1

Vulnerability Analyst Jobs in Virginia (NOW HIRING)

Cybersecurity Analyst LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this ... Experience conducting vulnerability assessments * Proficiency in creating detailed security reports

Cybersecurity Analyst LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this ... Experience conducting vulnerability assessments * Proficiency in creating detailed security reports

RF Analyst - Senior

Springfield, VA · On-site

$110 - $140/hr

Develop and refine RF threat models and vulnerability analysis methodologies (e.g., coupling pathways, susceptibility thresholds, system-level impacts).* Provide expert guidance on protective ...

Cybersecurity Analyst LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this ... Experience conducting vulnerability assessments * Proficiency in creating detailed security reports

RF Analyst - Senior

Springfield, VA · On-site

$183K - $224K/yr

Develop and refine RF threat models and vulnerability analysis methodologies (e.g., coupling pathways, susceptibility thresholds, system-level impacts). * Provide expert guidance on protective ...

RF Analyst - Senior

Springfield, VA · On-site

$183K - $224K/yr

Develop and refine RF threat models and vulnerability analysis methodologies (e.g., coupling pathways, susceptibility thresholds, system-level impacts). * Provide expert guidance on protective ...

Skilled in risk management, business risk analysis, and making complex business/risk trade-off recommendations and decisions. * Experience in penetration testing and vulnerability analysis in modern ...

New

Showing results 41-60

Vulnerability Analyst information

See Virginia salary details

$30.7K

$72.6K

$128.9K

How much do vulnerability analyst jobs pay per year?

As of Aug 21, 2026, the average yearly pay for vulnerability analyst in Virginia is $72,633.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,000.00 and $86,300.00 per year, depending on experience, location, and employer.

What is a vulnerability analyst?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

What are the typical day-to-day responsibilities of a vulnerability analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

How do you become a vulnerability analyst?

To become a vulnerability analyst, typically one needs a bachelor's degree in cybersecurity, computer science, or a related field, along with knowledge of network protocols, operating systems, and security tools. Gaining experience through internships or entry-level IT roles and obtaining certifications such as CompTIA Security+ or Certified Ethical Hacker can enhance prospects. Strong analytical skills and familiarity with vulnerability scanning tools like Nessus or Qualys are also important.

What does a vulnerability analyst do?

A vulnerability analyst identifies, assesses, and prioritizes security weaknesses in computer systems, networks, and applications. They use tools like vulnerability scanners and follow industry standards to recommend remediation strategies, often working with cybersecurity teams to improve overall security posture.

What are the most commonly searched types of Vulnerability Analyst jobs in Virginia?

The most popular types of Vulnerability Analyst jobs in Virginia are:

What job categories do people searching Vulnerability Analyst jobs in Virginia look for?

The top searched job categories for Vulnerability Analyst jobs in Virginia are:

What cities in Virginia are hiring for Vulnerability Analyst jobs?

Cities in Virginia with the most Vulnerability Analyst job openings:

Infographic showing various Vulnerability Analyst job openings in Virginia as of August 2026, with employment types broken down into 81% Full Time, 14% Part Time, and 5% Contract. Highlights an 80% Physical, 9% Hybrid, and 11% Remote job distribution, with an average salary of $72,633 per year, or $34.9 per hour.

Vulnerability Assessment Analyst - Intermediate

RiVidium, Inc

Springfield, VA • On-site

Full-time

Posted 24 days ago


Job description

Full-Time/Part-Time
Full-Time
Description
RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.
TASKS:
  • Analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.
  • Conduct and/or support authorized penetration testing on enterprise network assets.
  • Maintain deployable cyber defense audit toolkit (e.g., specialized cyber defense software and hardware) to support cyber defense audit missions.
  • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Prepare audit reports that identify technical and procedural findings, and provide recommended remediation strategies/solutions.
  • Conduct required reviews as appropriate within environment (e.g., Technical Surveillance, Countermeasure Reviews [TSCM], TEMPEST countermeasure reviews).
  • Perform technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., local computing environment, network and infrastructure, enclave boundary, supporting infrastructure, and applications).
  • Make recommendations regarding the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems and processes).

ABILITIES:
  • Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems.
  • Skill in assessing the robustness of security systems and designs.
  • Skill in detecting host and network based intrusions via intrusion detection technologies (e.g., Snort).
  • Skill in mimicking threat behaviors.
  • Skill in the use of penetration testing tools and techniques.
  • Skill in the use of social engineering techniques. (e.g., phishing, baiting, tailgating, etc.).
  • Skill in using network analysis tools to identify vulnerabilities. (e.g., fuzzing, nmap, etc.).
  • Skill in reviewing logs to identify evidence of past intrusions.
  • Skill in conducting application vulnerability assessments.
  • Skill in performing impact/risk assessments.
  • Skill to develop insights about the context of an organization's threat environment
  • Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

Requirements:
  • Bachelor degree or higher from an accredited college or university
    • Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field.
  • IAT/ IAM Level 2
  • Active TS/SCI clearence

About the Organization
Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology.
EOE Statement
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.
This position is currently accepting applications.