1

Vulnerability Assessment Analyst Jobs in Springfield, VA

Responsibilities Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure Analyze vulnerabilities and support ...

next page

Showing results 1-20

Vulnerability Assessment Analyst information

What are some common challenges a vulnerability assessment analyst faces when collaborating with other IT teams?

A Vulnerability Assessment Analyst often works closely with network, systems, and application teams to identify and mitigate security risks. One common challenge is effectively communicating technical findings in a way that is understandable and actionable for non-security specialists. Additionally, prioritizing vulnerabilities based on business impact and coordinating remediation efforts across different teams can be complex, especially in large organizations. Building strong relationships and maintaining clear communication channels are key to overcoming these challenges and ensuring timely resolution of security issues.

What is the difference between Vulnerability Assessment Analyst vs Penetration Tester?

AspectVulnerability Assessment AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, CISSP (preferred)OSCP, CEH, GPEN
Work EnvironmentConducts assessments within organizations' security teams, often in office settingsPerforms simulated attacks, often in controlled or client environments
Industry UsageUsed across various industries for identifying security weaknessesMore common in cybersecurity consulting and offensive security roles

While both roles focus on security vulnerabilities, Vulnerability Assessment Analysts primarily identify and report weaknesses, whereas Penetration Testers actively exploit vulnerabilities to test security defenses. The roles often overlap but differ in scope and approach, with Analysts focusing on assessment and reporting, and Penetration Testers on active exploitation.

What does a vulnerability assessment analyst do?

A Vulnerability Assessment Analyst is responsible for identifying, evaluating, and prioritizing security vulnerabilities within an organization’s IT systems and networks. They use specialized tools to scan for weaknesses, analyze the results, and provide actionable recommendations to mitigate risks. Their work helps protect the organization from cyber threats by ensuring that vulnerabilities are addressed before they can be exploited. Additionally, they may assist in developing security policies, conducting penetration tests, and educating staff about security best practices.

What are the key skills and qualifications needed to thrive as a vulnerability assessment analyst, and why are they important?

To thrive as a Vulnerability Assessment Analyst, you need a solid understanding of network security, risk assessment, and vulnerability management, often supported by a degree in cybersecurity or related field. Familiarity with tools like Nessus, Qualys, and Metasploit, as well as certifications such as CompTIA Security+ or CEH, is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify, report, and explain vulnerabilities to technical and non-technical stakeholders. These qualifications are crucial for proactively identifying security risks and helping organizations protect their information assets from potential threats.
What are popular job titles related to Vulnerability Assessment Analyst jobs in Springfield, VA? For Vulnerability Assessment Analyst jobs in Springfield, VA, the most frequently searched job titles are:
What job categories do people searching Vulnerability Assessment Analyst jobs in Springfield, VA look for? The top searched job categories for Vulnerability Assessment Analyst jobs in Springfield, VA are:
What cities near Springfield, VA are hiring for Vulnerability Assessment Analyst jobs? Cities near Springfield, VA with the most Vulnerability Assessment Analyst job openings:
Infographic showing various Vulnerability Assessment Analyst job openings in Springfield, VA as of August 2026, with employment types broken down into 86% Full Time, and 14% Contract. Highlights an 86% In-person, and 14% Remote job distribution.

VULNERABILITY ASSESSMENT ANALYST

Quantum Research International Inc

Springfield, VA • On-site

Full-time

Posted 3 days ago

New


Job description

Overview:
Quantum Research International, Inc. (Quantum
) is a certified DoD Contractor providing services and products to US/Allied governments and industry in the following main areas: (1) Cybersecurity, High Performance Computing Systems, Cloud Services and Systems; (2) Space and Ground Support Systems; (3) Aviation Systems; (4) Missile Systems; (5) Artificial Intelligence/ Machine Learning Systems and Experimentation/Training; and (6) Audio Visual Systems and Services. Quantum’s Corporate Office is in Huntsville, AL, but Quantum actively hires for positions nationwide and internationally. We pride ourselves on providing high quality support to the U.S. Government and our Nation’s Warfighters. In addition to our corporate office, we have physical locations in Aberdeen; MD; Colorado Springs, CO; Orlando, FL; Crestview, FL; Madison, AL, and Tupelo, MS.


Mission:

As a member of the NGA Defender Cybersecurity Vulnerability Management team, the contractor executes the Vulnerability Management aspect of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 R2 (or subsequent versions) and National Geospatial-Intelligence Agency's (NGA) RMF Implementation Guide (RIG) for all NGA-authorized systems. This position supports NGA in Springfield, VA and is on-site only. No remote/hybrid work.

Responsibilities:

  • Perform assessments of systems and networks within the network environment or enclave and identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Review, promulgate, and track Cyber Task Orders. Coordinate and assist the relevant information system owners to resolve findings.
  • Develop measures of effectiveness for defense-in-depth architectures against known vulnerabilities.
  • Identify systemic security issues based on the analysis of vulnerability and configuration (STIG) data.
  • Prioritize vulnerability reduction activities based on threat data, vulnerability severity, and mission criticality.
  • Conduct vulnerability scans and mitigate vulnerabilities in security systems.
  • Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations.
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).


Requirements:

  • Bachelor’s degree (technically relevant degree preferred). In lieu of degree, candidates may qualify with experience combined with one of the following: Security+, PenTest+, GSEC, GICSP, GCSA, GCIH, GCED, FITSP-A, CPTE, Cloud+, RCCE Level 1, CEH (Practical).
  • TS/SCI eligible, subject to CI Polygraph.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology or other relevant fields.
  • Experience in vulnerability management using tools such as Nessus, ACAS, Tenable, etc.
  • Knowledge of computer networking concepts and protocols, and network security methodologies, risk management processes (e.g., methods for assessing and mitigating risk), and laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cyber threats and vulnerabilities, and operational impacts of cybersecurity lapses.
  • Knowledge of cryptography and cryptographic key management concepts
  • Knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
  • Ability to collaborate with IT asset owners to create vulnerability remediation plans using a positive customer service mindset.

Desired/Preferred Skills:

  • Experience with vulnerability and/or threat data visualization (Tableau, etc).


#LI-Onsite #LI-JL1

Equal Opportunity Employer/Affirmative Action Employer M/F/D/V:

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity, or any other characteristic protected by law. *Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.