1

Vulnerability Management Analyst Jobs (NOW HIRING)

Sr Vulnerability Management Analyst

Dallas, TX · On-site

$95K - $124K/yr

We're excited for a Senior Vulnerability Management Analyst to join our high-energy team - to help shape the future of Vanguard's attack surface management and VulnOps. This role sits at the ...

next page

Showing results 1-20

Vulnerability Management Analyst information

See salary details

$70K

$124.2K

$174.5K

How much do vulnerability management analyst jobs pay per year?

As of Jun 6, 2026, the average yearly pay for vulnerability management analyst in the United States is $124,243.00, according to ZipRecruiter salary data. Most workers in this role earn between $83,000.00 and $164,000.00 per year, depending on experience, location, and employer.

What is a Vulnerability Management Analyst job?

A Vulnerability Management Analyst is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT infrastructure. They use scanning tools, analyze threat data, and collaborate with teams to prioritize and remediate risks. Their role is crucial in maintaining cybersecurity by ensuring systems are patched and configured securely. Additionally, they may develop reports and provide recommendations to improve security posture. This position requires knowledge of security frameworks, risk assessment, and vulnerability management tools.

What are some typical daily responsibilities for a Vulnerability Management Analyst?

On a typical day, a Vulnerability Management Analyst reviews system scans, analyzes reports for potential vulnerabilities, and works with IT or security teams to prioritize remediation efforts. They may also track the status of vulnerabilities, ensure timely patch application, and help develop or update security policies. Collaboration with various departments is common to coordinate testing, remediation, and communicate risk summary findings. This role requires keeping up with emerging threats and sometimes participating in security audits or compliance reviews, making it both dynamic and integral to the organization's overall cybersecurity posture.

What are the key skills and qualifications needed to thrive in the Vulnerability Management Analyst position, and why are they important?

A Vulnerability Management Analyst requires a strong background in cybersecurity principles, risk assessment, and IT networking, often supported by a relevant degree or certifications like CompTIA Security+, CISSP, or CEH. Experience with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7) and familiarity with ticketing systems or SIEM platforms is essential. Strong analytical skills, attention to detail, effective communication, and the ability to work collaboratively help individuals succeed in this role. These capabilities are vital to proactively identify, assess, and mitigate security vulnerabilities, ensuring the organization's digital assets remain secure and compliant.

More about Vulnerability Management Analyst jobs
What cities are hiring for Vulnerability Management Analyst jobs? Cities with the most Vulnerability Management Analyst job openings:
What are the most commonly searched types of Vulnerability Management Analyst jobs? The most popular types of Vulnerability Management Analyst jobs are:
What states have the most Vulnerability Management Analyst jobs? States with the most job openings for Vulnerability Management Analyst jobs include:
Infographic showing various Vulnerability Management Analyst job openings in the United States as of May 2026, with employment types broken down into 4% Locum Tenens, 16% As Needed, 17% Full Time, 12% Temporary, 46% Contract, and 5% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $124,243 per year, or $59.7 per hour.
Vulnerability Management Analyst- Secret Clearance Required

Vulnerability Management Analyst- Secret Clearance Required

Sherpa 6

Springfield, VA

$90K - $125K/yr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 27 days ago


Job description

Description

Security Clearance: Active Secret clearance required (Interim ok)

Travel Requirement: Up to 10%

Citizenship: US Citizenship required


Sherpa 6 is seeking a highly motivated and skilled Vulnerability Management Analyst to join our team. We build mission critical systems for the Department of Defense (DoD) and other commercial customers. You'll be responsible for identifying, assessing, prioritizing, and tracking remediation of security vulnerabilities across our software development process. You will partner with infrastructure, application, and security teams to ensure risks are properly understood, addressed, and reported.


Responsibilities:

  • Perform regular vulnerability scans across cloud, on-prem, application, and endpoint environments.
  • Work alongside Software and DevSecOps teams to develop strategies for incorporating vulnerability detection and management in CI/CD pipelines as part of our software development process
  • Analyze scan results, validate findings, and assign severity based on industry standards (e.g., CVSS), business context, and exploitability.
  • Work collaboratively with engineering and operations teams to drive timely remediation of vulnerabilities.
  • Monitor external threat intelligence and evaluate emerging vulnerabilities (e.g., zero-days, trending exploits).
  • Maintain the vulnerability management platform and improve scanning coverage and accuracy.
  • Support patch management processes and ensure alignment with remediation SLAs.
  • Assist in developing and refining policies, procedures, and best practices for vulnerability management.
  • Participate in incident response efforts when vulnerabilities contribute to active threats.

Requirements

  • 7+ years of experience in cybersecurity, vulnerability management, or related fields.
  • 3+ years of experience working alongside software development and DevSecOps teams as part of the software development process
  • Hands-on experience with tools such as Tenable, Qualys, Rapid7, OpenVAS, or similar.
  • Strong understanding of CVE, CVSS, NIST, CIS benchmarks, and vulnerability classification frameworks.
  • Familiarity with cloud platforms (AWS, Azure, GCP)
  • Ability to interpret vulnerability findings, identify actual risk, and communicate clearly with technical and non-technical stakeholders.
  • Knowledge of patch management practices and change management workflows.
  • Understanding of network architecture, security controls, and common attack vectors.
  • Excellent analytical and problem-solving skills, with a keen attention to detail.
  • Strong communication and interpersonal skills, with the ability to effectively collaborate with cross-functional teams
  • Must be a US citizen

Qualities of Exceptional Candidates:

  • Relevant certifications (Security+, CySA+, CEH, GSEC, or similar).
  • Experience with automation or scripting (Python, PowerShell, Bash).
  • Background in secure configuration management, container security, or DevSecOps tooling.
  • Knowledge of SIEM or threat detection platforms.

About Sherpa 6:

At Sherpa 6 we love to solve problems and provide the best solutions for our customers. Our approach to a problem is to find a user-focused and design-driven solution that is simple yet functional and effective. We are a group of enthusiastic forward-thinkers who are excited to build amazing solutions with bleeding-edge technology. We hire people who are forward thinkers, passionate about what they do, love to collaborate and want to constantly learn. We enjoy what we do and we're not afraid to put the extra effort in to accomplish the mission; call us Sherpas. As a Service-Disabled Veteran Owned Small Business, we know what it means to serve. We have made it our mission to be the leaders in solutions that protect and give our Warfighters the edge they need when put into harm's way.

Background Screening/Check/Investigation:

Successful completion of a background screening/check/investigation will/may be required as a condition of hire.

ADA:

Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act 1990.

EEO/AA:

Sherpa 6 does not discriminate based on race, color, national origin, sex, religion age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status in employment or the provision of services and is an equal access/opportunity/affirmative action employer.

Benefits:

We offer a competitive benefits package, covering the cost of medical for you and your family; we also offer dental, vision, health and wellness benefits and a generous retirement savings plan. We believe that our employees can manage their workload and their personal life, therefore we extend a generous PTO policy. This allows our employees to balance their lives as they see fit.

Salary Range

The proposed salary range is reflective across all Sherpa 6 locations, years of experience, and skill levels. Salary negotiations will be based on a host of factors including but not limited to your geographic location, prior experience, relevant skills, education, and certifications.