1

Vulnerability Management Analyst Jobs (NOW HIRING)

Vulnerability Management Analyst

Chantilly, VA · On-site

$70K - $85K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

Requirements • Minimum 6 years of experience in systems analysis, vulnerability management, information security, or a related IT infrastructure/security role. • Hands-on experience using Qualys ...

GRC, Vulnerability Management Analyst

Atlanta, GA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and ...

Senior Vulnerability Management Analyst

Scottsdale, AZ · Hybrid

$105K - $120K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

Current Employees and Contractors Apply HereOsaic Careers IT Vulnerability Opportunity in Financial Services Senior Vulnerability Management Analyst Location(s): Atlanta: 2300 Windy Ridge Pkwy SE ...

Showing results 21-40

Vulnerability Management Analyst information

See salary details

$70K

$124.2K

$174.5K

How much do vulnerability management analyst jobs pay per year?

As of Aug 16, 2026, the average yearly pay for vulnerability management analyst in the United States is $124,243.00, according to ZipRecruiter salary data. Most workers in this role earn between $83,000.00 and $164,000.00 per year, depending on experience, location, and employer.

What is a vulnerability management analyst?

A Vulnerability Management Analyst is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT infrastructure. They use scanning tools, analyze threat data, and collaborate with teams to prioritize and remediate risks. Their role is crucial in maintaining cybersecurity by ensuring systems are patched and configured securely. Additionally, they may develop reports and provide recommendations to improve security posture. This position requires knowledge of security frameworks, risk assessment, and vulnerability management tools.

What are the typical daily responsibilities of a vulnerability management analyst?

On a typical day, a Vulnerability Management Analyst reviews system scans, analyzes reports for potential vulnerabilities, and works with IT or security teams to prioritize remediation efforts. They may also track the status of vulnerabilities, ensure timely patch application, and help develop or update security policies. Collaboration with various departments is common to coordinate testing, remediation, and communicate risk summary findings. This role requires keeping up with emerging threats and sometimes participating in security audits or compliance reviews, making it both dynamic and integral to the organization's overall cybersecurity posture.

What are the key skills and qualifications needed to thrive as a vulnerability management analyst?

A Vulnerability Management Analyst requires a strong background in cybersecurity principles, risk assessment, and IT networking, often supported by a relevant degree or certifications like CompTIA Security+, CISSP, or CEH. Experience with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7) and familiarity with ticketing systems or SIEM platforms is essential. Strong analytical skills, attention to detail, effective communication, and the ability to work collaboratively help individuals succeed in this role. These capabilities are vital to proactively identify, assess, and mitigate security vulnerabilities, ensuring the organization's digital assets remain secure and compliant.

More about Vulnerability Management Analyst jobs

What cities are hiring for Vulnerability Management Analyst jobs?

Cities with the most Vulnerability Management Analyst job openings:

What are the most commonly searched types of Vulnerability Management Analyst jobs?

The most popular types of Vulnerability Management Analyst jobs are:

Who are the top companies hiring for Vulnerability Management Analyst jobs?

The top employers for Vulnerability Management Analyst jobs are:

What states have the most Vulnerability Management Analyst jobs?

States with the most job openings for Vulnerability Management Analyst jobs include:

What job categories do people searching Vulnerability Management Analyst jobs look for?

The top searched job categories for Vulnerability Management Analyst jobs are:

Infographic showing various Vulnerability Management Analyst job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 74% In-person, 9% Hybrid, and 17% Remote job distribution, with an average salary of $124,243 per year, or $59.7 per hour.

Vulnerability Management Analyst

Leidos

Camp Springs, MD • On-site

Full-time

Re-posted 4 days ago


Leidos rating

8.3

Company rating: 8.3 out of 10

Based on 152 frontline employees who took The Breakroom Quiz

79th of 492 rated business services


Job description

Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program.

The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), Office of the Secretary of Defense (OSD), Joint Chiefs of Staff, and other Air Force activities within the AFNCR, missions to include the Pentagon, Joint Base Andrews (JBA), Joint Base Anacostia-Bolling (JBAB), and other locations, leased spaces, and alternate sites. The major support areas required are IT Operations and Maintenance; Plans, Projects, and Engineering (PP&E); and National Military Command Center (NMCC). The senior leaders and national defense missions that are supported require that the AFNCR operations never fail, resulting in a fast-paced, challenging, but also rewarding environment.

If this sounds like the kind of environment where you can thrive, keep reading!

Leidos Defense Group provides a diverse portfolio of systems, solutions, and services covering land, sea, air, space, and cyberspace for customers worldwide. Solutions for Defense include enterprise and mission IT, large-scale intelligence systems, command and control, geospatial and data analytics, cybersecurity, logistics, training, and intelligence analysis and operations support. Our team is solving the world's toughest security challenges for customers with "can't fail" missions. To explore and learn more, click here!

Are you ready to make an impact? Begin your journey of a flourishing and meaningful career, share your resume with us today!

POSITION SUMMARY:

Leidos is seeking a Vulnerability Management Analyst to join our Cybersecurity Operations team supporting the AFNCR IT Services (AFNCRIT) program. This T1-level position is ideal for an entry-level cybersecurity professional interested in learning vulnerability management processes. The role will assist with running vulnerability scans using ACAS, reviewing STIG findings, and supporting remediation coordination across Air Force enterprise systems under the guidance of senior team members.

PRIMARY RESPONSIBILITIES:

Assist with scheduling and running vulnerability scans using Tenable SecurityCenter/Nessus (ACAS) in classified and unclassified environments under senior staff guidance.

Review scan results to help identify potential CAT I/II/III findings, false positives, and basic configuration issues.

Support tracking of remediation actions, Plans of Action and Milestones (POA&Ms), and exceptions in accordance with RMF guidance.

Follow established procedures to validate DISA STIG checklists and work with team members to ensure secure system configurations.

Help prepare basic vulnerability reports, compliance summaries, and metrics to support leadership briefings and inspection readiness (e.g., CCRI/CORA).

Assist in maintaining asset groupings, scan zones, and credentialed scanning configurations as directed by senior analysts.

Coordinate with Queue Managers, ISSOs, and Engineering teams to support the remediation of high-priority vulnerabilities.

Maintain data accuracy within ACAS, including proper tagging and grouping for consistent reporting.

BASIC QUALIFICATIONS:

Active DoD Secret clearance required.

CompTIA Security+ CE or higher DoD 8570 IAT Level II certification must meet 8140 ISSM role qualification

Bachelor's Degree and 4-8 years of cybersecurity or system administration experience, with at least 1 year of direct ACAS or Tenable experience. Additional education and years of experience may be considered in lieu of a degree.

Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.

Familiarity with NIST SP 800-53, RMF compliance, and Air Force cybersecurity policy (AFMAN 17-130).

Strong attention to detail, documentation skills, and the ability to interpret technical vulnerability data.

PREFERRED QUALIFICATIONS:

Experience supporting USAF, DISA, or other DoD mission systems.

Familiarity with eMASS, SCAP Compliance Checker (SCC), or HBSS.

Prior involvement in CCRI/CORA preparation or vulnerability remediation campaigns.

Ability to communicate risk-based recommendations to both technical and non-technical stakeholders.

Understanding of automation tools/scripts (e.g., PowerShell, Nessus APIs) to support scan or report optimization.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:July 13, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media