1

Vulnerability Assessment Analyst Jobs (NOW HIRING)

Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools. * Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs ...

Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools. * Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs ...

Responsibilities Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure Analyze vulnerabilities and support ...

Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis activities in alignment with our customer. This role is responsible for conducting ...

Responsibilities • Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure • Analyze vulnerabilities and ...

Showing results 21-40

Vulnerability Assessment Analyst information

See salary details

$15

$52

$73

How much do vulnerability assessment analyst jobs pay per hour?

As of Jul 24, 2026, the average hourly pay for vulnerability assessment analyst in the United States is $52.16, according to ZipRecruiter salary data. Most workers in this role earn between $38.22 and $62.74 per hour, depending on experience, location, and employer.

What are some common challenges a Vulnerability Assessment Analyst faces when collaborating with other IT teams?

A Vulnerability Assessment Analyst often works closely with network, systems, and application teams to identify and mitigate security risks. One common challenge is effectively communicating technical findings in a way that is understandable and actionable for non-security specialists. Additionally, prioritizing vulnerabilities based on business impact and coordinating remediation efforts across different teams can be complex, especially in large organizations. Building strong relationships and maintaining clear communication channels are key to overcoming these challenges and ensuring timely resolution of security issues.

What is the difference between Vulnerability Assessment Analyst vs Penetration Tester?

AspectVulnerability Assessment AnalystPenetration Tester
CertificationsCompTIA Security+, CEH, CISSP (preferred)OSCP, CEH, GPEN
Work EnvironmentConducts assessments within organizations' security teams, often in office settingsPerforms simulated attacks, often in controlled or client environments
Industry UsageUsed across various industries for identifying security weaknessesMore common in cybersecurity consulting and offensive security roles

While both roles focus on security vulnerabilities, Vulnerability Assessment Analysts primarily identify and report weaknesses, whereas Penetration Testers actively exploit vulnerabilities to test security defenses. The roles often overlap but differ in scope and approach, with Analysts focusing on assessment and reporting, and Penetration Testers on active exploitation.

What does a Vulnerability Assessment Analyst do?

A Vulnerability Assessment Analyst is responsible for identifying, evaluating, and prioritizing security vulnerabilities within an organization’s IT systems and networks. They use specialized tools to scan for weaknesses, analyze the results, and provide actionable recommendations to mitigate risks. Their work helps protect the organization from cyber threats by ensuring that vulnerabilities are addressed before they can be exploited. Additionally, they may assist in developing security policies, conducting penetration tests, and educating staff about security best practices.

What are the key skills and qualifications needed to thrive as a Vulnerability Assessment Analyst, and why are they important?

To thrive as a Vulnerability Assessment Analyst, you need a solid understanding of network security, risk assessment, and vulnerability management, often supported by a degree in cybersecurity or related field. Familiarity with tools like Nessus, Qualys, and Metasploit, as well as certifications such as CompTIA Security+ or CEH, is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify, report, and explain vulnerabilities to technical and non-technical stakeholders. These qualifications are crucial for proactively identifying security risks and helping organizations protect their information assets from potential threats.
More about Vulnerability Assessment Analyst jobs
What cities are hiring for Vulnerability Assessment Analyst jobs? Cities with the most Vulnerability Assessment Analyst job openings:
What states have the most Vulnerability Assessment Analyst jobs? States with the most job openings for Vulnerability Assessment Analyst jobs include:
What job categories do people searching Vulnerability Assessment Analyst jobs look for? The top searched job categories for Vulnerability Assessment Analyst jobs are:
Infographic showing various Vulnerability Assessment Analyst job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 83% Physical, 7% Hybrid, and 10% Remote job distribution, with an average salary of $108,489 per year, or $52.2 per hour.
Information Assurance Analyst, Journeyman P60

Information Assurance Analyst, Journeyman P60

FEDITC LLC

Indianapolis, IN • On-site

Full-time

Posted yesterday


Job description

FEDITC, LLC is a fast-growing business supporting DoD and other intelligence agencies worldwide. FEDITC develops mission critical national security systems throughout the world directly supporting the Warfighter, DoD Leadership, & the country. We are proud & honored to provide these services.
Overview of position:
We are looking for an Information Assurance Analyst, Journeyman, to work in Indianapolis, IN.
An active Top Secret / SCI (TS/SCI) clearance and United States Citizenship are required to be considered for this position.
Responsibilities
  • Provide vulnerability assessment support for DFAS CCE classified enclaves
  • Assist with security assessments IAW DoD RMF Process
  • Support documentation in eMASS records for CCE
  • Assist with ATO Status process calendar maintenance
  • Support compliance date tracking and Government POC notification
  • Assist with RMF artifact creation and maintenance
  • Support FISCAM audit preparation and documentation
  • Conduct vulnerability scanning and assessment activities
  • Document and track POA&M items
  • Support senior IA analysts with assessment and documentation tasks

Experience/Skills:
  • 5+ years Information Assurance/vulnerability assessment experience
  • DoD 8140 Work Role 541 Vulnerability Assessment Analyst Intermediate qualification
  • Knowledge of DoD Risk Management Framework (RMF)
  • Experience with vulnerability scanning tools (ACAS, Nessus)
  • Familiarity with eMASS documentation
  • Understanding of FISMA and FISCAM requirements
  • Experience with security documentation
  • Knowledge of POA&M management
  • Experience with classified system assessments

Preferred Qualifications:
  • CISSP or CAP certification (upgrade path)
  • Experience with DFAS IA programs
  • Prior DoD vulnerability assessment experience
  • ACAS Experience
  • Experience with JWICS authorization
  • Knowledge of STIG compliance verification
  • Scripting skills for vulnerability automation

Education:
  • Bachelor's degree in Computer Science, Engineering, Information Technology, or a related field

Certifications:
  • CompTIA CySA+
  • CompTIA Cloud+
  • CompTIA Security+
  • CompTIA PenTest+
  • GIAC GCIH
  • GIAC GSEC
  • GIAC GCED
  • GIAC GICSP
  • or higher-level equivalent certification

Clearance:
  • Active Top- Secret/ SCI Clearance is required.
  • Must be a United States Citizen and pass a background check.
  • Maintain applicable security clearance(s) at the level required by the client and/or applicable certification(s) as requested by FEDITC and/or required by FEDITC'S Client(s)/Customer(s)/Prime contractor(s).

FEDITC, LLC. is committed to fostering an inclusive workplace and provides equal employment opportunities (EEO) to all employees and applicants for employment. We do not employ AI tools in our decision-making processes. Regardless of race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran, FEDITC, LLC. ensures that all employment decisions are made in accordance with applicable federal, state, and local laws. Our commitment to non-discrimination in employment extends to every location in which our company operates.