1

Vulnerability Analyst Jobs (NOW HIRING)

Vulnerability Analyst, Journeyman

Herndon, VA ยท On-site

$80K - $128K/yr

Responsibilities We are seeking a highly skilled and innovative Vulnerability Analyst, Journeyman to join our team in the greater DMV area, supporting the Army National Guard. Responsibilities

next page

Showing results 1-20

Vulnerability Analyst information

See salary details

$31K

$73.3K

$130K

How much do vulnerability analyst jobs pay per year?

As of Jun 29, 2026, the average yearly pay for vulnerability analyst in the United States is $73,261.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,500.00 and $87,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Vulnerability Analyst position, and why are they important?

To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.

Is SOC 1 entry level?

A SOC 1 (Service Organization Control 1) report is an audit report used to evaluate internal controls at a service organization, not a job role. For vulnerability analysts, entry-level positions typically require basic knowledge of cybersecurity principles, risk assessment, and familiarity with security tools, but SOC 1 itself is not an entry-level role. Entry-level roles in cybersecurity may involve supporting audits or controls but do not directly correspond to SOC 1 as a position.

What are the typical day-to-day responsibilities of a Vulnerability Analyst?

As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.

Can you make $500,000 a year in cyber security?

Vulnerability analysts typically earn between $70,000 and $130,000 annually, with top-tier professionals in senior or specialized roles potentially earning over $200,000. Achieving a $500,000 salary usually requires advanced positions such as cybersecurity managers, directors, or consultants with extensive experience, certifications, and leadership responsibilities. High salaries in cybersecurity often depend on industry, location, and individual expertise.

Is 40 too old for cyber security?

A Vulnerability Analyst can be of any age, as cybersecurity values skills, experience, and continuous learning. Many professionals successfully transition into cybersecurity later in their careers by gaining relevant certifications like CISSP or CompTIA Security+ and developing technical expertise. Age is generally not a barrier if you have the necessary skills and a strong understanding of security tools and protocols.

What does a vulnerability analyst do?

A vulnerability analyst identifies, assesses, and prioritizes security weaknesses in computer systems, networks, and applications. They use tools like vulnerability scanners and follow industry standards to recommend remediation strategies, often working closely with IT teams to improve cybersecurity defenses.

What is a Vulnerability Analyst job?

A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

More about Vulnerability Analyst jobs
What cities are hiring for Vulnerability Analyst jobs? Cities with the most Vulnerability Analyst job openings:
What are the most commonly searched types of Vulnerability Analyst jobs? The most popular types of Vulnerability Analyst jobs are:
What states have the most Vulnerability Analyst jobs? States with the most job openings for Vulnerability Analyst jobs include:

System Vulnerability Analyst 4

Gormat

Annapolis Junction, MD โ€ข On-site

Full-time

Posted 3 days ago


Job description

We are looking for a System Vulnerability Analyst to identify vulnerabilities of and attacks to the design and operation of a system (H/W, S/W, personnel, procedures, logistics, and physical security) by relating vulnerabilities and attacks to effects on operations and missions supported by those systems. You will compare and contrast various system attack techniques and develop operationally effective countermeasures. You will also produce formal and informal reports, briefings, and perspectives of actual and potential attacks against the systems or missions being studied.

The Level 4 System Vulnerability Analyst shall possess the following capabilities:

  • The ability to exploit captured media and/or investigate computer security incidents in order to derive useful intelligence and/or enable mitigation of network vulnerabilities.
  • Relevant experience must be in the design/development of computer or information systems, programming, computer/network security, vulnerability analysis, penetration testing, computer forensics, and/or systems engineering.
  • Red team experience required.
  • Blue and purple team experience is required.
  • OCONUS Travel is required.
  • Zero Trust Experience rel to CNE, CNO, network infrastructure, architecture and hardening is a plus.
  • Analyst should be comfortable with network analysis, network anomaly detection, IOC's MITRE ATT&CK framework, NIST/ISO 27001 and able to analyze data to discover malicious or unauthorized activity collected from various sources.
  • Minimal python is a plus.
  • Having a pen testing experience is a plus.

Qualifications:

  • Doctoral degree with 7 years of relevant experience.
  • Master's degree with 9 years of relevant experience.
  • Bachelor's Degree with 11 years of relevant experience.
  • Associates degree with 13 years of relevant experience.
  • Degree must be in Computer Science or a related field (e.g. General Engineering, Computer Engineering, System Engineering, Mathematics, Computer Forensics, Cyber Security, Information Technology, Information Assurance, and Information Security.
  • Completion of military training in a relevant area such as JCAC (Joint Cyber Analysis Course), Undergraduate Cyber Training (UCT), Network Warfare Bridge Course (NWBC)/Intermediate Network Warfare Training (INWT), Cyber Defense Operations will be considered towards the relevant experience required (i.e. 20-24 weeks course will count as 6 months of experience, 10-14 weeks will count as 3 months or experience).

Certifications Required:

  • Information Assurance Certification may be required.

TS/SCI with polygraph is required.