1

Sr Risk And Vulnerability Analyst Jobs (NOW HIRING)

... risk across the software ecosystem - growing your expertise alongside senior analysts while putting ... Support vulnerability disclosure activities in coordination with researchers, vendors, and ...

... risk across the software ecosystem - growing your expertise alongside senior analysts while putting ... Support vulnerability disclosure activities in coordination with researchers, vendors, and ...

Senior Web Vulnerability Analyst

Fort George G Meade, MD · On-site

$92K - $107K/yr

  • Medical

  • Retirement

  • PTO

Senior Web Vulnerability Analyst Location: Fort Meade, MD 20755 Clearance Level: Active Secret ... Ensure high risk and high severity vulnerabilities are managed with increased visibility and ...

Vulnerability Analyst

Oak Ridge, TN · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

Senior Specialist Job Specialty: Cyber Security What You'll Do The Vulnerability Analyst is ... Perform impact/risk assessments. * Develop insights about the context of an organization's threat ...

Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL ... The Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and ...

Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL ... The Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and ...

Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible for conducting ...

Serves as a senior technical leader within the Security Operations Center (SOC), responsible for ... Maintain detailed risk registers by analyzing threat intelligence and vulnerability data to ...

Principle, Vulnerability Analyst

O Fallon, MO · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Document validation rationale, remediation decisions, residual risk, and closure evidence in ... Mentor analysts and engineers on vulnerability validation, risk-based prioritization, secure ...

Sr Risk Analyst

Newton, MA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

We are seeking an experienced and strategic Senior Cyber Risk Analyst to join our team. This role ... Oversee vulnerability management program effectiveness and risk prioritization * Analyze ...

New

Sr Risk Analyst

Newton, MA · Hybrid

  • Medical

  • Dental

  • Vision

  • Retirement

We are seeking an experienced and strategic Senior Cyber Risk Analyst to join our team. This role ... Oversee vulnerability management program effectiveness and risk prioritization * Analyze ...

New

Principle, Vulnerability Analyst

O Fallon, MO · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... risk reduction across Mastercard's software environment. • This position is for a Principal Vulnerability Analyst who will work directly with application, engineering, product, and security teams ...

Showing results 21-40

Sr Risk And Vulnerability Analyst information

See salary details

$53.5K

$109.8K

$142.5K

How much do sr risk and vulnerability analyst jobs pay per year?

As of Aug 19, 2026, the average yearly pay for sr risk and vulnerability analyst in the United States is $109,846.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,500.00 and $137,000.00 per year, depending on experience, location, and employer.

What does a Sr Risk and Vulnerability Analyst do?

A Sr Risk and Vulnerability Analyst is responsible for identifying, assessing, and mitigating risks and vulnerabilities within an organization’s information systems and processes. They conduct security assessments, analyze potential threats, and recommend strategies to protect assets and data. Their role often involves collaborating with IT, compliance, and management teams to develop risk management policies and respond to emerging security issues. Additionally, they may lead vulnerability testing and ensure the organization meets regulatory and industry standards for cybersecurity.

What are the key skills and qualifications needed to thrive as a Sr Risk and Vulnerability Analyst, and why are they important?

To thrive as a Sr Risk and Vulnerability Analyst, you need in-depth knowledge of cybersecurity principles, risk assessment methodologies, and a relevant degree or certifications such as CISSP or CEH. Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys), SIEM systems, and risk management frameworks (like NIST or ISO 27001) is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex data and collaborate across teams. These competencies are vital for identifying threats, reducing organizational risk, and ensuring robust security defenses.

What are some common challenges faced by a Sr Risk and Vulnerability Analyst, and how can they be addressed?

Sr Risk and Vulnerability Analysts often encounter challenges such as staying updated with rapidly evolving threats, managing a large volume of vulnerabilities, and effectively communicating risks to non-technical stakeholders. Addressing these challenges involves continuous learning, leveraging automated tools for vulnerability management, and developing strong reporting and presentation skills to translate technical findings into actionable business insights. Collaboration with IT, security teams, and business leaders is essential to prioritize and remediate risks efficiently.

What is the difference between Sr Risk And Vulnerability Analyst vs Risk Analyst?

AspectSr Risk And Vulnerability AnalystRisk Analyst
CertificationsCertifications like CISSP, CISA often preferredSimilar certifications, often entry to mid-level
Work EnvironmentFocus on cybersecurity vulnerabilities and risk management in ITBroader risk assessment across financial, operational, or strategic areas
Employer & Industry UsageCommon in cybersecurity, IT, finance sectorsUsed across various industries including finance, insurance, and consulting

The Sr Risk And Vulnerability Analyst specializes in identifying and mitigating cybersecurity vulnerabilities, often requiring advanced certifications and experience. In contrast, a Risk Analyst has a broader scope, assessing risks across multiple business areas. Both roles require analytical skills but differ in focus and industry application.

What cities are hiring for Sr Risk And Vulnerability Analyst jobs?

Cities with the most Sr Risk And Vulnerability Analyst job openings:

What states have the most Sr Risk And Vulnerability Analyst jobs?

States with the most job openings for Sr Risk And Vulnerability Analyst jobs include:

Infographic showing various Sr Risk And Vulnerability Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $109,846 per year, or $52.8 per hour.

Full-time

Posted 29 days ago


Job description

Location: Oak Ridge, TN
Job Title: Vulnerability Analyst 
Career Level From: Associate
Career Level To: Senior Specialist 
Job Specialty: Cyber Security 
 

What You'll Do

The Vulnerability Analyst is responsible for analyzing key data streams and interpreting threats, vulnerabilities, impacts, and likelihood of asset exposure. The aggregation of ingested data informs analysis with key identifiers to generate a holistic view of the enterprise and provide recommended mitigations and/or remediation of possible exploitable assets. The analyst also assists Vulnerability and Compliance Assessment Management with cyber analysis to support requested exception requests. Responsible for cybersecurity assessment/analysis and provides recommendations for Enterprise level systems and applications designs. Involved in a wide range of cybersecurity areas, including system architectures, firewalls, inspection and analysis tools, encryption components and networking architectures. Involved in security reporting and analysis to regulatory agencies.

POSITION DUTIES AND RESPONSBILBILITES

  • Identify systemic security issues based on the analysis of vulnerability and configuration data.
  • Share meaningful insights about the context of an organization's threat environment that improve its risk management posture. 
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, and non-repudiation). 
  • Host/network access control mechanisms (e.g., access control list, capabilities lists). 
  • Conduct vulnerability scans and recognizing vulnerabilities in security systems.
  • Assessing the robustness of security systems and designs.
  • Detecting host and network-based intrusions via intrusion detection technologies (e.g., Snort).
  • Ability to mimic threat behaviors.
  • Support penetration testing tools and techniques.
  • Use social engineering techniques. (e.g., phishing, baiting, tailgating, etc.).
  • Support network analysis tools to identify vulnerabilities. (e.g., fuzzing, nmap, etc.).
  • Review logs to identify evidence of past intrusions.
  • Conduct application vulnerability assessments.
  • Perform impact/risk assessments.
  • Develop insights about the context of an organization's threat environment.
  • Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.
  • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
What You Can Expect
  • Meaningful work and unique opportunities to support missions vital to national and global security
  • Top-notch, dedicated colleagues
  • Generous pay and benefits with a stable organization
  • Career advancement and professional development programs
  • Work-life balance fostered through flexible work options and wellness initiatives