1

Vulnerability Assessment Analyst Jobs in Virginia

next page

Showing results 1-20

Vulnerability Assessment Analyst information

See Virginia salary details

$14

$50

$71

How much do vulnerability assessment analyst jobs pay per hour?

As of Sep 8, 2026, the average hourly pay for vulnerability assessment analyst in Virginia is $50.73, according to ZipRecruiter salary data. Most workers in this role earn between $37.17 and $61.02 per hour, depending on experience, location, and employer.

What does a vulnerability assessment analyst do?

A Vulnerability Assessment Analyst is responsible for identifying, evaluating, and prioritizing security vulnerabilities within an organization’s IT systems and networks. They use specialized tools to scan for weaknesses, analyze the results, and provide actionable recommendations to mitigate risks. Their work helps protect the organization from cyber threats by ensuring that vulnerabilities are addressed before they can be exploited. Additionally, they may assist in developing security policies, conducting penetration tests, and educating staff about security best practices.

What are the key skills and qualifications needed to thrive as a vulnerability assessment analyst, and why are they important?

To thrive as a Vulnerability Assessment Analyst, you need a solid understanding of network security, risk assessment, and vulnerability management, often supported by a degree in cybersecurity or related field. Familiarity with tools like Nessus, Qualys, and Metasploit, as well as certifications such as CompTIA Security+ or CEH, is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify, report, and explain vulnerabilities to technical and non-technical stakeholders. These qualifications are crucial for proactively identifying security risks and helping organizations protect their information assets from potential threats.

What are some common challenges a vulnerability assessment analyst faces when collaborating with other IT teams?

A Vulnerability Assessment Analyst often works closely with network, systems, and application teams to identify and mitigate security risks. One common challenge is effectively communicating technical findings in a way that is understandable and actionable for non-security specialists. Additionally, prioritizing vulnerabilities based on business impact and coordinating remediation efforts across different teams can be complex, especially in large organizations. Building strong relationships and maintaining clear communication channels are key to overcoming these challenges and ensuring timely resolution of security issues.

What is the difference between Vulnerability Assessment Analyst vs Penetration Tester?

AspectVulnerability Assessment AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, CISSP (preferred)OSCP, CEH, GPEN
Work EnvironmentConducts assessments within organizations' security teams, often in office settingsPerforms simulated attacks, often in controlled or client environments
Industry UsageUsed across various industries for identifying security weaknessesMore common in cybersecurity consulting and offensive security roles

While both roles focus on security vulnerabilities, Vulnerability Assessment Analysts primarily identify and report weaknesses, whereas Penetration Testers actively exploit vulnerabilities to test security defenses. The roles often overlap but differ in scope and approach, with Analysts focusing on assessment and reporting, and Penetration Testers on active exploitation.

What are popular job titles related to Vulnerability Assessment Analyst jobs in Virginia?

For Vulnerability Assessment Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Vulnerability Assessment Analyst jobs in Virginia look for?

The top searched job categories for Vulnerability Assessment Analyst jobs in Virginia are:

What cities in Virginia are hiring for Vulnerability Assessment Analyst jobs?

Cities in Virginia with the most Vulnerability Assessment Analyst job openings:

Infographic showing various Vulnerability Assessment Analyst job openings in Virginia as of August 2026, with employment types broken down into 2% As Needed, 79% Full Time, 15% Part Time, 3% Contract, and 1% Nights. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $105,509 per year, or $50.7 per hour.

Vulnerability Assessment Analyst

Newport News, VA • On-site

$100 - $125/hr

Other

Posted 7 days ago


Job description

The Vulnerability Assessment Analyst conducts comprehensive vulnerability scanning and analysis across the NNPS network, web applications, business systems, and public-facing web properties. You will work across a large, complex environment and are responsible for producing findings that are accurate, prioritized, and tied to real business risk — not just raw scan output.

Responsibilities
  • Conduct external and internal vulnerability scans of all in-scope NNPS systems and network infrastructure.
  • Assess network security architecture against NIST 800-53 controls and identify gaps.
  • Perform web application security assessment across NNPS-hosted and district-utilized applications.
  • Conduct website security assessment of NNPS public-facing web properties.
  • Assess HR, Payroll, and Business Office systems for vulnerabilities affecting sensitive employee and financial data.
  • Correlate scan results against NIST 800-53 and produce a prioritized findings report with severity ratings.
  • Work with internal scanning agents as part of the assessment methodology if required.
  • Collaborate with the Senior Penetration Tester to share findings and inform active testing priorities.
RequirementsREQUIRED QUALIFICATIONS
  • 3 or more years of experience conducting vulnerability assessments in enterprise or institutional environments.
  • Proficiency with vulnerability scanning platforms — OpenVAS, Nessus, Qualys, or equivalent.
  • Working knowledge of NIST 800-53 and its application to vulnerability prioritization.
  • Experience conducting web application security assessments.
  • Strong documentation skills — findings must be written clearly with business context, not just raw tool output.
PREFERRED QUALIFICATIONS
  • CEH, CompTIA PenTest+, or equivalent certification.
  • Experience in K-12, higher education, or municipal government environments.
  • Familiarity with OpenVAS specifically — the current scanning tool in the NNPS environment.
  • Experience with FERPA-regulated environments.
#J-18808-Ljbffr