1

Vulnerability Assessor Jobs (NOW HIRING)

Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...

Perform comprehensive vulnerability assessments and continuous monitoring across the organization. * Manage the entire lifecycle of vulnerabilities from discovery, triage, advising, remediation, and ...

New

They are seeking a Vulnerability Assessment professional with extensive experience in business process consulting and vulnerability assessment to join their team. Responsibilities : • At least 5 ...

next page

Showing results 1-20

Vulnerability Assessor information

See salary details

$32.5K

$75.3K

$125.5K

How much do vulnerability assessor jobs pay per year?

As of Jul 30, 2026, the average yearly pay for vulnerability assessor in the United States is $75,259.00, according to ZipRecruiter salary data. Most workers in this role earn between $46,000.00 and $97,000.00 per year, depending on experience, location, and employer.

What are the typical daily responsibilities of a Vulnerability Assessor?

As a Vulnerability Assessor, your daily tasks often include conducting scans of network systems and applications to identify security weaknesses, analyzing assessment results, and preparing detailed reports for technical and non-technical audiences. You’ll frequently review existing security controls, prioritize discovered vulnerabilities based on risk, and collaborate with IT or development teams to recommend remediation steps. Many roles also involve staying updated on the latest threats and participating in team meetings or briefings. This routine helps ensure the organization's cyber defenses remain strong and compliant with industry standards.

What is a Vulnerability Assessor job?

A Vulnerability Assessor is a cybersecurity professional responsible for identifying and evaluating security weaknesses in an organization's systems, networks, and applications. They use tools and techniques to scan for vulnerabilities, analyze potential threats, and provide recommendations to mitigate risks. Their work helps organizations strengthen security defenses and prevent cyber attacks. Vulnerability Assessors often collaborate with security teams, compliance officers, and IT personnel to ensure ongoing protection.

What are the key skills and qualifications needed to thrive in the Vulnerability Assessor position, and why are they important?

To thrive as a Vulnerability Assessor, you need a strong understanding of cybersecurity principles, vulnerability assessment methodologies, and risk analysis, typically supported by a degree in information security or related field. Familiarity with industry-standard tools such as Nessus, OpenVAS, and Nmap, along with certifications like CompTIA Security+ or CEH, is highly valuable. Strong analytical skills, attention to detail, and effective communication help you convey findings clearly and collaborate with diverse teams. These skills are crucial for identifying, prioritizing, and reporting security weaknesses to help organizations proactively manage risks.

More about Vulnerability Assessor jobs
What cities are hiring for Vulnerability Assessor jobs? Cities with the most Vulnerability Assessor job openings:
What are the most commonly searched types of Vulnerability Assessor jobs? The most popular types of Vulnerability Assessor jobs are:
Who are the top companies hiring for Vulnerability Assessor jobs? The top employers for Vulnerability Assessor jobs are:
What states have the most Vulnerability Assessor jobs? States with the most job openings for Vulnerability Assessor jobs include:
Infographic showing various Vulnerability Assessor job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 6% Part Time, 2% Temporary, and 3% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $75,259 per year, or $36.2 per hour.

Vulnerability Assessor

asrcfh

Alexandria, VA • Hybrid

Other

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Vulnerability Assessor

Location: Alexandria, VA (Hybrid – Telework with periodic on-site support as required)
Clearance: Active Secret


Position Overview

ASRC Federal is seeking a Vulnerability Assessor to support the Department of War Education Activity (DoWEA) Enterprise Cyber Program. The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organization’s cybersecurity posture and ensure compliance with DoD Risk Management Framework (RMF) requirements. This role supports Continuous Monitoring (ConMon) activities and works closely with cybersecurity and system teams to enhance DoWEA’s enterprise-wide security operations.


Responsibilities
  • Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools.

  • Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs, and DoDI 8510.01 (RMF).

  • Collaborate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), and system administrators to track remediation and update Plans of Action and Milestones (POA&Ms).

  • Prepare and maintain vulnerability assessment reports and risk summaries for leadership.

  • Support RMF Steps 3–6 and Continuous Monitoring documentation within eMASS.

  • Research and evaluate emerging technologies to identify new or evolving risks and recommend mitigation strategies.


Basic Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline (four additional years of equivalent experience may substitute).

  • Minimum 5+ years of cybersecurity or vulnerability management experience.

  • Active DoD Secret clearance

  • DoD 8570.01-M IAT Level II certification (e.g., Security+ CE, CySA+, CCNA-Security).

  • Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.

  • Strong analytical, documentation, and communication skills.

  • Working knowledge of vulnerability scanning, risk assessment methodologies, and remediation tracking.


Preferred Qualifications
  • Familiarity with DoW (DoD) RMF, eMASS, and DISA STIG/SRG compliance.

  • Understanding of NIST SP 800-53, CNSSI 1253, and DoDI 8510.01 frameworks.

  • Knowledge of common cybersecurity threats, exploits, and attack vectors.

  • Experience supporting federal or DoD IT environments.

  • Positive, proactive approach and ability to collaborate effectively across remote and on-site teams.