Vulnerability Assessor
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Washington, DC · On-site
$55 - $65/hr
Experience collaborating with key stakeholders to assess, prioritize, and develop actionable plans to address the discovered gaps Capabilities * Provide support for the Board's vulnerability ...
Quick apply
Washington, DC · On-site
$55 - $65/hr
Experience collaborating with key stakeholders to assess, prioritize, and develop actionable plans to address the discovered gaps Capabilities * Provide support for the Board's vulnerability ...
Stafford, VA · On-site +1
$90K - $118K/yr
CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred) Essential Skills/Qualifications: * Expert experience conducting ad-hoc ...
Stafford, VA · On-site +1
$90K - $118K/yr
CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred) Essential Skills/Qualifications: * Expert experience conducting ad-hoc ...
Stafford, VA · Remote
$90K - $118K/yr
CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred) Essential Skills/Qualifications: * Expert experience conducting ad-hoc ...
Quick apply
Stafford, VA · Remote
$90K - $118K/yr
CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred) Essential Skills/Qualifications: * Expert experience conducting ad-hoc ...
Gritter Francona is looking for a Vulnerability Assessment Team Lead to support a potential project with the Department of Homeland Security. The Lead will manage a comprehensive vulnerability ...
Gritter Francona is looking for a Vulnerability Assessment Team Lead to support a potential project with the Department of Homeland Security. The Lead will manage a comprehensive vulnerability ...
Globe, AZ · On-site
Perform comprehensive vulnerability assessments and continuous monitoring across the organization. * Manage the entire lifecycle of vulnerabilities from discovery, triage, advising, remediation, and ...
New
Globe, AZ · On-site
Perform comprehensive vulnerability assessments and continuous monitoring across the organization. * Manage the entire lifecycle of vulnerabilities from discovery, triage, advising, remediation, and ...
New
Stafford, VA · Remote
$90K - $118K/yr
CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred) Essential Skills/Qualifications: * Expert experience conducting ad-hoc ...
Stafford, VA · Remote
$90K - $118K/yr
CompTIA Security+ or Global Information Assurance Certification (GIAC) Enterprise Vulnerability Assessor (GEVA) (preferred) Essential Skills/Qualifications: * Expert experience conducting ad-hoc ...
Gritter Francona is looking for a Vulnerability Assessment Team Lead to support a potential project with the Department of Homeland Security. The Lead will manage a comprehensive vulnerability ...
Gritter Francona is looking for a Vulnerability Assessment Team Lead to support a potential project with the Department of Homeland Security. The Lead will manage a comprehensive vulnerability ...
As a Vulnerability Assessment Analyst at AFS, you will play a pivotal role in safeguarding critical systems by configuring and executing vulnerability scans, analyzing threat intelligence, and ...
As a Vulnerability Assessment Analyst at AFS, you will play a pivotal role in safeguarding critical systems by configuring and executing vulnerability scans, analyzing threat intelligence, and ...
Rothe Development, Inc. (RDI) is seeking a Cybersecurity Risk Vulnerability Analyst II to join their security control assessment, vulnerability assessment, software assurance, and risk assessment ...
Rothe Development, Inc. (RDI) is seeking a Cybersecurity Risk Vulnerability Analyst II to join their security control assessment, vulnerability assessment, software assurance, and risk assessment ...
Springfield, VA · On-site
$104K - $134K/yr
Senior Cyber Vulnerability Assessment Analyst Location: Springfield, Virginia Contract Term: 6 months Project/Role Description: The key is someone who can analyze vulnerabilities in connected devices ...
Springfield, VA · On-site
$104K - $134K/yr
Senior Cyber Vulnerability Assessment Analyst Location: Springfield, Virginia Contract Term: 6 months Project/Role Description: The key is someone who can analyze vulnerabilities in connected devices ...
Reston, VA · Hybrid
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance Required Certification(s): One of the following: Active Certified Information Security Manager or Active ...
Reston, VA · Hybrid
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance Required Certification(s): One of the following: Active Certified Information Security Manager or Active ...
Amyx is seeking to hire a Vulnerability Assessment Analyst-Intermediate to support our Cybersecurity Division and Intel client in the St. Louis, MO area. * Analyze organization's cyber defense ...
Amyx is seeking to hire a Vulnerability Assessment Analyst-Intermediate to support our Cybersecurity Division and Intel client in the St. Louis, MO area. * Analyze organization's cyber defense ...
Reston, VA · On-site
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance Required Certification(s): One of the following: Active Certified Information Security Manager or Active ...
Reston, VA · On-site
$155K - $180K/yr
Vulnerability Assessment (VA) Team Lead Location: Reston, VA Clearance Level: Secret Clearance Required Certification(s): One of the following: Active Certified Information Security Manager or Active ...
The CSVR conducts advanced vulnerability discovery, exploitation development, and security assessment across weapons systems, enterprise networks, and embedded platforms. This position contributes to ...
The CSVR conducts advanced vulnerability discovery, exploitation development, and security assessment across weapons systems, enterprise networks, and embedded platforms. This position contributes to ...
Washington, DC · On-site
$160K - $205K/yr
Everforth ECS is seeking a Top Secret Cleared AI-focused Enterprise Vulnerability Assessment Program with deep experience in vulnerability assessments to support a premier Law Enforcement Agency in ...
Washington, DC · On-site
$160K - $205K/yr
Everforth ECS is seeking a Top Secret Cleared AI-focused Enterprise Vulnerability Assessment Program with deep experience in vulnerability assessments to support a premier Law Enforcement Agency in ...
San Francisco, CA · On-site
They are seeking a Vulnerability Assessment professional with extensive experience in business process consulting and vulnerability assessment to join their team. Responsibilities : • At least 5 ...
San Francisco, CA · On-site
They are seeking a Vulnerability Assessment professional with extensive experience in business process consulting and vulnerability assessment to join their team. Responsibilities : • At least 5 ...
Conduct vulnerability assessments of systems, applications, and networks to identify security weaknesses and recommend remediation. * Analyze system configurations, network traffic, and software ...
Conduct vulnerability assessments of systems, applications, and networks to identify security weaknesses and recommend remediation. * Analyze system configurations, network traffic, and software ...
Washington, DC · On-site
Support vulnerability assessment, security patch management, secure cloud/hybrid engineering, and CDS activities. * Identify, analyze, document, and communicate vulnerabilities and remediation ...
Washington, DC · On-site
Support vulnerability assessment, security patch management, secure cloud/hybrid engineering, and CDS activities. * Identify, analyze, document, and communicate vulnerabilities and remediation ...
Overview Amyx is seeking to hire a Vulnerability Assessment Analyst-Intermediate to support our Cybersecurity Division and Intel client in the St. Louis, MO area. Responsibilities * Analyze ...
Overview Amyx is seeking to hire a Vulnerability Assessment Analyst-Intermediate to support our Cybersecurity Division and Intel client in the St. Louis, MO area. Responsibilities * Analyze ...
$32.5K - $41K
17% of jobs
$46.7K is the 25th percentile. Wages below this are outliers.
$41K - $49.4K
12% of jobs
$49.4K - $57.9K
11% of jobs
$57.9K - $66.3K
5% of jobs
The median wage is $73.4K / yr.
$66.3K - $74.8K
6% of jobs
$74.8K - $83.2K
9% of jobs
$83.2K - $91.7K
13% of jobs
$94K is the 75th percentile. Wages above this are outliers.
$91.7K - $100.1K
10% of jobs
$100.1K - $108.6K
3% of jobs
$108.6K - $117K
11% of jobs
$117K - $125.5K
4% of jobs
$32.5K
$75.3K
$125.5K
As a Vulnerability Assessor, your daily tasks often include conducting scans of network systems and applications to identify security weaknesses, analyzing assessment results, and preparing detailed reports for technical and non-technical audiences. You’ll frequently review existing security controls, prioritize discovered vulnerabilities based on risk, and collaborate with IT or development teams to recommend remediation steps. Many roles also involve staying updated on the latest threats and participating in team meetings or briefings. This routine helps ensure the organization's cyber defenses remain strong and compliant with industry standards.
A Vulnerability Assessor is a cybersecurity professional responsible for identifying and evaluating security weaknesses in an organization's systems, networks, and applications. They use tools and techniques to scan for vulnerabilities, analyze potential threats, and provide recommendations to mitigate risks. Their work helps organizations strengthen security defenses and prevent cyber attacks. Vulnerability Assessors often collaborate with security teams, compliance officers, and IT personnel to ensure ongoing protection.
To thrive as a Vulnerability Assessor, you need a strong understanding of cybersecurity principles, vulnerability assessment methodologies, and risk analysis, typically supported by a degree in information security or related field. Familiarity with industry-standard tools such as Nessus, OpenVAS, and Nmap, along with certifications like CompTIA Security+ or CEH, is highly valuable. Strong analytical skills, attention to detail, and effective communication help you convey findings clearly and collaborate with diverse teams. These skills are crucial for identifying, prioritizing, and reporting security weaknesses to help organizations proactively manage risks.

Other
This job post has expired 1 day ago. Applications are no longer accepted.
Location: Alexandria, VA (Hybrid – Telework with periodic on-site support as required)
Clearance: Active Secret
ASRC Federal is seeking a Vulnerability Assessor to support the Department of War Education Activity (DoWEA) Enterprise Cyber Program. The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organization’s cybersecurity posture and ensure compliance with DoD Risk Management Framework (RMF) requirements. This role supports Continuous Monitoring (ConMon) activities and works closely with cybersecurity and system teams to enhance DoWEA’s enterprise-wide security operations.
Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools.
Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs, and DoDI 8510.01 (RMF).
Collaborate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), and system administrators to track remediation and update Plans of Action and Milestones (POA&Ms).
Prepare and maintain vulnerability assessment reports and risk summaries for leadership.
Support RMF Steps 3–6 and Continuous Monitoring documentation within eMASS.
Research and evaluate emerging technologies to identify new or evolving risks and recommend mitigation strategies.
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline (four additional years of equivalent experience may substitute).
Minimum 5+ years of cybersecurity or vulnerability management experience.
Active DoD Secret clearance
DoD 8570.01-M IAT Level II certification (e.g., Security+ CE, CySA+, CCNA-Security).
Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.
Strong analytical, documentation, and communication skills.
Working knowledge of vulnerability scanning, risk assessment methodologies, and remediation tracking.
Familiarity with DoW (DoD) RMF, eMASS, and DISA STIG/SRG compliance.
Understanding of NIST SP 800-53, CNSSI 1253, and DoDI 8510.01 frameworks.
Knowledge of common cybersecurity threats, exploits, and attack vectors.
Experience supporting federal or DoD IT environments.
Positive, proactive approach and ability to collaborate effectively across remote and on-site teams.