1

Vulnerability Assessor Jobs (NOW HIRING)

Perform vulnerability assessments utilizing Tenable SecurityCenter, Nessus, and Assured Compliance Assessment Solution (ACAS) across classified and unclassified environments. * Review vulnerability ...

Perform vulnerability assessments utilizing Tenable SecurityCenter, Nessus, and Assured Compliance Assessment Solution (ACAS) across classified and unclassified environments. * Review vulnerability ...

Responsibilities Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure Analyze vulnerabilities and support ...

Understanding of 'hacking' methodology concerning performing a vulnerability assessment * The ability to describe a system's avenues of compromise in a network environment and differentiate between ...

Responsibilities • Perform vulnerability assessments and security scanning across operating systems, databases, web applications, and enterprise infrastructure • Analyze vulnerabilities and ...

Showing results 41-60

Vulnerability Assessor information

See salary details

$32.5K

$75.3K

$125.5K

How much do vulnerability assessor jobs pay per year?

As of Aug 23, 2026, the average yearly pay for vulnerability assessor in the United States is $75,259.00, according to ZipRecruiter salary data. Most workers in this role earn between $46,000.00 and $97,000.00 per year, depending on experience, location, and employer.

What is a vulnerability assessor?

A Vulnerability Assessor is a cybersecurity professional responsible for identifying and evaluating security weaknesses in an organization's systems, networks, and applications. They use tools and techniques to scan for vulnerabilities, analyze potential threats, and provide recommendations to mitigate risks. Their work helps organizations strengthen security defenses and prevent cyber attacks. Vulnerability Assessors often collaborate with security teams, compliance officers, and IT personnel to ensure ongoing protection.

What are the typical daily responsibilities of a vulnerability assessor?

As a Vulnerability Assessor, your daily tasks often include conducting scans of network systems and applications to identify security weaknesses, analyzing assessment results, and preparing detailed reports for technical and non-technical audiences. You’ll frequently review existing security controls, prioritize discovered vulnerabilities based on risk, and collaborate with IT or development teams to recommend remediation steps. Many roles also involve staying updated on the latest threats and participating in team meetings or briefings. This routine helps ensure the organization's cyber defenses remain strong and compliant with industry standards.

What are the key skills and qualifications needed to thrive as a vulnerability assessor, and why are they important?

To thrive as a Vulnerability Assessor, you need a strong understanding of cybersecurity principles, vulnerability assessment methodologies, and risk analysis, typically supported by a degree in information security or related field. Familiarity with industry-standard tools such as Nessus, OpenVAS, and Nmap, along with certifications like CompTIA Security+ or CEH, is highly valuable. Strong analytical skills, attention to detail, and effective communication help you convey findings clearly and collaborate with diverse teams. These skills are crucial for identifying, prioritizing, and reporting security weaknesses to help organizations proactively manage risks.

More about Vulnerability Assessor jobs

What cities are hiring for Vulnerability Assessor jobs?

Cities with the most Vulnerability Assessor job openings:

What are the most commonly searched types of Vulnerability Assessor jobs?

The most popular types of Vulnerability Assessor jobs are:

Who are the top companies hiring for Vulnerability Assessor jobs?

The top employers for Vulnerability Assessor jobs are:

What states have the most Vulnerability Assessor jobs?

States with the most job openings for Vulnerability Assessor jobs include:

Infographic showing various Vulnerability Assessor job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, 3% Part Time, and 6% Contract. Highlights an 81% Physical, 7% Hybrid, and 12% Remote job distribution, with an average salary of $75,259 per year, or $36.2 per hour.

Cyber Vulnerability Assessment Analyst - Intermediate

NewSat North America LLC

Colorado Springs, CO • On-site

$130K - $140K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 9 hours ago

Be Seen First

After you apply to this job, you can share why you’re interested to jump to the top of the candidate list.


Job description

POSITION SUMMARY

NewSat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels.


Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order’s Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas.

KEY RESPONSIBILITIES

•      Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling.

•      Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives.

•      Analyze scan output, correlate findings across environments, and document results in standardized assessment reports.

•      Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence.

•      Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements.

•      Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services.

•      Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication.

•      Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures.

REQUIRED QUALIFICATIONS

•      Active TS clearance with SCI eligibility; ability to meet program-directed access requirements.

•      Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility.

•      Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire.

•      Hands-on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking.

•      Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes.

•      Ability to work non-routine assessment tasks with only periodic high-level supervision.

PREFERRED QUALIFICATIONS

•      Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.

•      Experience supporting DoD, IC, or space ground system programs.

•      Certifications such as CySA+, CEH, GCIH, or GSEC.

•      Exposure to containerized or cloud environments (Kubernetes/EKS, AWS).

•      Scripting familiarity (Python, PowerShell, Bash) for reporting and data reduction.

Company Description

NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.