1

Vulnerability Analyst Jobs in Raleigh, NC (NOW HIRING)

Technical Analyst Location: Raleigh, NC (locals only) Duration: 12 Months Client : Direct Client ... vulnerability assessments Manage remediation of issues identified by penetration tests Maintain ...

... vulnerability-first remediation by identifying affected assets and determining the appropriate patch, configuration change, software upgrade, or compensating control. · Analyze patch compliance ...

Hands-on experience in embedded firmware debugging using JTAG-based debuggers and logic analyzers. * Deep understanding of the vulnerability lifecycle, including scanning, CVE management, and risk ...

Hands-on experience in embedded firmware debugging using JTAG-based debuggers and logic analyzers. * Deep understanding of the vulnerability lifecycle, including scanning, CVE management, and risk ...

Vulnerability Management & Remediation Collaborate with engineering and development teams to analyze vulnerabilities, develop remediation plans, and strengthen application security across development ...

Showing results 41-60

Vulnerability Analyst information

See Raleigh, NC salary details

$30.1K

$71.2K

$126.4K

How much do vulnerability analyst jobs pay per year?

As of Aug 23, 2026, the average yearly pay for vulnerability analyst in Raleigh, NC is $71,212.00, according to ZipRecruiter salary data. Most workers in this role earn between $51,000.00 and $84,600.00 per year, depending on experience, location, and employer.

What is a vulnerability analyst?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

What are the typical day-to-day responsibilities of a vulnerability analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

How do you become a vulnerability analyst?

To become a vulnerability analyst, typically one needs a bachelor's degree in cybersecurity, computer science, or a related field, along with knowledge of network protocols, operating systems, and security tools. Gaining experience through internships or entry-level IT roles and obtaining certifications such as CompTIA Security+ or Certified Ethical Hacker can enhance prospects. Strong analytical skills and familiarity with vulnerability scanning tools like Nessus or Qualys are also important.

What does a vulnerability analyst do?

A vulnerability analyst identifies, assesses, and prioritizes security weaknesses in computer systems, networks, and applications. They use tools like vulnerability scanners and follow industry standards to recommend remediation strategies, often working with cybersecurity teams to improve overall security posture.

What are the most commonly searched types of Vulnerability Analyst jobs in Raleigh, NC?

The most popular types of Vulnerability Analyst jobs in Raleigh, NC are:

What job categories do people searching Vulnerability Analyst jobs in Raleigh, NC look for?

The top searched job categories for Vulnerability Analyst jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Vulnerability Analyst jobs?

Cities near Raleigh, NC with the most Vulnerability Analyst job openings:

Infographic showing various Vulnerability Analyst job openings in Raleigh, NC as of August 2026, with employment types broken down into 87% Full Time, 7% Part Time, and 6% Contract. Highlights an 82% Physical, 8% Hybrid, and 10% Remote job distribution, with an average salary of $71,212 per year, or $34.2 per hour.

Cyber Manager - ASM Vulnerability Management - Patching

Deloitte

Raleigh, NC • On-site

$107K - $145K/yr

Full-time

Re-posted 28 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 93 frontline employees who took The Breakroom Quiz

45th of 151 rated financial services


Job description

Are you an experienced cybersecurity professional looking to help organizations reduce cyber risk and improve resilience? At Deloitte & Touche LLP, you'll work with leading organizations to strengthen security, enable innovation, and reduce threat exposure. Join Deloitte's Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team to help clients identify, assess, and reduce their attack surface. In this role, you'll lead remediation efforts, work with cross-functional stakeholders, and deliver solutions aligned to business and security priorities.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering Manager II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...

  • Managing exposure-based remediation and patching activities aligned to CTEM priorities
  • Leading vulnerability and patch management operations across infrastructure, middleware, and applications
  • Prioritizing remediation activities using threat intelligence, exploitability, attack paths, asset criticality, and exposure data
  • Supporting exception management, incident-driven response activities, and process improvements that reduce cyber risk
  • Developing client deliverables, contributing to proposals and points of view, and mentoring junior practitioners

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, the CTEM team helps clients identify exposures, prioritize remediation, and reduce risk across complex technology environments.

Qualifications

Required:

  • 10+ years of experience in information technology, information security, or both
  • Experience leading vulnerability management, patch management, or continuous threat exposure management remediation programs
  • Experience remediating vulnerabilities across Linux, Windows, middleware, and applications using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
  • Experience automating remediation workflows using PowerShell, Bash, Python, JavaScript Object Notation, Ansible, Terraform, or a combination of these
  • Experience using Information Technology Service Management or configuration management database platforms such as ServiceNow to coordinate remediation and report exposure reduction
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, or a related field
  • Experience in a consulting environment or with a Big 4 firm
  • Experience with ServiceNow workflows, automation, or orchestration
  • Experience with frameworks such as the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
  • Experience supporting proposals, statements of work, or work orders

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

#CyberCDR27

Qualifications:

Are you an experienced cybersecurity professional looking to help organizations reduce cyber risk and improve resilience? At Deloitte & Touche LLP, you'll work with leading organizations to strengthen security, enable innovation, and reduce threat exposure. Join Deloitte's Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team to help clients identify, assess, and reduce their attack surface. In this role, you'll lead remediation efforts, work with cross-functional stakeholders, and deliver solutions aligned to business and security priorities.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering Manager II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...

  • Managing exposure-based remediation and patching activities aligned to CTEM priorities
  • Leading vulnerability and patch management operations across infrastructure, middleware, and applications
  • Prioritizing remediation activities using threat intelligence, exploitability, attack paths, asset criticality, and exposure data
  • Supporting exception management, incident-driven response activities, and process improvements that reduce cyber risk
  • Developing client deliverables, contributing to proposals and points of view, and mentoring junior practitioners

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, the CTEM team helps clients identify exposures, prioritize remediation, and reduce risk across complex technology environments.

Qualifications

Required:

  • 10+ years of experience in information technology, information security, or both
  • Experience leading vulnerability management, patch management, or continuous threat exposure management remediation programs
  • Experience remediating vulnerabilities across Linux, Windows, middleware, and applications using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
  • Experience automating remediation workflows using PowerShell, Bash, Python, JavaScript Object Notation, Ansible, Terraform, or a combination of these
  • Experience using Information Technology Service Management or configuration management database platforms such as ServiceNow to coordinate remediation and report exposure reduction
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, or a related field
  • Experience in a consulting environment or with a Big 4 firm
  • Experience with ServiceNow workflows, automation, or orchestration
  • Experience with frameworks such as the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
  • Experience supporting proposals, statements of work, or work orders

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

#CyberCDR27

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom