1

Vulnerability Assessment Analyst Jobs (NOW HIRING)

Vulnerability Assessment Analyst (Intermediate) Playlist; E3ABR1D731D00BB); OR * Relevant professional certification or equivalent experience (examples: CEH(P); RCCE Level 1; CompTIA Cloud+; CPTE;

Vulnerability Assessment Analyst (Intermediate) Playlist; E3ABR1D731D00BB); OR * Relevant professional certification or equivalent experience (examples: CEH(P); RCCE Level 1; CompTIA Cloud+; CPTE;

Vulnerability Assessment Analyst (Intermediate) Playlist; E3ABR1D731D00BB); OR * Relevant professional certification or equivalent experience (examples: CEH(P); RCCE Level 1; CompTIA Cloud+; CPTE;

Defensive Cyber Assessment Analyst - Senior

Fairfax, VA · On-site

$99K - $128K/yr

The analyst conducts configuration reviews, analyzes vulnerability scan results, collects assessment evidence, documents findings, and supports POA&M updates, remediation tracking, and follow-up ...

Analyze vulnerability scan results to identify potential security risks. * Develop and maintain ... Conduct security assessments of third-party vendors and ensure that their security practices meet ...

next page

Showing results 1-20

Vulnerability Assessment Analyst information

See salary details

$15

$52

$73

How much do vulnerability assessment analyst jobs pay per hour?

As of Jun 12, 2026, the average hourly pay for vulnerability assessment analyst in the United States is $52.16, according to ZipRecruiter salary data. Most workers in this role earn between $38.22 and $62.74 per hour, depending on experience, location, and employer.

What are some common challenges a Vulnerability Assessment Analyst faces when collaborating with other IT teams?

A Vulnerability Assessment Analyst often works closely with network, systems, and application teams to identify and mitigate security risks. One common challenge is effectively communicating technical findings in a way that is understandable and actionable for non-security specialists. Additionally, prioritizing vulnerabilities based on business impact and coordinating remediation efforts across different teams can be complex, especially in large organizations. Building strong relationships and maintaining clear communication channels are key to overcoming these challenges and ensuring timely resolution of security issues.

What is the difference between Vulnerability Assessment Analyst vs Penetration Tester?

AspectVulnerability Assessment AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, CISSP (preferred)OSCP, CEH, GPEN
Work EnvironmentConducts assessments within organizations' security teams, often in office settingsPerforms simulated attacks, often in controlled or client environments
Industry UsageUsed across various industries for identifying security weaknessesMore common in cybersecurity consulting and offensive security roles

While both roles focus on security vulnerabilities, Vulnerability Assessment Analysts primarily identify and report weaknesses, whereas Penetration Testers actively exploit vulnerabilities to test security defenses. The roles often overlap but differ in scope and approach, with Analysts focusing on assessment and reporting, and Penetration Testers on active exploitation.

What does a Vulnerability Assessment Analyst do?

A Vulnerability Assessment Analyst is responsible for identifying, evaluating, and prioritizing security vulnerabilities within an organization’s IT systems and networks. They use specialized tools to scan for weaknesses, analyze the results, and provide actionable recommendations to mitigate risks. Their work helps protect the organization from cyber threats by ensuring that vulnerabilities are addressed before they can be exploited. Additionally, they may assist in developing security policies, conducting penetration tests, and educating staff about security best practices.

What are the key skills and qualifications needed to thrive as a Vulnerability Assessment Analyst, and why are they important?

To thrive as a Vulnerability Assessment Analyst, you need a solid understanding of network security, risk assessment, and vulnerability management, often supported by a degree in cybersecurity or related field. Familiarity with tools like Nessus, Qualys, and Metasploit, as well as certifications such as CompTIA Security+ or CEH, is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify, report, and explain vulnerabilities to technical and non-technical stakeholders. These qualifications are crucial for proactively identifying security risks and helping organizations protect their information assets from potential threats.
More about Vulnerability Assessment Analyst jobs
What cities are hiring for Vulnerability Assessment Analyst jobs? Cities with the most Vulnerability Assessment Analyst job openings:
What states have the most Vulnerability Assessment Analyst jobs? States with the most job openings for Vulnerability Assessment Analyst jobs include:
What job categories do people searching Vulnerability Assessment Analyst jobs look for? The top searched job categories for Vulnerability Assessment Analyst jobs are:
Infographic showing various Vulnerability Assessment Analyst job openings in the United States as of June 2026, with employment types broken down into 98% Full Time, and 2% Part Time. Highlights an 80% Physical, 6% Hybrid, and 14% Remote job distribution, with an average salary of $108,489 per year, or $52.2 per hour.
Senior Cyber Vulnerability Assessment Analyst

Senior Cyber Vulnerability Assessment Analyst

West Advanced Technologies (WATI)

Springfield, VA • On-site

$104K - $134K/yr

Full-time

Posted 9 days ago


Job description

Senior Cyber Vulnerability Assessment Analyst
Location: Springfield, Virginia
Contract Term: 6 months
Project/Role Description:
The key is someone who can analyze vulnerabilities in connected devices - such as cameras, badges and come up impact, gaps to be filled etc.
Consultant will perform vulnerability assessment vulnerability assessments and gap analysis of operational technology in conjunction with IT systems. An example of the type of assessment is to see how susceptible operational technologies such as cameras, elevators, badge systems, etc. are to vulnerabilities and if so can they lead to a compromise of other systems on the client's network.
Responsibilities
Work closely with client's cyber security team to follow standard vulnerability assessment process, compliance requirements and prepare reports based on findings
Identify gaps in usage of operational technology in conjunction with IT systems and propose options to harden the systems using industry standards, best practices
Create and update Information Assurance artifacts
Create and manage Plans of Actions and Milestones, and perform all duties pertinent to the role of cybersecurity operations engineer
Work closely with various teams to ensure that they understand, appreciate and follow the standard operating procedures (SOP) for cybersecurity in all aspects including infrastructure, connected devices, database, application
Requirements
10+ years of experience as a Cyber Security Engineer/Analyst
Demonstrable experience with vulnerability assessment of physical infrastructure items such as security cameras, badged entry into doors, elevators, wi-fi enabled, network connected conference room cameras etc.
CISSP/CISM certification preferred
Experience with IT Compliance and Risk Management Methodologies Cyber Security Framework, NIST Standards (SP 800-53r5), HIPPA, and FISMA.
Experience with one or more tools such as Netsparker, Tenable, Kenna, Nessus
Strong knowledge of best practices associated with as well as appropriate authoritative guidance for physical security, security risk assessments, critical infrastructure protection, continuity and contingency planning, emergency preparedness, security awareness, and training
Strong analysis and comprehension skills
Ability to provide technical knowledge and information assurance analysis support
Excellent communication skills
Ability to work independently and in a team
Regards
Naresh Damagalla
West Advanced Technologies, Inc
E: *************