1

Vulnerability Engineer Jobs (NOW HIRING)

BDR is seeking a Vulnerability Engineer to join our growing team! This position will be hybrid with three (3) days a week on-site in Washington, D.C. This position requires US Citizenship with an ...

ClifyX is a company focused on cybersecurity solutions, and they are seeking a Vulnerability Engineer to enhance their vulnerability management processes. The role involves analyzing vulnerability ...

BDR is seeking a Vulnerability Engineer to join our growing team! This position will be hybrid with three (3) days a week on-site in Washington, D.C. This position requires US Citizenship with an ...

Senior Vulnerability Engineer

Reston, VA ยท On-site

$108K - $149K/yr

As our Senior Vulnerability Engineer, you will provide Subject Matter Expertise support to maintain Vulnerability Management Program requirements including, but not limited to, maintaining the patch ...

Senior Vulnerability Engineer

Reston, VA ยท On-site

$108K - $149K/yr

As our Senior Vulnerability Engineer, you will provide Subject Matter Expertise support to maintain Vulnerability Management Program requirements including, but not limited to, maintaining the patch ...

Senior Vulnerability Engineer

Reston, VA ยท On-site

$108K - $149K/yr

As our Senior Vulnerability Engineer, you will provide Subject Matter Expertise support to maintain Vulnerability Management Program requirements including, but not limited to, maintaining the patch ...

Senior Vulnerability Engineer

Reston, VA ยท On-site

$150 - $190/hr

As our Senior Vulnerability Engineer, you will provide Subject Matter Expertise supportto maintain Vulnerability Management Program requirements including, but not limited to, maintaining the ...

Senior Vulnerability Engineer

Reston, VA ยท On-site

$120 - $180/hr

As our Senior Vulnerability Engineer, you will provide Subject Matter Expertise support to maintain Vulnerability Management Program requirements including, but not limited to, maintaining the patch ...

$120 - $180/hr

As our Senior Vulnerability Engineer, you will provide Subject Matter Expertise support to maintain Vulnerability Management Program requirements including, but not limited to, maintaining the patch ...

iOS Vulnerability Engineer (Software)

Tysons, VA ยท On-site

$140K/yr

iOS Vulnerability Engineer (Software) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are looking for a highly skilled ...

iOS Vulnerability Engineer (Software)

Reston, VA ยท On-site

$145K/yr

iOS Vulnerability Engineer (Software) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are looking for a highly skilled ...

iOS Vulnerability Engineer (Software)

Chantilly, VA ยท On-site

$144K/yr

iOS Vulnerability Engineer (Software) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are looking for a highly ...

next page

Showing results 1-20

Vulnerability Engineer information

See salary details

$39K

$101.8K

$137.5K

How much do vulnerability engineer jobs pay per year?

As of Aug 25, 2026, the average yearly pay for vulnerability engineer in the United States is $101,752.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,000.00 and $116,500.00 per year, depending on experience, location, and employer.

What is a vulnerability engineer?

A Vulnerability Engineer is a cybersecurity professional responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They use specialized tools to scan for weaknesses, analyze security data, and work with other IT teams to remediate risks. Their goal is to protect sensitive data and ensure compliance with industry regulations by proactively addressing potential security threats.

What are the key skills and qualifications needed to thrive as a vulnerability engineer, and why are they important?

To thrive as a Vulnerability Engineer, you need a strong understanding of cybersecurity principles, vulnerability assessment methodologies, and a background in IT or computer science. Familiarity with tools such as Nessus, Qualys, Burp Suite, and relevant certifications like OSCP or CompTIA Security+ are commonly expected. Analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying risks and collaborating with teams. These skills and qualifications are vital to proactively detect, assess, and mitigate security vulnerabilities, protecting organizational assets from cyber threats.

What are some common challenges faced by vulnerability engineers when coordinating with development teams to remediate identified vulnerabilities?

One of the primary challenges Vulnerability Engineers encounter is ensuring that development teams prioritize and address vulnerabilities promptly, especially when they have competing project deadlines. Effective communication is essential to explain the risk and potential business impact of each vulnerability in terms that are understandable to non-security professionals. Additionally, aligning remediation efforts with ongoing development cycles and managing false positives can require careful negotiation and collaboration. Building strong relationships and fostering a security-first culture within the organization can significantly ease these challenges.

What is the difference between Vulnerability Engineer vs Security Analyst?

AspectVulnerability EngineerSecurity Analyst
CertificationsOSCP, CISSP, CEHCISSP, Security+
Work EnvironmentFocus on identifying and fixing vulnerabilities in systems and applicationsMonitor security alerts, analyze threats, and respond to incidents
Employer & Industry UsageTech companies, cybersecurity firms, large enterprisesCorporate security teams, government agencies, financial institutions

While both roles focus on cybersecurity, Vulnerability Engineers primarily identify and remediate system vulnerabilities, whereas Security Analysts monitor and respond to security threats. Vulnerability Engineers are more technical and hands-on with system testing, while Security Analysts focus on threat detection and incident response. Both roles are essential for a comprehensive security strategy.

More about Vulnerability Engineer jobs

What states have the most Vulnerability Engineer jobs?

States with the most job openings for Vulnerability Engineer jobs include:

Infographic showing various Vulnerability Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $101,752 per year, or $48.9 per hour.

Vulnerability Engineer

BDR Solutions LLC

Washington, DC โ€ข On-site

Full-time

Posted 21 days ago


Job description

BDR Solutions, LLC, (BDR) supports the U.S. Federal Government in successfully achieving its mission and goals. Our service and solution delivery starts with understanding each client’s end-state, and then seamlessly integrating within each Agency’s organization to improve and enhance business and technical operations and deployments.

BDR is seeking a Vulnerability Engineer to join our growing team! This position will be hybrid with three (3) days a week on-site in Washington, D.C. This position requires US Citizenship with an active Top Secret clearance.

(Military Veterans are highly encouraged to apply)

Role Overview:

The Vulnerability Engineer will provide critical support in identifying, analyzing, and remediating vulnerabilities across an infrastructure consisting of over windows servers. This will include analyzing reports from multiple streams and sources as well as remediating and assigning to other members of the team when needed. This position requires a mixture of engineering, operations, hands on technical and support skills. Qualified candidates should have excellent troubleshooting and analytical skills. The individual will work closely with technical leads, infrastructure and operations teams and other cross-department teams to evaluate business needs and provide end-to-end technical solutions and manage, operate, monitor, audit, secure server assets.

Responsibilities:

  • Performs security hardening, patching and server certificate updates.
  • Run system scans and analyze reports on system vulnerabilities on windows servers.
  • Maintain and update environmental documentation, standard Operating Procedures, and engineering documentation.
  • Provide support to system administrators to resolve issues when required provide support in response to outages including conducting root cause analysis.
  • Recognize and escalate risks, issues, and concerns when necessary.
  • Analyze vulnerability reports identify areas of responsibility for remediation.
  • Resolve known exploited vulnerabilities, prioritizing critical and highs.
  • Facilitate coordination of vulnerability remediations across the team.
  • Develop and provide recommendations and remediations for vulnerabilities.
  • Harden Windows OS with secure versions of Transport Layer Security (TLS), and cipher suites according to NIST policy.
  • Assist Security Operations personnel in developing Plan of Action & Milestones (POAM’s) for vulnerabilities requiring long-lead time resolve.
  • Provide on-call support and manage ticket queue.
  • Demonstrate strong knowledge of vulnerability management tools such as Tenable Nessus and BigFix.

Required Minimum Qualifications:

  • 7+ years of experience administrating and managing servers and systems, cloud infrastructure, file and print environments, specializing in Windows operating systems.
  • Must possess one of the following certifications: M365, VCP, CCNP or Linux+.
  • Bachelor’s degree in networking, cybersecurity or similar field.
  • Must possess an active DOD Secret or higher clearance.
  • Must have advanced knowledge of Microsoft Active Directory and SQL Server.
  • Expert knowledge and troubleshooting skills to resolve failed update installation in Windows OS.
  • Expert knowledge of AD Group policy and applying security posture via GPO's.
  • Strong knowledge of System Center Configuration Manager (SCCM).
  • Experience with performing root cause analysis, risk identification, and risk mitigation
  • Understanding of FIPS 140-3 or cryptographic modules and how they are used.
  • Must be a self-started with strong problem solving and communication skills.
  • Strong knowledge of NIST-800 framework and security guidelines for windows servers and clients including DISA STIG
  • Strong knowledge of CIS Benchmark guidelines for Microsoft Windows servers
  • Experience with scripting tools such as, PowerShell, Azure CLI, AWS CLI, Python, and VBScript.
  • Experience with Nessus Tenable scanning tools and reporting.
  • Expert level experience with MS Office tools such as Excel, PowerPoint, Vizio, Word.
  • Experience with installing hardware drivers, firmware, bios, and other hardware upgrades for Dell servers.
  • Demonstrate knowledge of common ports and protocols used by Windows servers and clients.
  • Security certification(s) highly preferred such as Security+, CISSP, CASP+, CISA, CISM etc.
  • Experience Linux/Ansible, and/or Unix experience are a plus.


The salary compensation range for this position is 100,000-130,000. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.

In addition, U.S Citizenship is required. Select applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information and be able to obtain a government-granted security clearance. Individuals may also be subject to a background investigation including, but not limited to criminal history, employment and education verification, drug testing, and creditworthiness.

BDR Solutions is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.


Requirements:
None