1

Vulnerability Management Engineer Jobs in Washington, DC

Vulnerability Management Lead (RFP)

Washington, DC · On-site

$115K - $152K/yr

They are in search of a highly motivated candidate to join their talented team as a Vulnerability Management Lead, responsible for coordinating vulnerability tracking, remediation support, reporting ...

Vulnerability Management Lead

Herndon, VA · On-site

$105K - $138K/yr

We are seeking a Vulnerability Management Lead to join our team and support our client. The ideal candidate is a proactive cybersecurity professional with deep experience leading enterprise ...

Vulnerability Management Lead

Herndon, VA · On-site

$105K - $138K/yr

We are seeking a Vulnerability Management Lead to join our team and support our client. The ideal candidate is a proactive cybersecurity professional with deep experience leading enterprise ...

Vulnerability Management Lead

Bethesda, MD · On-site

$109K - $144K/yr

We are seeking a Vulnerability Management Lead to join our team and support our client. The ideal candidate is a proactive cybersecurity professional with deep experience leading enterprise ...

Showing results 21-40

Vulnerability Management Engineer information

See Washington, DC salary details

$44K

$114.9K

$155.3K

How much do vulnerability management engineer jobs pay per year?

As of Aug 11, 2026, the average yearly pay for vulnerability management engineer in Washington, DC is $114,903.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,900.00 and $131,600.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a vulnerability management engineer, and why are they important?

To thrive as a Vulnerability Management Engineer, you need a solid understanding of cybersecurity principles, vulnerability assessment methodologies, and experience with network and system security, often backed by a relevant degree and certifications like CISSP, CEH, or CompTIA Security+. Familiarity with vulnerability management tools such as Qualys, Nessus, or Rapid7, and knowledge of ticketing and SIEM systems, is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you collaborate with IT teams and convey security risks clearly. These skills and qualities are essential for proactively identifying, prioritizing, and remediating security vulnerabilities to protect organizational assets and maintain compliance.

What is the difference between Vulnerability Management Engineer vs Security Analyst?

AspectVulnerability Management EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Primary FocusIdentifying, assessing, and managing vulnerabilities in systemsMonitoring security events, analyzing threats, and incident response
Work EnvironmentIT/security teams, vulnerability scanning tools, security platformsSecurity operations centers, incident response teams, monitoring dashboards
Industry UsageIT security, cybersecurity firms, large enterprisesAll industries with cybersecurity needs, including finance, healthcare, and government

The Vulnerability Management Engineer primarily focuses on identifying and mitigating system vulnerabilities, while the Security Analyst monitors security events and responds to incidents. Both roles require similar certifications and often work within the same security teams, but their day-to-day tasks differ significantly.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires skills in security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and demand for qualified professionals.

What does a vulnerability management engineer do?

A Vulnerability Management Engineer is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems and networks. They use specialized tools to scan for weaknesses, prioritize risks based on potential impact, and work with IT teams to implement remediation strategies. Additionally, they monitor emerging threats, ensure compliance with security policies, and help educate staff on best practices to protect against cyberattacks.

How does a vulnerability management engineer typically collaborate with other IT and security teams within an organization?

As a Vulnerability Management Engineer, you will work closely with various teams, including IT operations, network administrators, and application developers, to identify, assess, and remediate security vulnerabilities. Collaboration often involves coordinating vulnerability scans, sharing prioritized risk assessments, and helping teams understand the technical and business impact of identified issues. You'll also facilitate remediation efforts by advising on best practices, tracking progress, and sometimes providing training or technical support to ensure vulnerabilities are addressed in a timely manner. Effective communication and relationship-building skills are essential for success in this collaborative, cross-functional role.
What are popular job titles related to Vulnerability Management Engineer jobs in Washington, DC? For Vulnerability Management Engineer jobs in Washington, DC, the most frequently searched job titles are:
What job categories do people searching Vulnerability Management Engineer jobs in Washington, DC look for? The top searched job categories for Vulnerability Management Engineer jobs in Washington, DC are:
Infographic showing various Vulnerability Management Engineer job openings in Washington, DC as of August 2026, with employment types broken down into 93% Full Time, and 7% Contract. Highlights an 93% In-person, and 7% Remote job distribution, with an average salary of $114,903 per year, or $55.2 per hour.

Vulnerability Management Analyst

Leidos

Camp Springs, MD • On-site

Full-time

Posted 28 days ago


Leidos rating

8.3

Company rating: 8.3 out of 10

Based on 151 frontline employees who took The Breakroom Quiz

76th of 485 rated business services


Job description

Leidos has a career opportunity for a Vulnerability Management Analyst to support the Air Force National Capital Region IT Services program.

The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), Office of the Secretary of Defense (OSD), Joint Chiefs of Staff, and other Air Force activities within the AFNCR, missions to include the Pentagon, Joint Base Andrews (JBA), Joint Base Anacostia-Bolling (JBAB), and other locations, leased spaces, and alternate sites. The major support areas required are IT Operations and Maintenance; Plans, Projects, and Engineering (PP&E); and National Military Command Center (NMCC). The senior leaders and national defense missions that are supported require that the AFNCR operations never fail, resulting in a fast-paced, challenging, but also rewarding environment.

If this sounds like the kind of environment where you can thrive, keep reading!

Leidos Defense Group provides a diverse portfolio of systems, solutions, and services covering land, sea, air, space, and cyberspace for customers worldwide. Solutions for Defense include enterprise and mission IT, large-scale intelligence systems, command and control, geospatial and data analytics, cybersecurity, logistics, training, and intelligence analysis and operations support. Our team is solving the world's toughest security challenges for customers with "can't fail" missions. To explore and learn more, click here!

Are you ready to make an impact? Begin your journey of a flourishing and meaningful career, share your resume with us today!

POSITION SUMMARY:

Leidos is seeking a Vulnerability Management Analyst to join our Cybersecurity Operations team supporting the AFNCR IT Services (AFNCRIT) program. This T1-level position is ideal for an entry-level cybersecurity professional interested in learning vulnerability management processes. The role will assist with running vulnerability scans using ACAS, reviewing STIG findings, and supporting remediation coordination across Air Force enterprise systems under the guidance of senior team members.

PRIMARY RESPONSIBILITIES:

Assist with scheduling and running vulnerability scans using Tenable SecurityCenter/Nessus (ACAS) in classified and unclassified environments under senior staff guidance.

Review scan results to help identify potential CAT I/II/III findings, false positives, and basic configuration issues.

Support tracking of remediation actions, Plans of Action and Milestones (POA&Ms), and exceptions in accordance with RMF guidance.

Follow established procedures to validate DISA STIG checklists and work with team members to ensure secure system configurations.

Help prepare basic vulnerability reports, compliance summaries, and metrics to support leadership briefings and inspection readiness (e.g., CCRI/CORA).

Assist in maintaining asset groupings, scan zones, and credentialed scanning configurations as directed by senior analysts.

Coordinate with Queue Managers, ISSOs, and Engineering teams to support the remediation of high-priority vulnerabilities.

Maintain data accuracy within ACAS, including proper tagging and grouping for consistent reporting.

BASIC QUALIFICATIONS:

Active DoD Secret clearance required.

CompTIA Security+ CE or higher DoD 8570 IAT Level II certification must meet 8140 ISSM role qualification

Bachelor's Degree and 4-8 years of cybersecurity or system administration experience, with at least 1 year of direct ACAS or Tenable experience. Additional education and years of experience may be considered in lieu of a degree.

Working knowledge of DISA STIGs, vulnerability risk levels, and POA&M remediation strategies.

Familiarity with NIST SP 800-53, RMF compliance, and Air Force cybersecurity policy (AFMAN 17-130).

Strong attention to detail, documentation skills, and the ability to interpret technical vulnerability data.

PREFERRED QUALIFICATIONS:

Experience supporting USAF, DISA, or other DoD mission systems.

Familiarity with eMASS, SCAP Compliance Checker (SCC), or HBSS.

Prior involvement in CCRI/CORA preparation or vulnerability remediation campaigns.

Ability to communicate risk-based recommendations to both technical and non-technical stakeholders.

Understanding of automation tools/scripts (e.g., PowerShell, Nessus APIs) to support scan or report optimization.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:July 13, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media