1

Vulnerability Analyst Jobs in Virginia (NOW HIRING)

Analyze scan data, validate findings and false positives, and prioritize based on CVSS ... Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis ...

Analyze scan data, validate findings and false positives, and prioritize based on CVSS ... Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis ...

Analyze scan data, validate findings and false positives, and prioritize based on CVSS ... Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis ...

iOS Vulnerability Engineer (Software)

Reston, VA · On-site

$145K/yr

iOS Vulnerability Engineer (Software) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please ... Identify and analyze iOS vulnerabilities * Develop mitigation strategies for discovered issues

iOS Vulnerability Engineer (Software)

Tysons, VA · On-site

$140K/yr

iOS Vulnerability Engineer (Software) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please ... Identify and analyze iOS vulnerabilities * Develop mitigation strategies for discovered issues

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

next page

Showing results 1-20

Vulnerability Analyst information

See Virginia salary details

$30.7K

$72.6K

$128.9K

How much do vulnerability analyst jobs pay per year?

As of Jul 31, 2026, the average yearly pay for vulnerability analyst in Virginia is $72,633.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,000.00 and $86,300.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Vulnerability Analyst position, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

What are the typical day-to-day responsibilities of a Vulnerability Analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

What is a Vulnerability Analyst job?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

What are the most commonly searched types of Vulnerability Analyst jobs in Virginia? The most popular types of Vulnerability Analyst jobs in Virginia are:
What job categories do people searching Vulnerability Analyst jobs in Virginia look for? The top searched job categories for Vulnerability Analyst jobs in Virginia are:
What cities in Virginia are hiring for Vulnerability Analyst jobs? Cities in Virginia with the most Vulnerability Analyst job openings:
Infographic showing various Vulnerability Analyst job openings in Virginia as of July 2026, with employment types broken down into 87% Full Time, 8% Part Time, 1% Temporary, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $72,633 per year, or $34.9 per hour.

Vulnerability Analyst (Remote)

Oxley Enterprises, Inc.

Stafford, VA • Remote

$90K - $118K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 28 days ago


Job description

The following states/districts are excluded from this job ad: AK, CA, CO, CT, DC, HI, LA, MA, MN, MO, NE, NV, NH, NJ, NM, NY, ND, OR, PR, RI, VT, WA, WY

Future Need - Actively Interviewing

Location: Remote in any United States jurisdiction not excluded from this job advertisement.

Defend the security posture of a mission-critical Department of Veterans Affairs (VA) cloud platform. As a Vulnerability Analyst, you will conduct continuous vulnerability scanning across hundreds of applications and drive remediation within defined timelines on Amazon Web Services (AWS) GovCloud.

Position Description: The Vulnerability Analyst conducts ad-hoc, prescribed, and recurring vulnerability scans across infrastructure, containers, applications, and code repositories, coordinating remediation with Operations and Engineering teams.

Minimum/General Experience: 5 years of experience in vulnerability management or security scanning

Minimum Education: Bachelor's Degree in cybersecurity, information technology, or related field; CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred)

Essential Skills/Qualifications:

  • Expert experience conducting ad-hoc, prescribed, and recurring vulnerability scans using Nessus or equivalent scanning tools
  • Expert ability to document and report scan findings in accordance with established processes
  • Excellent experience supporting routine vulnerability scanning of infrastructure, containers, applications, and code repositories
  • Excellent ability to track, report, and ensure remediation of vulnerabilities
  • Excellent knowledge of Continuous Monitoring system security reporting tools
  • Above average ability to support penetration testing, red team activities, and independent security assessments
  • Above average experience validating security control effectiveness through automated testing and configuration validation
  • Experience supporting a federal agency
  • Excellent verbal and written communication skills

General Physical Requirements needed to perform the essential functions of this job may vary based on the location of the assignment.

  • Assignment Location - Remote
  • Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.
  • Typing, communicating, repetitive motions.
  • Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting.
  • Inside environmental conditions with protection from outside elements.

Security: Active Federal Civilian Public Trust clearance

  • U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years

Federal Civilian Public Trust Consists of a review of up to but not limited to:

  • Covers 10 year period and in some instances lifetime events
  • OPM Security Investigations Index (SII)
  • DOD Defense Central Investigations Index (DCII)
  • National Agency Check (NAC) records
  • FBI name check
  • FBI fingerprint check
  • Credit report check
  • Written inquiries to previous employers and references listed on the application for employment
  • Potential interviews with the subject, spouse, neighbors, supervisor, coworkers
  • Law enforcement check
  • Court records check
  • Education check - Attendance and Degrees

Acceptable Credentials

Tasks/activities include, but are not limited to:

  • Conducts ad-hoc, prescribed, and recurring vulnerability scans for platform and all hosted applications
  • Reports scan results to Operations and Engineering team members
  • Conducts patch management, configuration changes, corrective actions, or Plan of Action and Milestones (POA&M) creation
  • Documents and reports scan findings in accordance with VA RMF and POA&M processes including uploading scan results to the appropriate scan repository
  • Performs upkeep of the Continuous Monitoring system security reporting tool and provides high-level reporting to portfolio Information System Owners
  • Ensures routine vulnerability scanning of infrastructure, containers, applications, and code repositories across production, staging, and sandbox environments
  • Tracks, reports, and ensures remediation of vulnerabilities within defined timelines coordinating with Operations and Engineering teams
  • Supports penetration testing, red team activities, and independent security assessments as required
  • Validates security control effectiveness through automated testing, configuration validation, and periodic assessments
  • Contributes vulnerability remediation status summaries to the monthly RMF, security, and Authorization to Operate (ATO) status report

Compensation & Benefits: The annual projected pay range for this position is $90,897 - $118,016 with consideration being given to various factors including but not limited to qualifications, experience, job responsibilities, and geographic location.

Oxley Enterprises, Inc. offers a full array of benefits including:

  • Medical, dental, vision and prescription drug coverage for you and your family.
  • Life Insurance, short-term disability and long-term disability paid for by the Company.
  • Supplemental coverages including Accident, Critical Illness, and Hospital.
  • Additional Life insurance coverage for you and your dependents.
  • 401k plan with various options to select based on your retirement goals.

Oxley Enterprises, Inc. is a certified service-disabled veteran-owned (SDVOSB), veteran-owned (VOSB), and woman-owned small business (WOSB) that has 26 years of experience building and delivering quality IT systems and programs. Oxley is ranked in the INC 5000 7 times (2016, 2017, 2018, 2021, 2023, 2024, 2025). Oxley is a 2019 - 2025 Department of Labor HIRE Vets Medallion Award Winner. Oxley is Virginia Values Veterans certified.

All qualified applicants will receive consideration for employment without regard to any status protected by applicable federal, state, or local law.

If you require a reasonable accommodation to apply for a position at Oxley Enterprises, Inc., please send an email to our Human Resources Department at: careers@oxleyenterprises.com with the following information:

Subject Line: Accommodation Request

Provide a description of your accommodation request

Include your contact information: Full name, Email address, Best number to reach you (optional)

We participate in the E-Verify program. http://www.dhs.gov/E-Verify