with IT, security teams, and business leaders is essential to prioritize and remediate risks efficiently.

What is the difference between Sr Risk And Vulnerability Analyst vs Risk Analyst?

AspectSr Risk And Vulnerability AnalystRisk Analyst
CertificationsCertifications like CISSP, CISA often preferredSimilar certifications, often entry to mid-level
Work EnvironmentFocus on cybersecurity vulnerabilities and risk management in ITBroader risk assessment across financial, operational, or strategic areas
Employer & Industry UsageCommon in cybersecurity, IT, finance sectorsUsed across various industries including finance, insurance, and consulting

The Sr Risk And Vulnerability Analyst specializes in identifying and mitigating cybersecurity vulnerabilities, often requiring advanced certifications and experience. In contrast, a Risk Analyst has a broader scope, assessing risks across multiple business areas. Both roles require analytical skills but differ in focus and industry application.

What are popular job titles related to Sr Risk And Vulnerability Analyst jobs in Baltimore, MD?

For Sr Risk And Vulnerability Analyst jobs in Baltimore, MD, the most frequently searched job titles are:

What job categories do people searching Sr Risk And Vulnerability Analyst jobs in Baltimore, MD look for?

The top searched job categories for Sr Risk And Vulnerability Analyst jobs in Baltimore, MD are:

What cities near Baltimore, MD are hiring for Sr Risk And Vulnerability Analyst jobs?

Cities near Baltimore, MD with the most Sr Risk And Vulnerability Analyst job openings:

Senior Database Vulnerability Analyst

PD Inc

Fort George G Meade, MD • On-site

$95K - $120K/yr

Full-time

Medical, Retirement, PTO

Re-posted 15 days ago


Job description

Job Title:  Senior Database Vulnerability Analyst
Location: Fort Meade, MD 20755
Clearance Level: Active Secret Clearance
Job Type: Full-Time
Must be U.S. Citizen
PD Inc International is seeking an experienced and mission-driven Senior Database Vulnerability Analyst to provide Cybersecurity Management support in a U.S. government (DoD) environment
Education Requirement:
  • Bachelor's degree or equivalent work experience
Years of Experience:
  • Five + years of relevant/recent experience with Oracle, SQL, MySQL, or DB2 and cybersecurity.
Certification Requirements:
  • Current 8570/8140 requirement certification
Clearance Requirements:
  • Active Secret Clearance
Requirements:
  • Serve as an application technical specialist for assets connected to isolated environments, NIPRNet and SIPRNet to support cybersecurity and IT services.
  • Review, identify, and report problems with the installation and operations of application instances to include system options, software used and not used, default security controls that are enabled, disabled, or bypassed, and system wide options or parameters that may create security vulnerabilities.
  • Determine the impact and risk of submitted change requests prior to implementation and participate in change advisory board (CAB) meetings (up to daily) to provide cyber oversight for database changes that affect the level of risk.
  • Recommend security countermeasures to mitigate identified application risks.
Application Vulnerability Analysis:
  • Identify, monitor, analyze, report, and brief status of vulnerabilities.
  • Ensure high risk and high severity vulnerabilities are managed with increased visibility and escalated.
  • Analyze, validate, monitor, and report compliance status of DoD and DISA directives and orders.           
  • Create, maintain, and provide automated and customized vulnerability reports.
  • Analyze mission requirements and organizational feedback to improve vulnerability reports and processes.
  • Provide recommendations for application vulnerability analysis, guidance, deficiency resolution, and implementation suggestions to DISA customers and Mission Partners.
Application Compliance Validation and Support:
  • Assess, audit, review, analyze, validate, and report database Security Requirements Guide (SRG) and STIG vulnerabilities, and ensure security controls are implemented within databases IAW DoD, DISA and cybersecurity policies and procedures.
  • Evaluate discrepancies as they relate to policy, orders, and database SRG and/or STIGs, and document recommended additions, deletions, or changes.
  • Identify and report the need to add technical guidance for modification of policies and orders.
  • Review and validate the installation and configuration of cyber tools on assets, and report deficiencies.
  • Review database SRG and/or STIGs as updates are released, and report changes with the potential to have significant impact.
  • Determine the impact and risk of submitted change requests prior to implementation and participate in meetings to provide cyber oversight for web changes that affect the level of risk.
  • Recommend security countermeasures to mitigate identified web risks.
  • Participate in audits and provide documentation (up to daily).
Deliverables:
  • Daily/weekly/monthly/quarterly/annual vulnerability analysis reports
  • Also includes Deliverables that apply to all tasks listed in section 6, Performance Requirements.
~~~~~~~~~~~~~~~
About PD Inc International (PD Inc): PD Inc is a leading high-tech firm as well as an applied think tank and solutions provider.  Our team has been providing expertise and solutions to the US Government (Department of Defense, Department of State, Department of Homeland Security, Veterans Affairs, etc.) and to commercial clients for over 20-years.  
We perform software development and complex technical implementation daily.  We conduct R&D, prototyping, and develop hardware and software solutions for our clients.  Our qualified personnel--including engineers and technical managers--are capable of performing system integration, technology implementation, and services throughout the federal government and in the private sector.
We have a highly innovative environment, and we foster consistent learning and growth. We encourage our employees to innovate while teaching them discipline and principles. 
PD Inc benefits include highly competitive salary, 401K, health care, paid time off, no-limit Student loan forgiveness (merit based), and we sponsor new/qualified employees for Security Clearance.
Employees can also take advantage of casual dress code, free parking, corporate discounts, and gym memberships.
 
 

Powered by JazzHR

YyCZgvWcdz


PD logo

About PD

Sourced by ZipRecruiter

Industry

It services

Company size

1 - 10 Employees

Headquarters location

Baltimore, MD, US

Year founded

2001