1

Vulnerability Engineer Jobs (NOW HIRING)

ORA_HYBRID Description The Application Vulnerability Assessment Program (AVAP) Engineer/System Administrator is responsible for operating and securing the program's application security platforms ...

Showing results 41-60

Vulnerability Engineer information

See salary details

$39K

$101.8K

$137.5K

How much do vulnerability engineer jobs pay per year?

As of Sep 14, 2026, the average yearly pay for vulnerability engineer in the United States is $101,752.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,000.00 and $116,500.00 per year, depending on experience, location, and employer.

What is a vulnerability engineer?

A Vulnerability Engineer is a cybersecurity professional responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They use specialized tools to scan for weaknesses, analyze security data, and work with other IT teams to remediate risks. Their goal is to protect sensitive data and ensure compliance with industry regulations by proactively addressing potential security threats.

What are the key skills and qualifications needed to thrive as a vulnerability engineer, and why are they important?

To thrive as a Vulnerability Engineer, you need a strong understanding of cybersecurity principles, vulnerability assessment methodologies, and a background in IT or computer science. Familiarity with tools such as Nessus, Qualys, Burp Suite, and relevant certifications like OSCP or CompTIA Security+ are commonly expected. Analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying risks and collaborating with teams. These skills and qualifications are vital to proactively detect, assess, and mitigate security vulnerabilities, protecting organizational assets from cyber threats.

What are some common challenges faced by vulnerability engineers when coordinating with development teams to remediate identified vulnerabilities?

One of the primary challenges Vulnerability Engineers encounter is ensuring that development teams prioritize and address vulnerabilities promptly, especially when they have competing project deadlines. Effective communication is essential to explain the risk and potential business impact of each vulnerability in terms that are understandable to non-security professionals. Additionally, aligning remediation efforts with ongoing development cycles and managing false positives can require careful negotiation and collaboration. Building strong relationships and fostering a security-first culture within the organization can significantly ease these challenges.

What is the difference between Vulnerability Engineer vs Security Analyst?

AspectVulnerability EngineerSecurity Analyst
CertificationsOSCP, CISSP, CEHCISSP, Security+
Work EnvironmentFocus on identifying and fixing vulnerabilities in systems and applicationsMonitor security alerts, analyze threats, and respond to incidents
Employer & Industry UsageTech companies, cybersecurity firms, large enterprisesCorporate security teams, government agencies, financial institutions

While both roles focus on cybersecurity, Vulnerability Engineers primarily identify and remediate system vulnerabilities, whereas Security Analysts monitor and respond to security threats. Vulnerability Engineers are more technical and hands-on with system testing, while Security Analysts focus on threat detection and incident response. Both roles are essential for a comprehensive security strategy.

More about Vulnerability Engineer jobs

What states have the most Vulnerability Engineer jobs?

States with the most job openings for Vulnerability Engineer jobs include:

What are popular job titles related to Vulnerability Engineer jobs?

For Vulnerability Engineer jobs, the most frequently searched job titles are:

Infographic showing various Vulnerability Engineer job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 89% Full Time, 7% Part Time, and 3% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $101,752 per year, or $48.9 per hour.

iOS Vulnerability Engineer (Software)

Reston, VA • On-site

Cymertek Corporation
IT Services • 11 - 50 employees

$145K/yr

Full-time

Re-posted 7 days ago


Job description

Job Summary:
Cymertek Corporation is seeking a highly skilled and innovative iOS Vulnerability Engineer (Software) to join their team. The role involves identifying, analyzing, and mitigating security vulnerabilities in iOS systems and applications, as well as collaborating with cross-functional teams to ensure robust security measures.
Responsibilities:
• Identify and analyze iOS vulnerabilities
• Develop mitigation strategies for discovered issues
• Conduct security assessments of iOS applications
• Perform reverse engineering of iOS binaries
• Collaborate with development teams to improve software security
• Document findings and recommend improvements
Qualifications:
Required:
• TS/SCI Full Poly (Please note this position requires full U.S. Citizenship)
• Bachelor's Degree
• Strong knowledge of iOS internals
• Proficiency in reverse engineering tools
• Expertise in static and dynamic code analysis
• Familiarity with secure coding practices
• Proficiency in iOS development tools (e.g., Xcode)
• Ability to exploit and remediate vulnerabilities
Preferred:
• Knowledge of ARM assembly
• Experience with fuzz testing methodologies
• Familiarity with jailbreak development
• Understanding of malware analysis techniques
• Expertise in cryptographic protocols
• Proficiency in scripting for automation (e.g., Python)
Company:
With headquarters in Maryland, Cymertek [/'sī-mer-tek/] Corporation provides superior consulting services for the implementation of high quality information systems. Founded in 2010, the company is headquartered in Laurel, USA, with a team of 11-50 employees. The company is currently Early Stage.