1

Sr Risk And Vulnerability Analyst Jobs (NOW HIRING)

Senior Cyber Vulnerability Analyst

Falls Church, VA

$106.70K - $137.60K/yr

The Senior Cyber Vulnerability Analyst will be responsible for providing recommendations for ... Use knowledge of Risk Management Framework (RMF) to map cyber vulnerabilities and mitigations to ...

Oversee analysis of vulnerability outputs (ACAS, Forescout, STIG findings, etc.) to adjudicate risk ... senior VM or programlevel roles. * Deep expertise with ACAS/NESSUS, Forescout/NAC, STIG/SRG ...

Vulnerability Analyst, Senior

Herndon, VA · On-site

$104K - $166K/yr

Oversee analysis of vulnerability outputs (ACAS, Forescout, STIG findings, etc.) to adjudicate risk ... senior VM or program-level roles. * Deep expertise with ACAS/NESSUS, Forescout/NAC, STIG/SRG ...

Vulnerability Analyst, Senior

Herndon, VA · On-site

$104K - $166K/yr

Oversee analysis of vulnerability outputs (ACAS, Forescout, STIG findings, etc.) to adjudicate risk ... senior VM or programlevel roles. * Deep expertise with ACAS/NESSUS, Forescout/NAC, STIG/SRG ...

Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL ... The Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and ...

Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL ... The Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and ...

Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible for conducting ...

next page

Showing results 1-20

People also search for

Sr Risk And Vulnerability Analyst information

See salary details

$53.5K

$109.8K

$142.5K

How much do sr risk and vulnerability analyst jobs pay per year?

As of May 30, 2026, the average yearly pay for sr risk and vulnerability analyst in the United States is $109,846.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,500.00 and $137,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Sr Risk and Vulnerability Analyst, and why are they important?

To thrive as a Sr Risk and Vulnerability Analyst, you need in-depth knowledge of cybersecurity principles, risk assessment methodologies, and a relevant degree or certifications such as CISSP or CEH. Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys), SIEM systems, and risk management frameworks (like NIST or ISO 27001) is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex data and collaborate across teams. These competencies are vital for identifying threats, reducing organizational risk, and ensuring robust security defenses.

What are some common challenges faced by a Sr Risk and Vulnerability Analyst, and how can they be addressed?

Sr Risk and Vulnerability Analysts often encounter challenges such as staying updated with rapidly evolving threats, managing a large volume of vulnerabilities, and effectively communicating risks to non-technical stakeholders. Addressing these challenges involves continuous learning, leveraging automated tools for vulnerability management, and developing strong reporting and presentation skills to translate technical findings into actionable business insights. Collaboration with IT, security teams, and business leaders is essential to prioritize and remediate risks efficiently.

What does a Sr Risk and Vulnerability Analyst do?

A Sr Risk and Vulnerability Analyst is responsible for identifying, assessing, and mitigating risks and vulnerabilities within an organization’s information systems and processes. They conduct security assessments, analyze potential threats, and recommend strategies to protect assets and data. Their role often involves collaborating with IT, compliance, and management teams to develop risk management policies and respond to emerging security issues. Additionally, they may lead vulnerability testing and ensure the organization meets regulatory and industry standards for cybersecurity.

What is the difference between Sr Risk And Vulnerability Analyst vs Risk Analyst?

AspectSr Risk And Vulnerability AnalystRisk Analyst
CertificationsCertifications like CISSP, CISA often preferredSimilar certifications, often entry to mid-level
Work EnvironmentFocus on cybersecurity vulnerabilities and risk management in ITBroader risk assessment across financial, operational, or strategic areas
Employer & Industry UsageCommon in cybersecurity, IT, finance sectorsUsed across various industries including finance, insurance, and consulting

The Sr Risk And Vulnerability Analyst specializes in identifying and mitigating cybersecurity vulnerabilities, often requiring advanced certifications and experience. In contrast, a Risk Analyst has a broader scope, assessing risks across multiple business areas. Both roles require analytical skills but differ in focus and industry application.

More about Sr Risk And Vulnerability Analyst jobs
What cities are hiring for Sr Risk And Vulnerability Analyst jobs? Cities with the most Sr Risk And Vulnerability Analyst job openings:
What states have the most Sr Risk And Vulnerability Analyst jobs? States with the most job openings for Sr Risk And Vulnerability Analyst jobs include:
What job categories do people searching Sr Risk And Vulnerability Analyst jobs look for? The top searched job categories for Sr Risk And Vulnerability Analyst jobs are:

Senior Cyber Vulnerability Analyst

kgs

Falls Church, VA

$106.70K - $137.60K/yr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 16 days ago


Job description

Koniag IT Systems, a Koniag Government Services company, is seeking a Senior Cyber Vulnerability Analyst  with a TS/SCI clearance to support KITS and our government customer in Falls Church, VA. 

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

 

Essential Functions, Responsibilities & Duties may include, but are not limited to:

The incumbent will have a strong background in cyber vulnerability analysis, system architecture reviews, and the RMF framework. The incumbent will also possess the ability to prepare technical briefs and coordinate with senior leaders and stakeholders. The Senior Cyber Vulnerability Analyst will be responsible for providing recommendations for mitigation to protect systems and data from cyber threats. 

Major Duties and Responsibilities 

  • Conduct cyber vulnerability analysis and system architecture reviews to identify and assess potential vulnerabilities in various systems and networks. 
  • Manage communication with technical and non-technical personnel of systems under review, such as system stakeholders and cybersecurity teams. 
  • Use knowledge of Risk Management Framework (RMF) to map cyber vulnerabilities and mitigations to NIST SP 800-53 controls and ensure compliance with regulatory requirements, best practices, and industry standards. 
  • Produce high quality technical and non-technical products, briefings, whitepapers, etc., with emphasis on effective/accurate reporting to improve the security posture of the customer system. 
  • Maintain a comprehensive understanding of the cyber threat landscape, situational awareness of emerging threats, zero days, vulnerabilities and other threats against customer systems, networks, and assets including identifying and analyzing cyber threats actors and/or activities. 
  •  

Minimum Candidate Requirements 

  • 10+ years of experience as a Vulnerability Analyst or similar role, with experience in a defense or government environment preferred. 
  • Expert knowledge of Information Assurance Vulnerability Management (IAVM), to include proficiency with vulnerability scanning tools such as Nessus or similar and correlating cyber vulnerabilities to measurable risk. 
  • Ability to identify indicators of an attack and document preliminary reports for cyber investigative teams, as well as executive-level summary briefings. 
  • Previous experience with associated cyber risk assessment/risk management methodologies-RMF preferred. 
  • Security Pre-Requisite – Must have a CURRENT/ACTIVE TOP SECRET with SCI Eligibility 

Desired Candidate Experience 

  • 15+ years of experience as a Vulnerability Analyst, with experience in a defense or government environment. 
  • Expert knowledge of Information Assurance Vulnerability Management (IAVM), to include proficiency with vulnerability scanning tools such as Nessus or similar and correlating cyber vulnerabilities to measurable risk. 
  • Must be able to identify indicators of an attack and document preliminary reports for cyber investigative teams, as well as executive-level summary briefings. 
  • Extensive experience with associated cyber risk assessment/risk management methodologies such as RMF. 
  • Security Pre-Requisite – Must have a CURRENT/ACTIVE TOP SECRET with SCI Eligibility 

Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352