1

Vulnerability Assessment Analyst Jobs (NOW HIRING)

$90 - $120/hr

The Vulnerability Assessment Analyst conducts comprehensive vulnerability scanning and analysis across the NNPS network, web applications, business systems, and public-facing web properties. You will ...

New

$100 - $140/hr

Perform regular vulnerability assessments of multiple device types and Operating Systems using ... Analyze scan results and generate comprehensive vulnerability reports. * Monitor and track ...

New

Vulnerability Assessment Analyst

Dallas, TX · On-site

$107K - $195K/yr

Vulnerability Assessment Analyst Location: Must be local to Richardson, TX and Greenville, TX Clearance: Secret with ability to obtain and maintain TS/SCI. The Decision Advantage Business Area within ...

$108 - $195/hr

Vulnerability Assessment Analyst Location: Must be local to Richardson, TX and Greenville, TX Clearance: Secret with ability to obtain and maintain TS/SCI. The Decision Advantage Business Area within ...

New

$90 - $115/hr

As a Mid-Level Vulnerability Assessment Analyst at Independent Software, you will support vulnerability management and continuous monitoring activities across secure enterprise environments. You will ...

New

Vulnerability Assessment Analyst

Dallas, TX · On-site

$107K - $195K/yr

Vulnerability Assessment Analyst Location: Must be local to Richardson, TX and Greenville, TX Clearance: Secret with ability to obtain and maintain TS/SCI. The Decision Advantage Business Area within ...

next page

Showing results 1-20

Vulnerability Assessment Analyst information

See salary details

$15

$52

$73

How much do vulnerability assessment analyst jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for vulnerability assessment analyst in the United States is $52.16, according to ZipRecruiter salary data. Most workers in this role earn between $38.22 and $62.74 per hour, depending on experience, location, and employer.

What does a vulnerability assessment analyst do?

A Vulnerability Assessment Analyst is responsible for identifying, evaluating, and prioritizing security vulnerabilities within an organization’s IT systems and networks. They use specialized tools to scan for weaknesses, analyze the results, and provide actionable recommendations to mitigate risks. Their work helps protect the organization from cyber threats by ensuring that vulnerabilities are addressed before they can be exploited. Additionally, they may assist in developing security policies, conducting penetration tests, and educating staff about security best practices.

What are the key skills and qualifications needed to thrive as a vulnerability assessment analyst, and why are they important?

To thrive as a Vulnerability Assessment Analyst, you need a solid understanding of network security, risk assessment, and vulnerability management, often supported by a degree in cybersecurity or related field. Familiarity with tools like Nessus, Qualys, and Metasploit, as well as certifications such as CompTIA Security+ or CEH, is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify, report, and explain vulnerabilities to technical and non-technical stakeholders. These qualifications are crucial for proactively identifying security risks and helping organizations protect their information assets from potential threats.

What are some common challenges a vulnerability assessment analyst faces when collaborating with other IT teams?

A Vulnerability Assessment Analyst often works closely with network, systems, and application teams to identify and mitigate security risks. One common challenge is effectively communicating technical findings in a way that is understandable and actionable for non-security specialists. Additionally, prioritizing vulnerabilities based on business impact and coordinating remediation efforts across different teams can be complex, especially in large organizations. Building strong relationships and maintaining clear communication channels are key to overcoming these challenges and ensuring timely resolution of security issues.

What is the difference between Vulnerability Assessment Analyst vs Penetration Tester?

AspectVulnerability Assessment AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, CISSP (preferred)OSCP, CEH, GPEN
Work EnvironmentConducts assessments within organizations' security teams, often in office settingsPerforms simulated attacks, often in controlled or client environments
Industry UsageUsed across various industries for identifying security weaknessesMore common in cybersecurity consulting and offensive security roles

While both roles focus on security vulnerabilities, Vulnerability Assessment Analysts primarily identify and report weaknesses, whereas Penetration Testers actively exploit vulnerabilities to test security defenses. The roles often overlap but differ in scope and approach, with Analysts focusing on assessment and reporting, and Penetration Testers on active exploitation.

More about Vulnerability Assessment Analyst jobs

What cities are hiring for Vulnerability Assessment Analyst jobs?

Cities with the most Vulnerability Assessment Analyst job openings:

Who are the top companies hiring for Vulnerability Assessment Analyst jobs?

The top employers for Vulnerability Assessment Analyst jobs are:

What states have the most Vulnerability Assessment Analyst jobs?

States with the most job openings for Vulnerability Assessment Analyst jobs include:

Infographic showing various Vulnerability Assessment Analyst job openings in the United States as of August 2026, with employment types broken down into 3% As Needed, 79% Full Time, 15% Part Time, and 3% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $108,489 per year, or $52.2 per hour.

$90 - $120/hr

Other

Posted yesterday

New


Job description

The Vulnerability Assessment Analyst conducts comprehensive vulnerability scanning and analysis across the NNPS network, web applications, business systems, and public-facing web properties. You will work across a large, complex environment and are responsible for producing findings that are accurate, prioritized, and tied to real business risk — not just raw scan output.

Responsibilities
  • Conduct external and internal vulnerability scans of all in-scope NNPS systems and network infrastructure.
  • Assess network security architecture against NIST 800-53 controls and identify gaps.
  • Perform web application security assessment across NNPS-hosted and district-utilized applications.
  • Conduct website security assessment of NNPS public-facing web properties.
  • Assess HR, Payroll, and Business Office systems for vulnerabilities affecting sensitive employee and financial data.
  • Correlate scan results against NIST 800-53 and produce a prioritized findings report with severity ratings.
  • Work with internal scanning agents as part of the assessment methodology if required.
  • Collaborate with the Senior Penetration Tester to share findings and inform active testing priorities.
RequirementsREQUIRED QUALIFICATIONS
  • 3 or more years of experience conducting vulnerability assessments in enterprise or institutional environments.
  • Proficiency with vulnerability scanning platforms — OpenVAS, Nessus, Qualys, or equivalent.
  • Working knowledge of NIST 800-53 and its application to vulnerability prioritization.
  • Experience conducting web application security assessments.
  • Strong documentation skills — findings must be written clearly with business context, not just raw tool output.
PREFERRED QUALIFICATIONS
  • CEH, CompTIA PenTest+, or equivalent certification.
  • Experience in K-12, higher education, or municipal government environments.
  • Familiarity with OpenVAS specifically — the current scanning tool in the NNPS environment.
  • Experience with FERPA-regulated environments.
#J-18808-Ljbffr