1

Vulnerability Assessment Jobs (NOW HIRING)

Position Overview The Vulnerability Assessments Engineer conducts comprehensive vulnerability assessments across networks, systems, applications, and third-party vendors, prioritizing risks and ...

Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools. * Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs ...

Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools. * Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs ...

next page

Showing results 1-20

Vulnerability Assessment information

See salary details

$115.5K

$313.5K

$396.5K

How much do vulnerability assessment jobs pay per year?

As of Jun 15, 2026, the average yearly pay for vulnerability assessment in the United States is $313,495.00, according to ZipRecruiter salary data. Most workers in this role earn between $274,000.00 and $353,500.00 per year, depending on experience, location, and employer.

What are some typical responsibilities in a Vulnerability Assessment role?

Professionals in Vulnerability Assessment are responsible for identifying and analyzing security weaknesses in computer systems, networks, and applications. This typically involves running vulnerability scans, conducting manual assessments, interpreting findings, and preparing detailed reports with actionable recommendations. You may also collaborate closely with IT, development, and security operations teams to ensure that identified risks are properly addressed and mitigated. The role often requires staying up to date with the latest threat intelligence and participating in ongoing security improvement initiatives.

What are the key skills and qualifications needed to thrive in the Vulnerability Assessment position, and why are they important?

To excel in Vulnerability Assessment, you need solid knowledge of cybersecurity principles, network protocols, and risk analysis, often supported by a computer science degree and industry certifications such as CEH, OSCP, or CISSP. Familiarity with vulnerability scanning tools (e.g., Nessus, Qualys, OpenVAS) and security information and event management (SIEM) systems is crucial. Analytical thinking, attention to detail, and clear communication are important soft skills for working effectively with IT teams and stakeholders. These qualifications ensure accurate identification, assessment, and communication of security risks, which is vital for protecting organizational assets.

What is a Vulnerability Assessment job?

A Vulnerability Assessment job involves identifying, analyzing, and evaluating security weaknesses in computer systems, networks, and applications. Professionals in this role use automated tools and manual techniques to assess potential threats and provide recommendations for mitigation. They often work with cybersecurity teams to ensure that vulnerabilities are patched before they can be exploited by attackers. The goal is to strengthen an organization's security posture and prevent data breaches or cyberattacks.

More about Vulnerability Assessment jobs
What cities are hiring for Vulnerability Assessment jobs? Cities with the most Vulnerability Assessment job openings:
What are the most commonly searched types of Vulnerability Assessment jobs? The most popular types of Vulnerability Assessment jobs are:
What states have the most Vulnerability Assessment jobs? States with the most job openings for Vulnerability Assessment jobs include:
What job categories do people searching Vulnerability Assessment jobs look for? The top searched job categories for Vulnerability Assessment jobs are:
Infographic showing various Vulnerability Assessment job openings in the United States as of June 2026, with employment types broken down into 11% As Needed, 15% Full Time, 73% Part Time, and 1% Contract. Highlights an 80% Physical, 6% Hybrid, and 14% Remote job distribution, with an average salary of $313,495 per year, or $150.7 per hour.
Vulnerability Assessment Engineer

Vulnerability Assessment Engineer

Paylocity

Schaumburg, IL • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 16 days ago

Be an early applicant


Paylocity rating

8.5

Company rating: 8.5 out of 10

Based on 34 frontline employees who took The Breakroom Quiz

46th of 428 rated business services


Job description

Description:

Paylocity is an award-winning provider of cloud-based HR and payroll software solutions, offering the most complete platform for the modern workforce. The company has become one of the fastest-growing HCM software providers worldwide by offering an intuitive, easy-to-use product suite that helps businesses automate and streamline HR and payroll processes, attract and retain talent, and build a strong workplace culture.


While traditional HR and payroll providers automate basic HR processes such as payroll and benefits administration, Paylocity goes further by developing tools that HR and businesses need to compete for talent and deliver against the expectations of the modern workforce.


We give our employees what they need to succeed, including great benefits and perks! We offer medical, dental, vision, life, disability, and a 401(k) match, as well as perks that support you, your family, and your finances. And if it’s career development you desire, we provide that, too! At Paylocity, people matter most and have always been at the heart of our business.


Help Paylocity enhance communication and enable employees to connect, collaborate, and create from anywhere with a position in Product & Technology!


Want to develop the strategies and principles needed to deliver compelling software? Join our team and help us enhance our all-in-one software platform, elevate our one-of-a-kind technology, and improve the employee experience.


Take your career to the next level at one of G2's Top 100 Software Companies. Explore our Product & Technology positions to see where you fit!


This is a fully remote position, allowing you to work from home or location of record within the U.S. with no in-office requirements. You must be available five days per week during designated work hours. The work arrangement for this role is subject to change based on business needs and individual performance. This may include adjustments to on-site requirements or schedule expectations, as necessary.


Position Overview

The Vulnerability Assessments Engineer conducts comprehensive vulnerability assessments across networks, systems, applications, and third-party vendors, prioritizing risks and coordinating remediation efforts in collaboration with internal teams and system owners. Develops and maintains vulnerability management policies, provides technical analysis and guidance, and ensures consistent reporting through standardized evaluation criteria. Supports cloud security initiatives and identifies opportunities to automate processes for improved scalability and efficiency, while staying current on emerging threats and best practices.


Primary Responsibilities

The below represents the primary duties of the position, others may be assigned as needed. To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Research, identify, assess, and prioritize vendor and third-party security advisories and acts as a bridge between Information Security and system owners to see through the remediation activities.
  • Conduct vulnerability assessments of our organization's networks, systems, and applications
  • Analyze vulnerability scan results to identify potential security risks.
  • Develop and maintain vulnerability management processes, policies, and procedures.
  • Collaborate with other teams to prioritize and remediate identified vulnerabilities.
  • Conduct security assessments of third-party vendors and ensure that their security practices meet our organization's standards.
  • Keep up to date with the latest security threats and vulnerabilities and provide recommendations on how to mitigate them.
  • Provide guidance and training to other teams on vulnerability management best practices.
  • Provide technical advice to associate team members on attacks
  • Perform technical analysis on vulnerabilities emanating from Cloud Security Posture Management (CSPM) tools.
  • Create vulnerability evaluation standards for consistent reporting of vulnerabilities across various platforms
  • Identify opportunities to automate repeatable tasks to solve scale and sustainability challenges associated with vulnerability triage

Education and Experience

  • 5+ years of experience within an information security role
  • Bachelor’s degree in computer science, information security, management information systems, or similar major a plus
  • Knowledge of vulnerability scanning tools and techniques
  • Basic ability to script in one of the programming languages such as Python, Ruby, C#, Java, etc.
  • Experience working with vulnerability scanning tools such as Tenable, CrowdStrike, Rapid7, Qualys, etc,.
  • Experience working with CVSS and ability to research vulnerabilities independently from sources such as NVD, VulndDB, etc,.
  • Familiarity with security frameworks such as NIST, ISO 27001, and CIS Controls
  • Professional certification such as the Security+, CEH, OSCP, AWS Certified Cloud Practitioner, Agile Scrum, CSM, CSPO, PMIACP, GSLC is a plus
  • Strong knowledge of IT ecosystem ranging from hardware network devices, storage systems, workstations, mobile devices, operating systems, and application frameworks
  • Intermediate knowledge of evolving technologies such as containers and cloud security
  • Basic knowledge of common cloud platforms such as AWS, Azure, GCP, etc.
  • Ability to evaluate cloud vulnerabilities resulting from Cloud Security Posture Management (CSPM) Tools such as Wiz, Prisma
  • Stays up to date and current on new threats and new developments in the information security field
  • OWASP standards such as ASVS, Testing Guide, Mobile & API Top 10
  • Experience with writing Burp plugins, opensource security tools, presenting at security conferences, writing technical research papers or publishing CVE is a plus
  • Experience working with Payroll, HR, Time & Labor Management, and Online Benefits Enrollment applications is a plus

Physical requirements

  • Ability to sit for extended periods: The role requires sitting at a desk or workstation for long periods, typically 7-8 hours a day.
  • Use of computer and phone systems: The employee must be able to operate a computer, use phone systems, and type. This includes using multiple software programs and inquiries simultaneously.

Paylocity is an equal-opportunity employer. Paylocity is committed to the full inclusion of all individuals. We recruit, train, compensate, and promote regardless of race, religion, color, national origin, sex, disability, age, veteran status, and other protected status as required by applicable law. At Paylocity, we believe diversity makes us better.


We embrace and encourage our employees’ differences in age, culture, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion or spiritual belief, sexual orientation, socio-economic status, veteran status, and other characteristics that make our employees unique. We actively cultivate these differences through our employee resource groups (ERGs), employee experiences, perspectives, talents, and approaches to drive innovation in the software and services we provide our customers.


We comply with federal and state disability laws and make reasonable accommodations for applicants and employees with disabilities. To request reasonable accommodation in the job application or interview process, please contact accessibility@paylocity.com. This email address is exclusively designated for such requests, aligning with federal and state disability laws. Please do not send resumes to this email address, as they will be removed.


The base pay range for this position is $106k - $130k/yr; however, base pay offered may vary depending on job-related knowledge, skills, and experience. This position is eligible for an annual bonus and restricted stock unit grant based on individual performance in addition to a full range of benefits outlined here. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed. Base pay information is based on market location. Applicants should apply via www.paylocity.com/careers.

Requirements:



What Paylocity employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom