Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations. * Apply cybersecurity and privacy principles to ...
Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations. * Apply cybersecurity and privacy principles to ...
Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations. * Apply cybersecurity and privacy principles to ...
Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations. * Apply cybersecurity and privacy principles to ...
RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from ...
RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from ...
Senior Cyber Vulnerability Assessment Analyst
Springfield, VA · On-site
$104K - $134K/yr
Senior Cyber Vulnerability Assessment Analyst Location: Springfield, Virginia Contract Term: 6 months Project/Role Description: The key is someone who can analyze vulnerabilities in connected devices ...
Senior Cyber Vulnerability Assessment Analyst
Springfield, VA · On-site
$104K - $134K/yr
Senior Cyber Vulnerability Assessment Analyst Location: Springfield, Virginia Contract Term: 6 months Project/Role Description: The key is someone who can analyze vulnerabilities in connected devices ...
Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and networks within the NE or enclave and identifies ...
Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and networks within the NE or enclave and identifies ...
Title Vulnerability Assessment Analyst - Intermediate Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and ...
Title Vulnerability Assessment Analyst - Intermediate Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a Vulnerability Assessment Analyst who will perform assessments of systems and ...
The Lead will direct a team of analysts responsible for conducting enterprise-wide vulnerability scanning, penetration testing, and specialized assessments (web, database, wireless). This is a ...
The Lead will direct a team of analysts responsible for conducting enterprise-wide vulnerability scanning, penetration testing, and specialized assessments (web, database, wireless). This is a ...
The Lead will direct a team of analysts responsible for conducting enterprise-wide vulnerability scanning, penetration testing, and specialized assessments (web, database, wireless). This is a ...
The Lead will direct a team of analysts responsible for conducting enterprise-wide vulnerability scanning, penetration testing, and specialized assessments (web, database, wireless). This is a ...
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · On-site
$125K - $150K/yr
Analyze vulnerability scan results. Identify security weaknesses and misconfigurations. Assess severity and operational impact of vulnerabilities. Validate remediation effectiveness. Provide ...
Quick apply
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · On-site
$125K - $150K/yr
Analyze vulnerability scan results. Identify security weaknesses and misconfigurations. Assess severity and operational impact of vulnerabilities. Validate remediation effectiveness. Provide ...
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · Hybrid
Software assurance analysis * Security control validation * Technical risk identification ... Vulnerability Assessment, the engineer shall: * Conduct comprehensive vulnerability assessments.
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · Hybrid
Software assurance analysis * Security control validation * Technical risk identification ... Vulnerability Assessment, the engineer shall: * Conduct comprehensive vulnerability assessments.
Vulnerability Assessment (VA) Team Lead
Reston, VA · Hybrid
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance ... The position will lead the analysts that will conduct enterprise-level security assessments and ...
Vulnerability Assessment (VA) Team Lead
Reston, VA · Hybrid
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance ... The position will lead the analysts that will conduct enterprise-level security assessments and ...
Vulnerability Assessment (VA) Team Lead
Reston, VA · On-site
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance ... The position will lead the analysts that will conduct enterprise-level security assessments and ...
Vulnerability Assessment (VA) Team Lead
Reston, VA · On-site
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance ... The position will lead the analysts that will conduct enterprise-level security assessments and ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. * Analyze ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. * Analyze ...
Cybersecurity and Risk Analyst
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. * Analyze ...
Cybersecurity and Risk Analyst
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. * Analyze ...
Cybersecurity and Risk Analyst
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. * Analyze ...
Cybersecurity and Risk Analyst
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. * Analyze ...
Enterprise Vulnerability Assessment Program- AI Focused
Washington, DC · On-site
$160K - $205K/yr
Everforth ECS is seeking a Top Secret Cleared AI-focused Enterprise Vulnerability Assessment ... Use of AI for offense: agent-driven recon, code analysis, payload generation, recon at scale * Use ...
Enterprise Vulnerability Assessment Program- AI Focused
Washington, DC · On-site
$160K - $205K/yr
Everforth ECS is seeking a Top Secret Cleared AI-focused Enterprise Vulnerability Assessment ... Use of AI for offense: agent-driven recon, code analysis, payload generation, recon at scale * Use ...
Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · On-site
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer Task and ... Identify, analyze, document, and communicate vulnerabilities and remediation recommendations.
Quick apply
Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · On-site
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer Task and ... Identify, analyze, document, and communicate vulnerabilities and remediation recommendations.
Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · On-site
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer Task and ... Identify, analyze, document, and communicate vulnerabilities and remediation recommendations.
Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · On-site
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer Task and ... Identify, analyze, document, and communicate vulnerabilities and remediation recommendations.
Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · Hybrid
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer Task and ... Identify, analyze, document, and communicate vulnerabilities and remediation recommendations.
Penetration Testing, Software Assurance and Vulnerability Assessment Engineer
Washington, DC · Hybrid
Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer Task and ... Identify, analyze, document, and communicate vulnerabilities and remediation recommendations.
Responsibilities Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure Analyze vulnerabilities and support ...
Responsibilities Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure Analyze vulnerabilities and support ...
Vulnerability Assessment Analyst information
What are some common challenges a vulnerability assessment analyst faces when collaborating with other IT teams?
What is the difference between Vulnerability Assessment Analyst vs Penetration Tester?
| Aspect | Vulnerability Assessment Analyst | Penetration Tester |
|---|---|---|
| Certifications | CompTIA Security+, CEH, CISSP (preferred) | OSCP, CEH, GPEN |
| Work Environment | Conducts assessments within organizations' security teams, often in office settings | Performs simulated attacks, often in controlled or client environments |
| Industry Usage | Used across various industries for identifying security weaknesses | More common in cybersecurity consulting and offensive security roles |
While both roles focus on security vulnerabilities, Vulnerability Assessment Analysts primarily identify and report weaknesses, whereas Penetration Testers actively exploit vulnerabilities to test security defenses. The roles often overlap but differ in scope and approach, with Analysts focusing on assessment and reporting, and Penetration Testers on active exploitation.
What does a vulnerability assessment analyst do?
What are the key skills and qualifications needed to thrive as a vulnerability assessment analyst, and why are they important?

Full-time
Posted 5 days ago
Job description
Overview:
Quantum Research International, Inc. (Quantum) is a certified DoD Contractor providing services and products to US/Allied governments and industry in the following main areas: (1) Cybersecurity, High Performance Computing Systems, Cloud Services and Systems; (2) Space and Ground Support Systems; (3) Aviation Systems; (4) Missile Systems; (5) Artificial Intelligence/ Machine Learning Systems and Experimentation/Training; and (6) Audio Visual Systems and Services. Quantum’s Corporate Office is in Huntsville, AL, but Quantum actively hires for positions nationwide and internationally. We pride ourselves on providing high quality support to the U.S. Government and our Nation’s Warfighters. In addition to our corporate office, we have physical locations in Aberdeen; MD; Colorado Springs, CO; Orlando, FL; Crestview, FL; Madison, AL, and Tupelo, MS.
Mission:
As a member of the NGA Defender Cybersecurity Vulnerability Management team, the contractor executes the Vulnerability Management aspect of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 R2 (or subsequent versions) and National Geospatial-Intelligence Agency's (NGA) RMF Implementation Guide (RIG) for all NGA-authorized systems. This position supports NGA in Springfield, VA and is on-site only. No remote/hybrid work.
Responsibilities:
- Perform assessments of systems and networks within the network environment or enclave and identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
- Review, promulgate, and track Cyber Task Orders. Coordinate and assist the relevant information system owners to resolve findings.
- Develop measures of effectiveness for defense-in-depth architectures against known vulnerabilities.
- Identify systemic security issues based on the analysis of vulnerability and configuration (STIG) data.
- Prioritize vulnerability reduction activities based on threat data, vulnerability severity, and mission criticality.
- Conduct vulnerability scans and mitigate vulnerabilities in security systems.
- Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations.
- Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
Requirements:
- Bachelor’s degree (technically relevant degree preferred). In lieu of degree, candidates may qualify with experience combined with one of the following: Security+, PenTest+, GSEC, GICSP, GCSA, GCIH, GCED, FITSP-A, CPTE, Cloud+, RCCE Level 1, CEH (Practical).
- TS/SCI eligible, subject to CI Polygraph.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology or other relevant fields.
- Experience in vulnerability management using tools such as Nessus, ACAS, Tenable, etc.
- Knowledge of computer networking concepts and protocols, and network security methodologies, risk management processes (e.g., methods for assessing and mitigating risk), and laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Knowledge of cyber threats and vulnerabilities, and operational impacts of cybersecurity lapses.
- Knowledge of cryptography and cryptographic key management concepts
- Knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
- Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
- Ability to collaborate with IT asset owners to create vulnerability remediation plans using a positive customer service mindset.
Desired/Preferred Skills:
- Experience with vulnerability and/or threat data visualization (Tableau, etc).
#LI-Onsite #LI-JL1
Equal Opportunity Employer/Affirmative Action Employer M/F/D/V:
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity, or any other characteristic protected by law. *Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
About Quantum Research International
Sourced by ZipRecruiter
Industry
Guided missile and space vehicle manufacturing
Company size
201 - 500 Employees
Headquarters location
Huntsville, AL, US
Year founded
1987