1

Vulnerability Analyst Jobs in Virginia (NOW HIRING)

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

Analyze and interpret ACAS scan results to identify, validate, and prioritize vulnerabilities based on severity, exploitability, asset criticality, and organizational risk. Investigate vulnerability ...

Showing results 21-40

Vulnerability Analyst information

See Virginia salary details

$30.7K

$72.6K

$128.9K

How much do vulnerability analyst jobs pay per year?

As of Sep 5, 2026, the average yearly pay for vulnerability analyst in Virginia is $72,633.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,000.00 and $86,300.00 per year, depending on experience, location, and employer.

What is a vulnerability analyst?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

What are the typical day-to-day responsibilities of a vulnerability analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

How do you become a vulnerability analyst?

To become a vulnerability analyst, typically one needs a bachelor's degree in cybersecurity, computer science, or a related field, along with knowledge of network protocols, operating systems, and security tools. Gaining experience through internships or entry-level IT roles and obtaining certifications such as CompTIA Security+ or Certified Ethical Hacker can enhance prospects. Strong analytical skills and familiarity with vulnerability scanning tools like Nessus or Qualys are also important.

What does a vulnerability analyst do?

A vulnerability analyst identifies, assesses, and prioritizes security weaknesses in computer systems, networks, and applications. They use tools like vulnerability scanners and follow industry standards to recommend remediation strategies, often working with cybersecurity teams to improve overall security posture.

What are the most commonly searched types of Vulnerability Analyst jobs in Virginia?

The most popular types of Vulnerability Analyst jobs in Virginia are:

What are popular job titles related to Vulnerability Analyst jobs in Virginia?

For Vulnerability Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Vulnerability Analyst jobs in Virginia look for?

The top searched job categories for Vulnerability Analyst jobs in Virginia are:

What cities in Virginia are hiring for Vulnerability Analyst jobs?

Cities in Virginia with the most Vulnerability Analyst job openings:

Infographic showing various Vulnerability Analyst job openings in Virginia as of August 2026, with employment types broken down into 88% Full Time, 8% Part Time, and 4% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution, with an average salary of $72,633 per year, or $34.9 per hour.

Vulnerability Assessment Analyst

Security 1st Consulting

Newport News, VA • On-site

$90 - $120/hr

Other

Posted 4 days ago


Job description

The Vulnerability Assessment Analyst conducts comprehensive vulnerability scanning and analysis across the NNPS network, web applications, business systems, and public-facing web properties. You will work across a large, complex environment and are responsible for producing findings that are accurate, prioritized, and tied to real business risk — not just raw scan output.

Responsibilities
  • Conduct external and internal vulnerability scans of all in-scope NNPS systems and network infrastructure.
  • Assess network security architecture against NIST 800-53 controls and identify gaps.
  • Perform web application security assessment across NNPS-hosted and district-utilized applications.
  • Conduct website security assessment of NNPS public-facing web properties.
  • Assess HR, Payroll, and Business Office systems for vulnerabilities affecting sensitive employee and financial data.
  • Correlate scan results against NIST 800-53 and produce a prioritized findings report with severity ratings.
  • Work with internal scanning agents as part of the assessment methodology if required.
  • Collaborate with the Senior Penetration Tester to share findings and inform active testing priorities.
RequirementsREQUIRED QUALIFICATIONS
  • 3 or more years of experience conducting vulnerability assessments in enterprise or institutional environments.
  • Proficiency with vulnerability scanning platforms — OpenVAS, Nessus, Qualys, or equivalent.
  • Working knowledge of NIST 800-53 and its application to vulnerability prioritization.
  • Experience conducting web application security assessments.
  • Strong documentation skills — findings must be written clearly with business context, not just raw tool output.
PREFERRED QUALIFICATIONS
  • CEH, CompTIA PenTest+, or equivalent certification.
  • Experience in K-12, higher education, or municipal government environments.
  • Familiarity with OpenVAS specifically — the current scanning tool in the NNPS environment.
  • Experience with FERPA-regulated environments.
#J-18808-Ljbffr