1

Vulnerability Jobs (NOW HIRING)

Vulnerability Manager Hybrid role - Birmingham on site 2-3 days per week 65,000 - 75,000 per annum (DOE) 12Month Fixed Term Contract We have an exciting opportunity for a Vulnerability Manager to ...

Vulnerability Researcher

Beavercreek, OH ยท On-site

$99.20K - $130K/yr

Vulnerability Researcher Why Join Us? * Innovative Projects: KBR's work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.

Vulnerability Researcher Why Join Us? * Innovative Projects: KBR's work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.

Vulnerability Engineer Vulnerability Engineer Must Have Technical/Functional Skills * Working knowledge of Python for scripting, troubleshooting, and modifying existing data pipelines. * Strong SQL ...

Vulnerability Manager Expected Duration: 18 months Location: Hybrid, candidates should be local to the Austin area Responsibilities include (but are not limited to): Review vulnerability and ...

Vulnerability Analyst

Washington, DC ยท On-site

$99K - $225K/yr

Vulnerability Analyst The Opportunity: As a vulnerability analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the first line of cyber defense for ...

The Global Vulnerability Management Team is hiring a Vulnerability Analyst . Join a highly talented, dynamic and energetic team that's passionate about attack surface reduction and contributing ...

New

The Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and assist others in mitigating vulnerabilities within an organization's information systems. This ...

They are seeking a highly skilled Vulnerability Researcher to support advanced mobile-focused research and development efforts across Android platforms, including vulnerability analysis and low-level ...

New

Vulnerability Manager The preferred candidate will have a total of 10 years' experience in the Information Technology/Information Security industry, with minimum of 5 years of experience performing ...

Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...

New

The Vulnerability Analyst will play an important role to identify, assess, prioritize, report, and assist others in mitigating vulnerabilities within an organization's information systems. This ...

next page

Showing results 1-20

Vulnerability information

See salary details

$37.5K

$107.9K

$143K

How much do vulnerability jobs pay per year?

As of Jun 4, 2026, the average yearly pay for vulnerability in the United States is $107,902.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,000.00 and $117,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Analyst, and why are they important?

To thrive as a Vulnerability Analyst, you need a solid understanding of network security, operating systems, and vulnerability assessment methodologies, typically supported by a degree in cybersecurity or IT and relevant certifications like CompTIA Security+ or CEH. Familiarity with tools such as Nessus, OpenVAS, Metasploit, and vulnerability management platforms is essential. Strong analytical thinking, attention to detail, and effective communication help in identifying risks and explaining findings to diverse stakeholders. These skills ensure timely detection and remediation of security weaknesses, protecting organizations from cyber threats.

What are some common challenges faced by professionals working in vulnerability management roles?

Professionals in vulnerability management often face the challenge of keeping up with constantly evolving threats and newly discovered vulnerabilities. Prioritizing which vulnerabilities to address first, especially in large environments with thousands of potential risks, can be demanding. Collaborating with IT, development, and security teams to ensure timely remediation and maintaining clear communication about risk levels are also essential parts of the role. Additionally, balancing the need for quick patching with the risk of disrupting business operations requires careful judgment.

What are vulnerability analysts?

Vulnerability analysts are cybersecurity professionals who identify, assess, and help remediate security weaknesses in computer systems, networks, and software. They use various tools and techniques to scan for vulnerabilities, analyze threats, and recommend solutions to mitigate risks. Their work is crucial in preventing cyberattacks and ensuring the security of organizational assets. Vulnerability analysts often collaborate with IT and security teams to prioritize and address vulnerabilities based on their potential impact.

Can I make $200,000 a year in cyber security?

Vulnerability analysts and cybersecurity professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and roles in high-demand sectors or management positions. Salaries vary based on location, expertise, and the complexity of the security environment, but high-level cybersecurity roles often reach or exceed this income level.

What is the difference between Vulnerability vs Penetration Tester?

AspectVulnerabilityPenetration Tester
Primary FocusIdentifying security weaknesses and vulnerabilities in systemsSimulating cyberattacks to exploit vulnerabilities and test defenses
CertificationsCompTIA Security+, CEH, OSCP (for some roles)OSCP, CEH, GPEN, CISSP (often overlapping)
Work EnvironmentSecurity analysis, vulnerability scanning, reportingActive testing, exploitation, reporting
Industry UsageSecurity assessment, risk managementSecurity testing, red teaming

Vulnerability specialists focus on identifying weaknesses in systems, while penetration testers actively exploit those vulnerabilities to assess security effectiveness. Both roles require similar certifications and work in cybersecurity, but their methods and objectives differ: vulnerability analysts aim to find issues, whereas penetration testers simulate attacks to evaluate defenses.

More about Vulnerability jobs
What cities are hiring for Vulnerability jobs? Cities with the most Vulnerability job openings:
What are the most commonly searched types of Vulnerability jobs? The most popular types of Vulnerability jobs are:
What states have the most Vulnerability jobs? States with the most job openings for Vulnerability jobs include:
Vulnerability Manager

Vulnerability Manager

Amtis

Birmingham, AL โ€ข Hybrid

Other

Posted 28 days ago


Job description

Job Description Vulnerability Manager Hybrid role - Birmingham on site 2-3 days per week 65,000 - 75,000 per annum (DOE) 12Month Fixed Term Contract We have an exciting opportunity for a Vulnerability Manager to join a highperforming Business Change and Technology function on a 12month fixed term salaried contract. Reporting into the Information Security Manager, you will be responsible for managing, maintaining, and continuously improving the vulnerability management programme across a complex enterprise technology estate. This includes the identification, assessment, prioritisation, and remediation tracking of security vulnerabilities across onpremises systems, cloud environments, networks, applications, and endpoint devices.

This role plays a critical part in ensuring the organisation's technology environment remains secure, resilient, and aligned with internal security policies, legal and regulatory requirements, and industry best practice. The Opportunity - Vulnerability Manager Vulnerability Management & Analysis Lead the endtoend vulnerability management lifecycle, including discovery, scanning, validation, prioritisation, reporting, and remediation tracking. Operate and optimise vulnerability scanning platforms (e.g

Microsoft Defender Vulnerability Management, Edgescan, or equivalent). Conduct regular internal and external vulnerability assessments across infrastructure, applications, and cloud environments. Validate and analyse vulnerability data to ensure findings are accurate, contextualised, and relevant to the organisation's operational environment.

Identify and assess critical vulnerabilities and zeroday threats, determining when expedited remediation is required. Assess vulnerability severity based on realworld exploitability, considering threat intelligence, exposure, asset criticality, and compensating controls. Maintain a defensible position on exploitable vs nonexploitable vulnerabilities, clearly documenting risk decisions and rationale.

Assess and articulate business risk based on exploitability, asset value, and threat intelligence. Remediation Coordination Work closely with internal technical teams and thirdparty partners to ensure vulnerabilities are remediated within agreed SLAs and risk tolerances. Develop remediation plans, monitor progress, and escalate highrisk issues where necessary.

Support patch governance activities, ensuring both routine and emergency patching meets security requirements. Security Governance & Compliance Ensure vulnerability management activities align with internal information security policies, standards, and procedures. Support compliance with relevant regulatory and security frameworks (e.g

GDPR, PCI DSS). Produce regular vulnerability risk reports, dashboards, and KPIs for senior stakeholders. Provide evidence and reporting to support audits, penetration tests, and regulatory reviews.

Threat Intelligence & Continuous Improvement Integrate threat intelligence to prioritise remediation of actively exploited or highrisk vulnerabilities. Recommend and drive improvements to tools, processes, automation, and reporting to enhance programme maturity. Stay current with emerging vulnerabilities, zeroday threats, and vendor advisories.

Support incident response activities where vulnerabilities are linked to potential security events. What You'll Bring Proven experience in vulnerability management, cyber security operations, or a related technical security role. Strong handson experience with vulnerability management tooling (e.g

Microsoft Defender Vulnerability Management, Edgescan, or similar). Solid understanding of cloud platforms (Azure), operating systems (Windows, Linux), networking, and enterprise technologies. Strong knowledge of CVSS scoring, exploit analysis, and riskbased prioritisation.

Experience working in large, complex enterprise environments. Familiarity with regulatory and compliance requirements relevant to vulnerability management. Knowledge of SIEM, SOAR, EDR, and associated security tooling.

Strong analytical skills with the ability to translate technical risk into clear, executivelevel reporting. Experience supporting incident response and investigations. Excellent stakeholder management skills, with the confidence to challenge and influence both technical and nontechnical teams.

Strong understanding of patch management processes and operational constraints in businesscritical environments. Able to manage multiple competing priorities and make pragmatic, riskbased decisions. Qualifications Proven handson experience in vulnerability management or cyber security operations.

Demonstrable understanding of security principles, standards, and methodologies. One or more of the following certifications preferred: CISM, CISSP, CEH, CompTIA Security+, CompTIA CySA+, GIAC GVMS


AMTIS logo

About AMTIS

Sourced by ZipRecruiter

Industry

Guided missile and space vehicle manufacturing

Company size

11 - 50 Employees

Headquarters location

Orlando, FL, US

Year founded

2007

Social media