Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Strong experience with vulnerability data analysis, reporting, and remediation support. * Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
Cybersecurity Analyst
Houston, TX · On-site
Conduct security assessments and vulnerability scans, documenting findings and tracking remediation ... Collect and analyze security metrics including alert volumes, incident response times, and ...
Cybersecurity Analyst
Houston, TX · On-site
Conduct security assessments and vulnerability scans, documenting findings and tracking remediation ... Collect and analyze security metrics including alert volumes, incident response times, and ...
Threat Analyst
Houston, TX · On-site
$86K - $111K/yr
The analyst collaborates with internal teams to enhance security operations, participates in ... Facilitate vulnerability management by correlating vuln data with exploits-in-the-wild; prioritize ...
Threat Analyst
Houston, TX · On-site
$86K - $111K/yr
The analyst collaborates with internal teams to enhance security operations, participates in ... Facilitate vulnerability management by correlating vuln data with exploits-in-the-wild; prioritize ...
Security Analyst
Houston, TX · On-site
SUMMARY The Security Analyst detects, manages and reduces the impact of cybersecurity threats to ... Perform vulnerability testing and security assessments * Conduct internal security audits ...
Security Analyst
Houston, TX · On-site
SUMMARY The Security Analyst detects, manages and reduces the impact of cybersecurity threats to ... Perform vulnerability testing and security assessments * Conduct internal security audits ...
Security Analyst
Houston, TX · On-site
SUMMARY The Security Analyst detects, manages and reduces the impact of cybersecurity threats to ... Perform vulnerability testing and security assessments * Conduct internal security audits ...
Security Analyst
Houston, TX · On-site
SUMMARY The Security Analyst detects, manages and reduces the impact of cybersecurity threats to ... Perform vulnerability testing and security assessments * Conduct internal security audits ...
Vulnerability Management Cybersecurity Data Protection (DLP) Lead
Houston, TX · On-site +1
$60 - $65/hr
Vulnerability Management Cybersecurity Data Protection (DLP) Lead Engagement Type: Contract ... Analyze data classification trends and misclassifications, and coordinate user awareness and policy ...
Quick apply
Vulnerability Management Cybersecurity Data Protection (DLP) Lead
Houston, TX · On-site +1
$60 - $65/hr
Vulnerability Management Cybersecurity Data Protection (DLP) Lead Engagement Type: Contract ... Analyze data classification trends and misclassifications, and coordinate user awareness and policy ...
Vulnerability Management Cybersecurity Data Protection (DLP) Lead Engagement Type: Contract ... analysis Develop and enhance sensitivity labeling frameworks, including taxonomy, enforcement ...
Vulnerability Management Cybersecurity Data Protection (DLP) Lead Engagement Type: Contract ... analysis Develop and enhance sensitivity labeling frameworks, including taxonomy, enforcement ...
Internet Analyst
Spring, TX · On-site
Title: Internet Analyst Duration: 12+ month contract Location: Spring, TX Qualifications ... vulnerability remediation. Work also includes change, incident, and problem management to ...
Internet Analyst
Spring, TX · On-site
Title: Internet Analyst Duration: 12+ month contract Location: Spring, TX Qualifications ... vulnerability remediation. Work also includes change, incident, and problem management to ...
Perform risk assessments, vulnerability analysis, and security audits * Develop and maintain network security policies, standards, and procedures * Troubleshoot complex network and security issues
Perform risk assessments, vulnerability analysis, and security audits * Develop and maintain network security policies, standards, and procedures * Troubleshoot complex network and security issues
Incident Response Analyst
Houston, TX · On-site
... vulnerability risk assessments of network environments using both manual procedures and automated analysis tools. • Experience with enterprise security solutions, incident crisis management. • ...
Incident Response Analyst
Houston, TX · On-site
... vulnerability risk assessments of network environments using both manual procedures and automated analysis tools. • Experience with enterprise security solutions, incident crisis management. • ...
Strong analytical, troubleshooting, and problem-solving skills with attention to detail. * Ability ... vulnerability remediation concepts. * Willingness and ability to learn defense and aerospace ...
Strong analytical, troubleshooting, and problem-solving skills with attention to detail. * Ability ... vulnerability remediation concepts. * Willingness and ability to learn defense and aerospace ...
Internet Analyst (F2F)
Spring, TX · On-site
Internet Analyst 12+ month contract Spring, TX local candidates only Qualifications Per the manager ... vulnerability remediation. Work also includes change, incident, and problem management to ...
Internet Analyst (F2F)
Spring, TX · On-site
Internet Analyst 12+ month contract Spring, TX local candidates only Qualifications Per the manager ... vulnerability remediation. Work also includes change, incident, and problem management to ...
IT Security Analyst II
Houston, TX · On-site
... Support vulnerability management and security hygiene activities by reviewing findings ... phishing analysis, incident triage, endpoint investigation, identity-related threats, cloud ...
IT Security Analyst II
Houston, TX · On-site
... Support vulnerability management and security hygiene activities by reviewing findings ... phishing analysis, incident triage, endpoint investigation, identity-related threats, cloud ...
IT Security Analyst II
Houston, TX · On-site
: The IT Security Analyst II is responsible for monitoring, analyzing, and remediating security ... Support vulnerability management and security hygiene activities by reviewing findings ...
IT Security Analyst II
Houston, TX · On-site
: The IT Security Analyst II is responsible for monitoring, analyzing, and remediating security ... Support vulnerability management and security hygiene activities by reviewing findings ...
Key Responsibilities Elicit, analyze, and document business, technical, and regulatory requirements across cybersecurity domains (e.g., IAM, network security, threat detection, vulnerability ...
Key Responsibilities Elicit, analyze, and document business, technical, and regulatory requirements across cybersecurity domains (e.g., IAM, network security, threat detection, vulnerability ...
: The IT Security Analyst II is responsible for monitoring, analyzing, and remediating security ... Support vulnerability management and security hygiene activities by reviewing findings ...
: The IT Security Analyst II is responsible for monitoring, analyzing, and remediating security ... Support vulnerability management and security hygiene activities by reviewing findings ...
Vulnerability Analyst information
See Spring, TX salary details
$27.6K - $35.6K
11% of jobs
$35.6K - $43.6K
9% of jobs
$46.3K is the 25th percentile. Wages below this are outliers.
$43.6K - $51.6K
15% of jobs
$51.6K - $59.6K
15% of jobs
The median wage is $59.9K / yr.
$59.6K - $67.6K
18% of jobs
$73.4K is the 75th percentile. Wages above this are outliers.
$67.6K - $75.6K
11% of jobs
$75.6K - $83.7K
7% of jobs
$83.7K - $91.7K
5% of jobs
$91.7K - $99.7K
4% of jobs
$99.7K - $107.7K
2% of jobs
$107.7K - $115.7K
3% of jobs
$27.6K
$65.2K
$115.7K
How much do vulnerability analyst jobs pay per year?
What are the key skills and qualifications needed to thrive in the Vulnerability Analyst position, and why are they important?
To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.
Is SOC 1 entry level?
What are the typical day-to-day responsibilities of a Vulnerability Analyst?
As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.
Can you make $500,000 a year in cyber security?
Is 40 too old for cyber security?
What does a vulnerability analyst do?
What is a Vulnerability Analyst job?
A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.
Qualys Reporting & Risk Visibility Analyst - Hybrid (Houston or Dallas TX)
AECOMHouston, TX • On-site, Remote
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 23 days ago
AECOM rating
8.1
Based on 58 frontline employees who took The Breakroom Quiz
15th of 78 rated construction
Job description
Work with Us. Change the World.
At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world’s most complex challenges and build legacies for future generations.
There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.
We're one global team driven by our common purpose to deliver a better world. Join us.
Job DescriptionWe are seeking a skilled and motivated professional to join the Qualys support function within the Cybersecurity Engineering team, with an initial focus on reporting and External Attack Surface Management (EASM). This role supports the operation and optimization of the Qualys platform—particularly EASM, CyberSecurity Asset Management (CSAM), and VMDR—to provide accurate visibility, actionable insights, and high-quality reporting that enable effective vulnerability remediation across the enterprise.
While the specific Qualys modules supported by this role may evolve over time, enterprise reporting and risk visibility remain core to the position. This is a senior individual contributor role, requiring deep technical expertise, sound judgment, and the ability to operate independently while influencing outcomes across Cybersecurity, IT, and Executive stakeholders.
This position will offer some flexibility for hybrid work schedules to include both in-office presence and telecommute/virtual work to be based in either Houston or Dallas, TX.
Key Responsibilities:
- Serve as a subject-matter expert for Qualys reporting and risk visibility, providing guidance and support to Cybersecurity, IT Infrastructure, and Executive stakeholders.
- Partner with infrastructure, cloud, and application teams to support remediation efforts by providing accurate data, context, and reporting from the Qualys platform.
- Develop, maintain, and deliver clear, audience-specific reports and dashboards for IT Infrastructure teams, Software Governance, Cybersecurity teams, IT leadership, and Executive leadership.
- Support and optimize Qualys EASM and CSAM to provide accurate visibility into the organization’s external attack surface, including identifying, analyzing, and helping prioritize externally exposed vulnerabilities and risks to enable effective remediation.
- Support and maintain Qualys integrations with ServiceNow to enable accurate vulnerability intake, workflow routing, remediation tracking, and reporting.
- Serve as secondary support for Qualys platform operations, backing up another Cybersecurity Engineering resource and assisting with VMDR configuration, integrations, upgrades, and troubleshooting.
- Expand Qualys reporting and risk-visibility capabilities over time to support additional modules (e.g., TotalCloud, TotalAppSec, and Software Composition Analysis (SCA)) as organizational needs and platform maturity evolve.
- Drive continuous improvements to processes, environments, and overall security posture, ensuring operational efficiency and risk reduction.
Minimum Requirements:
- Bachelor’s degree (BA/BS) and at least 6 years of experience in cybersecurity, IT security, or a related field or demonstrated equivalency of experience and/or education
- Hands-on experience supporting Qualys in an enterprise environment, specifically EASM, CSAM, and VMDR.
- Strong experience with vulnerability data analysis, reporting, and remediation support.
- Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
- Strong analytical, problem-solving, and communication skills.
- Ability to work independently while collaborating effectively across cross-functional teams.
Preferred Qualifications
- Qualys certifications (e.g., Qualys EASM Specialist, Qualys VMDR Specialist).
- Experience with, or demonstrated interest in expanding into, additional Qualys modules such as TotalCloud, TotalAppSec, or SCA.
- Direct experience supporting IT infrastructure teams (e.g., server, network, cloud, or platform operations), enabling effective collaboration and practical, context-aware support.
- Broader cybersecurity experience outside of vulnerability management (e.g., network security, security architecture, cloud security, or security operations).
- Experience integrating Qualys with ServiceNow (e.g., vulnerability intake, ticket creation, workflow automation, or reporting).
- Industry certifications such as CISSP, CEH, CompTIA Security+, or equivalent.
Additional Information
- Sponsorship for US work authorization is not available for this position, now or in the future
- Relocation assistance is not available for this position
About AECOM
AECOM is proud to offer comprehensive benefits to meet the diverse needs of our employees. Depending on your employment status, AECOM benefits may include medical, dental, vision, life, AD&D, disability benefits, paid time off, leaves of absences, voluntary benefits, perks, flexible work options, well-being resources, employee assistance program, business travel insurance, service recognition awards, retirement savings plan, and employee stock purchase plan.
AECOM is the global infrastructure leader, committed to delivering a better world. As a trusted professional services firm powered by deep technical abilities, we solve our clients’ complex challenges in water, environment, energy, transportation and buildings. Our teams partner with public- and private-sector clients to create innovative, sustainable and resilient solutions throughout the project lifecycle – from advisory, planning, design and engineering to program and construction management. AECOM is a Fortune 500 firm that had revenue of $16.1 billion in fiscal year 2025. Learn more at aecom.com.
What makes AECOM a great place to work
You will be part of a global team that champions your growth and career ambitions. Work on groundbreaking projects - both in your local community and on a global scale - that are transforming our industry and shaping the future. With cutting-edge technology and a network of experts, you’ll have the resources to make a real impact. Our award-winning training and development programs are designed to expand your technical expertise and leadership skills, helping you build the career you’ve always envisioned. Here, you’ll find a welcoming workplace built on respect, collaboration and community—where you have the freedom to grow in a world of opportunity.
As an Equal Opportunity Employer, we believe in your potential and are here to help you achieve it. All your information will be kept confidential according to EEO guidelines.