1

Vulnerability Analyst Jobs in Virginia (NOW HIRING)

Vulnerability Analyst

Fairfax, VA · On-site

$100K - $130K/yr

Vulnerability Analyst Location: Fairfax, VA (On-site, full-time) Employment Type: Full-time Status: Contingent upon contract award Signal Hill Technologies is seeking a highly skilled Vulnerability ...

Analyze scan data, validate findings and false positives, and prioritize based on CVSS ... Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis ...

Analyze scan data, validate findings and false positives, and prioritize based on CVSS ... Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis ...

Analyze scan data, validate findings and false positives, and prioritize based on CVSS ... Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis ...

iOS Vulnerability Engineer (Software)

Tysons, VA · On-site

$140K/yr

iOS Vulnerability Engineer (Software) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please ... Identify and analyze iOS vulnerabilities * Develop mitigation strategies for discovered issues

iOS Vulnerability Engineer (Software)

Reston, VA · On-site

$145K/yr

iOS Vulnerability Engineer (Software) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please ... Identify and analyze iOS vulnerabilities * Develop mitigation strategies for discovered issues

next page

Showing results 1-20

Vulnerability Analyst information

See Virginia salary details

$30.7K

$72.6K

$128.9K

How much do vulnerability analyst jobs pay per year?

As of Jul 27, 2026, the average yearly pay for vulnerability analyst in Virginia is $72,633.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,000.00 and $86,300.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Vulnerability Analyst position, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

What are the typical day-to-day responsibilities of a Vulnerability Analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

What is a Vulnerability Analyst job?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

What are the most commonly searched types of Vulnerability Analyst jobs in Virginia? The most popular types of Vulnerability Analyst jobs in Virginia are:
What job categories do people searching Vulnerability Analyst jobs in Virginia look for? The top searched job categories for Vulnerability Analyst jobs in Virginia are:
What cities in Virginia are hiring for Vulnerability Analyst jobs? Cities in Virginia with the most Vulnerability Analyst job openings:
Infographic showing various Vulnerability Analyst job openings in Virginia as of July 2026, with employment types broken down into 87% Full Time, 8% Part Time, 1% Temporary, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $72,633 per year, or $34.9 per hour.

Vulnerability Analyst

Signal Hill Technologies

Fairfax, VA • On-site

$100K - $130K/yr

Other

Medical, Retirement, PTO

Posted 8 days ago


Job description

Vulnerability Analyst


Location: Fairfax, VA (On-site, full-time)

Employment Type: Full-time

Status: Contingent upon contract award


Signal Hill Technologies is seeking a highly skilled Vulnerability Analyst to support our federal client's vulnerability management program. The position is contingent upon contract award and is anticipated as full-time/permanent. This role is responsible for identifying, assessing, and reporting on vulnerabilities across enterprise systems, networks, and applications, and for driving remediation efforts in coordination with system owners and cyber defenders. This position is on-site in Fairfax, VA.


About Signal Hill Technologies

Founded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well-funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands-on support to address each customer's unique cyber risks.


Position Responsibilities

  • Perform technical and non-technical risk and vulnerability assessments across the local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications.
  • Conduct recurring and ad-hoc vulnerability scans using Tenable Nessus (Nessus Professional, Tenable.sc, and/or Tenable.io), and analyze results to identify, prioritize, and track findings through remediation.
  • Prepare audit and assessment reports identifying technical and procedural findings, with clear, actionable remediation and mitigation recommendations for system owners and leadership.
  • Serve as the primary point of contact for system owners, walking them through scan results and advising on remediation priorities.
  • Analyze the organization's cyber defense policies and configurations and evaluate compliance with applicable regulations, directives, and enclave/local policy.
  • Maintain and operate a deployable cyber defense audit toolkit (scanning software/hardware) in support of assessment missions.
  • Maintain current knowledge of applicable cyber defense policies, regulations, and compliance frameworks relevant to vulnerability assessment and auditing (e.g., NIST RMF, DISA STIGs).
  • Measure the effectiveness of defense-in-depth architecture against known and emerging vulnerabilities.
  • Track vulnerability trends and metrics over time, and brief technical and non-technical stakeholders (including leadership) on posture, risk, and compliance status.
  • Coordinate with system/application owners, ISSOs/ISSMs, and engineering teams to validate findings and support timely remediation.
  • Support the development and refinement of vulnerability management processes, scanning schedules, and reporting standards.


Minimum Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related technical field.
  • Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation).
  • 2+ years of experience conducting network, system, or application vulnerability assessments.
  • Prior federal work experience.
  • Strong collaborative and interpersonal skills, with a customer-service mindset, and the ability to clearly communicate technical findings and actionable guidance in a diplomatic and approachable manner.
  • Hands-on, in-depth experience with Tenable products including Tenable Nessus Professional.
  • Working knowledge of network security architecture (topology, protocols, defense-in-depth) and traffic flows across TCP/IP and OSI layers.
  • Experience with operating system hardening standards, such as CIS or DISA STIGS
  • Ability to analyze scan output, correlate findings, and produce clear written reports for both technical and executive audiences.
  • Proficiency with Microsoft Office Suite and SharePoint for documentation and collaboration.


Preferred Qualifications

  • Direct experience supporting a federal civilian agency vulnerability management program.
  • Experience working with legacy operating systems and Linux.
  • Experience developing or delivering vulnerability management training or documentation for technical staff.
  • Certifications: e.g. Security+ CE, CySA+, GSEC or equivalent
  • Knowledge of the MITRE ATT&CK framework


Benefits

  • Compensation: $100k-$130k depending on experience
  • Company health plan
  • 401(k) plan with employer match
  • Paid holidays and paid time off
  • Education reimbursement


----------------

How to Apply

Submit a detailed resume (including complete work history with month/year for each role and all certifications) directly through LinkedIn. Please account for any gaps in employment and specify all relevant training and degrees with the year and month earned.



Signal Hill Technologies is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law.