1

Vulnerability Management Engineer Jobs in Washington, DC

Vulnerability Management Lead

Mclean, VA ยท On-site

$103K - $136K/yr

The Vulnerability Management Lead serves as the primary technical authority for enterprise ... Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and ...

Vulnerability Management Lead

Mclean, VA ยท On-site

$103K - $136K/yr

The Vulnerability Management Lead serves as the primary technical authority for enterprise ... Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and ...

Vulnerability Management Lead

Mclean, VA ยท On-site

$103K - $136K/yr

We are seeking a Vulnerability Management Lead responsible for planning, executing, and ... Collaborate with Service Areas, system owners, cloud administrators, cybersecurity engineers, and ...

Prepare and deliver vulnerability reports, compliance dashboards, and metrics for leadership and ... Work closely with Queue Managers, ISSOs, and Engineering teams to prioritize and close critical ...

Vulnerability Management to support the Air Force National Capital Region IT Services program. The ... Plans, Projects, and Engineering and National Military Command Center (NMCC). TekSynap is a fast ...

Vulnerability Management Analyst Location- Joint Base Andrews, MD Clearance- Secret Certifications ... This role will work closely with cybersecurity engineers, ISSOs, system administrators, and ...

ISSO - Vulnerability Management

MD ยท On-site

$100K - $114K/yr

The ISSO - Vulnerability Management will play a critical role in maintaining the cybersecurity ... Collaborate with Queue Managers, ISSOs, system administrators, and engineering teams to prioritize ...

next page

Showing results 1-20

Vulnerability Management Engineer information

See Washington, DC salary details

$44K

$114.9K

$155.3K

How much do vulnerability management engineer jobs pay per year?

As of Aug 15, 2026, the average yearly pay for vulnerability management engineer in Washington, DC is $114,903.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,900.00 and $131,600.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a vulnerability management engineer, and why are they important?

To thrive as a Vulnerability Management Engineer, you need a solid understanding of cybersecurity principles, vulnerability assessment methodologies, and experience with network and system security, often backed by a relevant degree and certifications like CISSP, CEH, or CompTIA Security+. Familiarity with vulnerability management tools such as Qualys, Nessus, or Rapid7, and knowledge of ticketing and SIEM systems, is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you collaborate with IT teams and convey security risks clearly. These skills and qualities are essential for proactively identifying, prioritizing, and remediating security vulnerabilities to protect organizational assets and maintain compliance.

What is the difference between Vulnerability Management Engineer vs Security Analyst?

AspectVulnerability Management EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Primary FocusIdentifying, assessing, and managing vulnerabilities in systemsMonitoring security events, analyzing threats, and incident response
Work EnvironmentIT/security teams, vulnerability scanning tools, security platformsSecurity operations centers, incident response teams, monitoring dashboards
Industry UsageIT security, cybersecurity firms, large enterprisesAll industries with cybersecurity needs, including finance, healthcare, and government

The Vulnerability Management Engineer primarily focuses on identifying and mitigating system vulnerabilities, while the Security Analyst monitors security events and responds to incidents. Both roles require similar certifications and often work within the same security teams, but their day-to-day tasks differ significantly.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires skills in security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and demand for qualified professionals.

What does a vulnerability management engineer do?

A Vulnerability Management Engineer is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems and networks. They use specialized tools to scan for weaknesses, prioritize risks based on potential impact, and work with IT teams to implement remediation strategies. Additionally, they monitor emerging threats, ensure compliance with security policies, and help educate staff on best practices to protect against cyberattacks.

How does a vulnerability management engineer typically collaborate with other IT and security teams within an organization?

As a Vulnerability Management Engineer, you will work closely with various teams, including IT operations, network administrators, and application developers, to identify, assess, and remediate security vulnerabilities. Collaboration often involves coordinating vulnerability scans, sharing prioritized risk assessments, and helping teams understand the technical and business impact of identified issues. You'll also facilitate remediation efforts by advising on best practices, tracking progress, and sometimes providing training or technical support to ensure vulnerabilities are addressed in a timely manner. Effective communication and relationship-building skills are essential for success in this collaborative, cross-functional role.

What are popular job titles related to Vulnerability Management Engineer jobs in Washington, DC?

For Vulnerability Management Engineer jobs in Washington, DC, the most frequently searched job titles are:

What job categories do people searching Vulnerability Management Engineer jobs in Washington, DC look for?

The top searched job categories for Vulnerability Management Engineer jobs in Washington, DC are:

Infographic showing various Vulnerability Management Engineer job openings in Washington, DC as of August 2026, with employment types broken down into 93% Full Time, and 7% Contract. Highlights an 93% In-person, and 7% Remote job distribution, with an average salary of $114,903 per year, or $55.2 per hour.

Senior Vulnerability Management Engineer

System One

Bethesda, MD โ€ข Remote

$107K - $146K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 2 days ago

New


Job description

Job Title: Senior Vulnerability Management Engineer / Lead Location: Bethesda, Maryland Type: Direct Hire / Perm Work Model: 99% remote with occasional onsite for meetings Security Clearance: Public Trust Position Summary The Senior Vulnerability Management Engineer leads enterprise vulnerability management activities across NIH/OD-managed environments, providing technical leadership for vulnerability identification, risk prioritization, remediation coordination, reporting, and compliance. Key Responsibilities

  • Lead enterprise vulnerability management operations and continuous program improvement.
  • Manage and optimize vulnerability scanning infrastructure and tools.
  • Oversee credentialed host, network, application, database, and endpoint vulnerability scanning.
  • Analyze scan results and prioritize vulnerabilities based on risk and federal requirements.
  • Lead vulnerability discovery, validation, mitigation, remediation tracking, and closure.
  • Ensure critical vulnerabilities are escalated and tracked through resolution.
  • Monitor the CISA Known Exploited Vulnerabilities (KEV) Catalog and other authoritative sources.
  • Coordinate remediation activities with system owners and technical teams.
  • Provide risk analysis and technical recommendations for identified vulnerabilities.
  • Support specialized vulnerability assessments for High Value Assets.
  • Develop reports, dashboards, metrics, and executive briefings.
  • Ensure reporting complies with NIH, HHS, CISA, FISMA, and HVA requirements.
  • Improve tool tuning, asset visibility, and reporting accuracy.
  • Mentor mid-level and junior staff.
Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
  • 8–12 years of cybersecurity experience, including at least 5 years in enterprise vulnerability management.
  • Experience with Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or similar tools.
  • Knowledge of CVEs, CVSS, KEVs, NIST guidance, FISMA, CISA directives, and federal vulnerability remediation requirements.
  • Strong communication and reporting skills.
Recommended Certifications
  • CISSP
  • CISM
  • GIAC Certified Enterprise Defender (GCED)
  • GIAC Certified Vulnerability Assessor (GCVA)
  • CompTIA CySA+
  • Tenable Certified Professional
  • Qualys VMDR Certification

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

#M-2 #LI-CB5 Ref: #856-Baltimore-S1