1

Vulnerability Analyst Jobs in Raleigh, NC (NOW HIRING)

Runs and delivers monthly security reports such as vulnerability and remediation reports to ... Helps the administration team in budgetary preparation, analysis and resource planning for the ...

As a security analyst at Lucid you will be helping to protect corporate assets, including our world ... vulnerability scans, and internal risk discussions * Proactively identify threats and associated ...

As a security analyst at Lucid you will be helping to protect corporate assets, including our world ... vulnerability scans, and internal risk discussions * Proactively identify threats and associated ...

Collaborate with engineering teams to drive root cause analysis, develop fixes, mitigations, and workarounds, and validate their effectiveness. Manage the full vulnerability lifecycle, including ...

DevSecOps Engineer

Morrisville, NC

$55 - $73.50/hr

Software Composition Analysis (SCA) * Secrets Management and Scanning Tools Review vulnerability findings and collaborate with development teams to remediate issues. Implement automated security ...

Technical Analyst Location: Raleigh, NC (locals only) Duration: 12 Months Client : Direct Client ... vulnerability assessments Manage remediation of issues identified by penetration tests Maintain ...

Showing results 21-40

Vulnerability Analyst information

See Raleigh, NC salary details

$30.1K

$71.2K

$126.4K

How much do vulnerability analyst jobs pay per year?

As of Jul 25, 2026, the average yearly pay for vulnerability analyst in Raleigh, NC is $71,212.00, according to ZipRecruiter salary data. Most workers in this role earn between $51,000.00 and $84,600.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Vulnerability Analyst position, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

What are the typical day-to-day responsibilities of a Vulnerability Analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

What is a Vulnerability Analyst job?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

What are the most commonly searched types of Vulnerability Analyst jobs in Raleigh, NC? The most popular types of Vulnerability Analyst jobs in Raleigh, NC are:
What job categories do people searching Vulnerability Analyst jobs in Raleigh, NC look for? The top searched job categories for Vulnerability Analyst jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Vulnerability Analyst jobs? Cities near Raleigh, NC with the most Vulnerability Analyst job openings:
Infographic showing various Vulnerability Analyst job openings in Raleigh, NC as of July 2026, with employment types broken down into 87% Full Time, 8% Part Time, 1% Temporary, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $71,212 per year, or $34.2 per hour.
Senior Cybersecurity Governance Analyst

Senior Cybersecurity Governance Analyst

Civic Federal Credit Union

Raleigh, NC

$97K - $125K/yr

Other

Posted 3 days ago


Job description

Description

OUR CULTURE

Our organization believes we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of prosperity for all. To this end, we recruit bright, energetic, and talented people to be members of our team. In return, we offer a dynamic workplace that presents opportunities for professional advancement and individual growth. We strive to always display integrity, self-awareness, courage, and respect for one another while continuing to seek opportunities to learn. We really believe that when our employees succeed, our community wins. 


ABOUT THE POSITION

The Senior Cybersecurity Governance Analyst provides second-line oversight of the organization's cybersecurity risk management program by leading security architecture governance, threat-informed risk analysis, vulnerability management oversight, and independent security assurance activities. This role ensures cybersecurity risks are identified, evaluated, communicated, and managed in alignment with the organization's risk appetite, regulatory requirements, and strategic objectives. The Senior Cybersecurity Governance Analyst serves as a key advisor to technology, business, and risk stakeholders by providing independent challenge, governance oversight, and risk-informed recommendations to strengthen the organization's overall cybersecurity posture.


NORMAL DAY-TO-DAY WORK

  1. Conduct independent, risk-based reviews of system, network, application, cloud, and third-party architectures to identify cybersecurity risks and evaluate alignment with security policies, standards, and secure-by-design principles.
  2. Provide governance oversight of network segmentation, identity management, cloud security, and infrastructure security initiatives, identifying risks and recommending appropriate mitigating controls.
  3. Participate in project governance and system development lifecycle processes to ensure cybersecurity risks are identified, assessed, and addressed throughout technology initiatives.
  4. Perform cybersecurity risk assessments for technology initiatives, applications, infrastructure changes, and third-party services, evaluating threats, vulnerabilities, control effectiveness, and residual risk exposure.
  5. Facilitate risk acceptance, exception management, and remediation tracking processes, ensuring cybersecurity risks are appropriately documented, communicated, and managed in alignment with organizational risk tolerance.
  6. Support enterprise and operational risk management activities through risk analysis, reporting, and communication.
  7. Monitor and assess relevant threat intelligence sources and industry threat activity to identify emerging cyber threats and evaluate potential impacts on organizational risk exposure.
  8. Translate threat intelligence into risk informed recommendations for control enhancements, mitigation strategies, and cybersecurity planning.
  9. Provide independent oversight of the vulnerability management program, including review of prioritization methodologies and validation of remediation plans for critical and high-risk vulnerabilities.
  10. Monitor remediation performance against established service level objectives and provide reporting on vulnerability trends, exposure metrics, program effectiveness, and significant risk conditions.
  11. Coordinate and oversee penetration testing, red team assessments, and independent security reviews; evaluate results and ensure identified risks are appropriately addressed and remediated.
  12. Develop and maintain cybersecurity metrics, dashboards, risk reporting, policies, standards, and control frameworks, while contributing to cybersecurity strategy, maturity improvement initiatives, and governance committee activities as a subject matter expert on cybersecurity risk and governance matters.
  13. Display integrity, self-awareness, courage, and respect for staff while ensuring learning agility and flexibility communicating and delegating effectively. Work effectively, collaboratively, and creatively in a team-oriented environment both internally and externally.


JOB QUALIFICATIONS 

Here are a few skills you MUST have to be qualified for this position.

  1. Minimum of 7-9 years of experience in cybersecurity governance, risk management, security architecture, security assurance, vulnerability management, or related disciplines.
  2. Strong understanding of cybersecurity frameworks including NIST Cybersecurity Framework (CSF), NIST SP 800-53, FFIEC ACET, CIS Controls, and industry best practices.
  3. Experience conducting cybersecurity risk assessments and evaluating control effectiveness.
  4. Knowledge of secure architecture principles across cloud, network, application, and identity platforms.
  5. Understanding of threat intelligence, vulnerability management, and cybersecurity risk analysis methodologies.
  6. Experience supporting audits, regulatory examinations, and compliance initiatives.
  7. Strong analytical, communication, presentation, and report writing skills.
  8. Ability to function in a Consumer business office environment and utilize standard office equipment including but not limited to: PC, copier, telephone, etc.
  9. Ability to lift a minimum of 25 lbs. (file boxes, computer).
  10. Travel required on occasion.


Here are a few qualities we'd LIKE for you to have to make you more suited for this position.

  1. BA/BS degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field.
  2. Experience in financial services, credit unions, or highly regulated industries.
  3. Familiarity with threat intelligence frameworks, MITRE ATT&CK, CVSS, and EPSS.
  4. Experience supporting board or executive-level cybersecurity reporting.
  5. Professional certifications such a CISSP, CRISC, CISM, CGRC, CISA, and/or GIAC (GCTI, GSEC, or equivalent).