1

Vulnerability Assessment Jobs in Virginia (NOW HIRING)

next page

Showing results 1-20

Vulnerability Assessment information

See Virginia salary details

$114.5K

$310.8K

$393.1K

How much do vulnerability assessment jobs pay per year?

As of Aug 6, 2026, the average yearly pay for vulnerability assessment in Virginia is $310,806.00, according to ZipRecruiter salary data. Most workers in this role earn between $271,600.00 and $350,500.00 per year, depending on experience, location, and employer.

What are the typical responsibilities in a vulnerability assessment role?

Professionals in Vulnerability Assessment are responsible for identifying and analyzing security weaknesses in computer systems, networks, and applications. This typically involves running vulnerability scans, conducting manual assessments, interpreting findings, and preparing detailed reports with actionable recommendations. You may also collaborate closely with IT, development, and security operations teams to ensure that identified risks are properly addressed and mitigated. The role often requires staying up to date with the latest threat intelligence and participating in ongoing security improvement initiatives.

What are the key skills and qualifications needed to thrive in a vulnerability assessment position?

To excel in Vulnerability Assessment, you need solid knowledge of cybersecurity principles, network protocols, and risk analysis, often supported by a computer science degree and industry certifications such as CEH, OSCP, or CISSP. Familiarity with vulnerability scanning tools (e.g., Nessus, Qualys, OpenVAS) and security information and event management (SIEM) systems is crucial. Analytical thinking, attention to detail, and clear communication are important soft skills for working effectively with IT teams and stakeholders. These qualifications ensure accurate identification, assessment, and communication of security risks, which is vital for protecting organizational assets.

What is a vulnerability assessment?

A Vulnerability Assessment job involves identifying, analyzing, and evaluating security weaknesses in computer systems, networks, and applications. Professionals in this role use automated tools and manual techniques to assess potential threats and provide recommendations for mitigation. They often work with cybersecurity teams to ensure that vulnerabilities are patched before they can be exploited by attackers. The goal is to strengthen an organization's security posture and prevent data breaches or cyberattacks.

What are the most commonly searched types of Vulnerability Assessment jobs in Virginia? The most popular types of Vulnerability Assessment jobs in Virginia are:
What are popular job titles related to Vulnerability Assessment jobs in Virginia? For Vulnerability Assessment jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Vulnerability Assessment jobs in Virginia look for? The top searched job categories for Vulnerability Assessment jobs in Virginia are:
What cities in Virginia are hiring for Vulnerability Assessment jobs? Cities in Virginia with the most Vulnerability Assessment job openings:
Infographic showing various Vulnerability Assessment job openings in Virginia as of August 2026, with employment types broken down into 2% As Needed, 76% Full Time, 17% Part Time, 4% Contract, and 1% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $310,806 per year, or $149.4 per hour.

VULNERABILITY ASSESSMENT ANALYST

Quantum Research International Inc

Springfield, VA โ€ข On-site

Full-time

Posted 3 days ago

New


Job description

Overview:
Quantum Research International, Inc. (Quantum
) is a certified DoD Contractor providing services and products to US/Allied governments and industry in the following main areas: (1) Cybersecurity, High Performance Computing Systems, Cloud Services and Systems; (2) Space and Ground Support Systems; (3) Aviation Systems; (4) Missile Systems; (5) Artificial Intelligence/ Machine Learning Systems and Experimentation/Training; and (6) Audio Visual Systems and Services. Quantum’s Corporate Office is in Huntsville, AL, but Quantum actively hires for positions nationwide and internationally. We pride ourselves on providing high quality support to the U.S. Government and our Nation’s Warfighters. In addition to our corporate office, we have physical locations in Aberdeen; MD; Colorado Springs, CO; Orlando, FL; Crestview, FL; Madison, AL, and Tupelo, MS.


Mission:

As a member of the NGA Defender Cybersecurity Vulnerability Management team, the contractor executes the Vulnerability Management aspect of the Risk Management Framework (RMF) in accordance with NIST SP 800-37 R2 (or subsequent versions) and National Geospatial-Intelligence Agency's (NGA) RMF Implementation Guide (RIG) for all NGA-authorized systems. This position supports NGA in Springfield, VA and is on-site only. No remote/hybrid work.

Responsibilities:

  • Perform assessments of systems and networks within the network environment or enclave and identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
  • Review, promulgate, and track Cyber Task Orders. Coordinate and assist the relevant information system owners to resolve findings.
  • Develop measures of effectiveness for defense-in-depth architectures against known vulnerabilities.
  • Identify systemic security issues based on the analysis of vulnerability and configuration (STIG) data.
  • Prioritize vulnerability reduction activities based on threat data, vulnerability severity, and mission criticality.
  • Conduct vulnerability scans and mitigate vulnerabilities in security systems.
  • Analyze web application vulnerability assessments to recommend remediation action for known web application vulnerabilities and misconfigurations.
  • Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).


Requirements:

  • Bachelor’s degree (technically relevant degree preferred). In lieu of degree, candidates may qualify with experience combined with one of the following: Security+, PenTest+, GSEC, GICSP, GCSA, GCIH, GCED, FITSP-A, CPTE, Cloud+, RCCE Level 1, CEH (Practical).
  • TS/SCI eligible, subject to CI Polygraph.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology or other relevant fields.
  • Experience in vulnerability management using tools such as Nessus, ACAS, Tenable, etc.
  • Knowledge of computer networking concepts and protocols, and network security methodologies, risk management processes (e.g., methods for assessing and mitigating risk), and laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cyber threats and vulnerabilities, and operational impacts of cybersecurity lapses.
  • Knowledge of cryptography and cryptographic key management concepts
  • Knowledge of applicable cyber defense policies, regulations, and compliance documents specifically related to cyber defense auditing.
  • Knowledge of what constitutes a network attack and a network attack’s relationship to both threats and vulnerabilities.
  • Ability to collaborate with IT asset owners to create vulnerability remediation plans using a positive customer service mindset.

Desired/Preferred Skills:

  • Experience with vulnerability and/or threat data visualization (Tableau, etc).


#LI-Onsite #LI-JL1

Equal Opportunity Employer/Affirmative Action Employer M/F/D/V:

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity, or any other characteristic protected by law. *Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.