1

Vulnerability Engineer Jobs (NOW HIRING)

Vulnerability Engineer Location: Phoenix AZ/ Westerville OH * Experienced resource capable of independently leading cadence calls with engineers and analysts. * Able to communicate effectively with ...

As a Vulnerability Automation Engineer, you will design, build, and operate lights-off pipelines that continuously discover assets, assess posture, scan for vulnerabilities, harden configurations ...

next page

Showing results 1-20

Vulnerability Engineer information

See salary details

$39K

$101.8K

$137.5K

How much do vulnerability engineer jobs pay per year?

As of May 29, 2026, the average yearly pay for vulnerability engineer in the United States is $101,752.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,000.00 and $116,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Engineer, and why are they important?

To thrive as a Vulnerability Engineer, you need a strong understanding of cybersecurity principles, vulnerability assessment methodologies, and a background in IT or computer science. Familiarity with tools such as Nessus, Qualys, Burp Suite, and relevant certifications like OSCP or CompTIA Security+ are commonly expected. Analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying risks and collaborating with teams. These skills and qualifications are vital to proactively detect, assess, and mitigate security vulnerabilities, protecting organizational assets from cyber threats.

What are some common challenges faced by Vulnerability Engineers when coordinating with development teams to remediate identified vulnerabilities?

One of the primary challenges Vulnerability Engineers encounter is ensuring that development teams prioritize and address vulnerabilities promptly, especially when they have competing project deadlines. Effective communication is essential to explain the risk and potential business impact of each vulnerability in terms that are understandable to non-security professionals. Additionally, aligning remediation efforts with ongoing development cycles and managing false positives can require careful negotiation and collaboration. Building strong relationships and fostering a security-first culture within the organization can significantly ease these challenges.

What is a Vulnerability Engineer?

A Vulnerability Engineer is a cybersecurity professional responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They use specialized tools to scan for weaknesses, analyze security data, and work with other IT teams to remediate risks. Their goal is to protect sensitive data and ensure compliance with industry regulations by proactively addressing potential security threats.

What is the difference between Vulnerability Engineer vs Security Analyst?

AspectVulnerability EngineerSecurity Analyst
CertificationsOSCP, CISSP, CEHCISSP, Security+
Work EnvironmentFocus on identifying and fixing vulnerabilities in systems and applicationsMonitor security alerts, analyze threats, and respond to incidents
Employer & Industry UsageTech companies, cybersecurity firms, large enterprisesCorporate security teams, government agencies, financial institutions

While both roles focus on cybersecurity, Vulnerability Engineers primarily identify and remediate system vulnerabilities, whereas Security Analysts monitor and respond to security threats. Vulnerability Engineers are more technical and hands-on with system testing, while Security Analysts focus on threat detection and incident response. Both roles are essential for a comprehensive security strategy.

More about Vulnerability Engineer jobs
What states have the most Vulnerability Engineer jobs? States with the most job openings for Vulnerability Engineer jobs include:
Infographic showing various Vulnerability Engineer job openings in the United States as of May 2026, with employment types broken down into 95% Full Time, and 5% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $101,752 per year, or $48.9 per hour.

Expert vunerability engineer

Sidram Technologies

New York, NY • Remote

Contractor

Posted 18 days ago


Job description

("Vulnerability Engineer" OR "Vulnerability Management" OR "Vulnerability Scanning" OR "Baseline Hardening" OR "CSPM" OR "Cloud Security Posture" OR "Security Engineer" OR "Cyber Risk Engineer")
AND
("Rapid7" OR "InsightVM" OR "Nexpose" OR "Qualys" OR "Aqua" OR "CrowdStrike" OR "Microsoft Defender for Cloud" OR "Policy Compliance" OR "Benchmark Scanning")
AND
("Automation" OR "CyberArk" OR "Azure Key Vault" OR "Jira" OR "Ivanti" OR "Compliance" OR "Hardening Baseline")
AND
("Information Security" OR "Security Operations" OR "Security Services")
AND
("Oakland" OR "Oakland CA" OR "Bay Area" OR "San Francisco" OR "San Jose" OR "California")
AND
("Delta Dental")