1

Vulnerability Management Analyst Jobs (NOW HIRING)

Vulnerability Management Analyst

Chantilly, VA ยท On-site

$70K - $85K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

Requirements โ€ข Minimum 6 years of experience in systems analysis, vulnerability management, information security, or a related IT infrastructure/security role. โ€ข Hands-on experience using Qualys ...

GRC, Vulnerability Management Analyst

Atlanta, GA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and ...

Senior Vulnerability Management Analyst

Scottsdale, AZ ยท Hybrid

$105K - $120K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

Current Employees and Contractors Apply HereOsaic Careers IT Vulnerability Opportunity in Financial Services Senior Vulnerability Management Analyst Location(s): Atlanta: 2300 Windy Ridge Pkwy SE ...

Senior Vulnerability Management Analyst

Scottsdale, AZ ยท Hybrid

$105K - $120K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

IT Vulnerability Opportunity in Financial Services Senior Vulnerability Management Analyst Location(s): Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339 La Vista:12325 Port Grace Blvd, ...

Showing results 21-40

Vulnerability Management Analyst information

See salary details

$70K

$124.2K

$174.5K

How much do vulnerability management analyst jobs pay per year?

As of Aug 17, 2026, the average yearly pay for vulnerability management analyst in the United States is $124,243.00, according to ZipRecruiter salary data. Most workers in this role earn between $83,000.00 and $164,000.00 per year, depending on experience, location, and employer.

What is a vulnerability management analyst?

A Vulnerability Management Analyst is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT infrastructure. They use scanning tools, analyze threat data, and collaborate with teams to prioritize and remediate risks. Their role is crucial in maintaining cybersecurity by ensuring systems are patched and configured securely. Additionally, they may develop reports and provide recommendations to improve security posture. This position requires knowledge of security frameworks, risk assessment, and vulnerability management tools.

What are the typical daily responsibilities of a vulnerability management analyst?

On a typical day, a Vulnerability Management Analyst reviews system scans, analyzes reports for potential vulnerabilities, and works with IT or security teams to prioritize remediation efforts. They may also track the status of vulnerabilities, ensure timely patch application, and help develop or update security policies. Collaboration with various departments is common to coordinate testing, remediation, and communicate risk summary findings. This role requires keeping up with emerging threats and sometimes participating in security audits or compliance reviews, making it both dynamic and integral to the organization's overall cybersecurity posture.

What are the key skills and qualifications needed to thrive as a vulnerability management analyst?

A Vulnerability Management Analyst requires a strong background in cybersecurity principles, risk assessment, and IT networking, often supported by a relevant degree or certifications like CompTIA Security+, CISSP, or CEH. Experience with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7) and familiarity with ticketing systems or SIEM platforms is essential. Strong analytical skills, attention to detail, effective communication, and the ability to work collaboratively help individuals succeed in this role. These capabilities are vital to proactively identify, assess, and mitigate security vulnerabilities, ensuring the organization's digital assets remain secure and compliant.

More about Vulnerability Management Analyst jobs

What cities are hiring for Vulnerability Management Analyst jobs?

Cities with the most Vulnerability Management Analyst job openings:

What are the most commonly searched types of Vulnerability Management Analyst jobs?

The most popular types of Vulnerability Management Analyst jobs are:

Who are the top companies hiring for Vulnerability Management Analyst jobs?

The top employers for Vulnerability Management Analyst jobs are:

What states have the most Vulnerability Management Analyst jobs?

States with the most job openings for Vulnerability Management Analyst jobs include:

What job categories do people searching Vulnerability Management Analyst jobs look for?

The top searched job categories for Vulnerability Management Analyst jobs are:

Infographic showing various Vulnerability Management Analyst job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 74% In-person, 9% Hybrid, and 17% Remote job distribution, with an average salary of $124,243 per year, or $59.7 per hour.

Vulnerability Management Analyst

DANE LLC

Chantilly, VA โ€ข On-site

$70K - $85K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 4 days ago


Job description

Benefits:
  • Life/STD/LTD
  • FSA/DCA
  • 401(k)
  • Employee discounts
  • Paid time off
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Tuition assistance
  • Vision insurance

Description
Looking for a place that invests in you from day one? At DANE, we offer aggressive PTO, strong benefits, and ongoing learning opportunities, backed by a culture that values and supports our team.
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology environment. This is a junior-level role (1–3 years of experience) focused on execution and coordination, working hands-on with Tenable/Nessus, iPost, Power BI, Excel, and ticketing systems to ensure that vulnerability data is accurate, actionable, and reportable.
Details:
Location: Hybrid - Onsite, Arlington, VA,1 day/week and as needed
Job Type: Full Time
Education: Minimum of a Bachelor’s degree in computer science or Equivalent
Experience: Minimum 1 year of relevant experience
Clearance: Must hold an Active DoD Secret Clearance or higher
Responsibilities
  • Run authorized Tenable/Nessus scans using credentialed scan profiles and review exports to identify CVEs, plugin findings, KEV status, EOL/EOS software risks, and affected assets.
  • Validate findings as true or false positives, track vulnerability age using first-seen/last-seen dates, and escalate unresolved findings to senior security staff or system owners.
  • Support the full vulnerability lifecycle from intake and triage through ownership assignment, remediation tracking, retest/rescan validation, and closure evidence collection.
  • Monitor KEV and Critical/High findings against federal remediation timelines (e.g., BOD 22-01) and flag aging, stale, or blocked findings for escalation.
  • Build and maintain Power BI dashboards and Excel reports covering vulnerability posture, patch compliance, KEV status, finding aging, and ownership tracking using Power Query, slicers, and basic DAX measures.
  • Produce recurring deliverables, including Critical/High aging reports, Tenable/iPost reconciliation summaries, EOL/EOS tracking, and executive snapshots; document KPI definitions and data sources.
  • Reconcile vulnerability data across Tenable/Nessus, iPost, ServiceNow/CA ServiceDesk, Jira, SharePoint, POA&M trackers, and Excel exports to identify mismatches and coverage gaps.
  • Coordinate with security, development, infrastructure, database, and cloud teams and ISSO stakeholders to drive remediation through closure.
Requirements

  • 1–3 years of experience in cybersecurity operations, vulnerability management, SOC, cyber GRC, IT operations, or application security support; working knowledge of CVE, CVSS, KEV, false positives, POA&M tracking, risk acceptance, and vulnerability aging.
  • Hands-on Tenable/Nessus experience: executing credentialed scans, analyzing plugin output and CVE findings, validating true/false positives, and building dashboards, saved filters, and exports for KEV, Critical/High, EOL/EOS, and aging tracking.
  • Intermediate Power BI (Power Query, data modeling, DAX, slicers) and strong Excel skills (pivot tables, VLOOKUP/XLOOKUP, conditional formatting, deduplication) for vulnerability reporting and KPI tracking.
  • Experience with iPost, ServiceNow, CA ServiceDesk, Jira, or SharePoint for remediation tracking; ability to reconcile data across multiple tools, identify mismatches, and maintain accurate ownership and evidence records.
  • Familiarity with EOL/EOS software tracking, patch compliance, remediation exceptions, risk acceptance documentation, and closure evidence collection.
  • Strong attention to detail, comfort working with large and messy datasets, and clear communication skills for translating technical findings into plain-language updates for leadership and non-technical stakeholders.
Preferred Qualifications

  • Experience supporting federal cybersecurity programs or regulated environments; familiarity with NIST SP 800-53, RMF, A&A, ATO, POA&M lifecycle management, CISA BOD 22-01, and FedRAMP vulnerability requirements.
  • Exposure to DevSecOps and application security tooling: SAST, DAST, SCA, container image scanning, secrets scanning, or Software Bill of Materials (SBOM) analysis.
  • Basic understanding of enterprise patching for Windows Server, Windows workstations, .NET Framework, Java JRE, SQL Server, and endpoint agents; familiarity with Splunk or other SIEM platforms.
  • Experience developing SOPs, RACI matrices, or workflow documentation in a security or IT operations context.
  • Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent entry-to-mid-level cybersecurity credentials.

DANE LLC is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Flexible work from home options available.