1

Vulnerability Management Project Manager Jobs (NOW HIRING)

Vulnerability Management Analyst Location: Hanscom AFB, MA Clearance: Secret Program: BLITS 3.0 Company/ Program Description: Centuria, a Service-Disabled Veteran-Owned Small Business (SDVOSB), has ...

Qualifications 2+ years of experience in vulnerability management, patch management, or system administration within a DoD or enterprise environment. Associate's degree in a related field. Must be ...

Senior Vulnerability Management Engineer

Seattle, WA · On-site

$118K - $163K/yr

About the role As a Senior Vulnerability Management Engineer you will independently identify, assess, prioritize, and drive the remediation of vulnerabilities across applications, infrastructure ...

Showing results 21-40

Vulnerability Management Project Manager information

See salary details

$37.5K

$103K

$166K

How much do vulnerability management project manager jobs pay per year?

As of Sep 9, 2026, the average yearly pay for vulnerability management project manager in the United States is $103,024.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,000.00 and $125,000.00 per year, depending on experience, location, and employer.

What is a vulnerability management project manager?

A Vulnerability Management Project Manager is a professional responsible for overseeing and coordinating projects that identify, assess, and remediate security vulnerabilities within an organization’s IT environment. They work with cross-functional teams to ensure vulnerabilities are tracked, prioritized, and addressed according to risk. This role involves project management, communication with stakeholders, and ensuring compliance with security policies and standards. Their goal is to minimize security risks and protect the organization’s assets from potential threats.

How does a vulnerability management project manager typically collaborate with IT and security teams to address identified vulnerabilities?

A Vulnerability Management Project Manager acts as a bridge between technical teams and organizational leadership, ensuring that vulnerabilities are prioritized and remediated efficiently. They coordinate with IT and security professionals to track the status of vulnerabilities, assign remediation tasks, and establish timelines for resolution. Regular meetings and progress updates help align all stakeholders and ensure compliance with internal policies and external regulations. This collaborative approach fosters a proactive security posture and streamlines communication across departments.

What are the key skills and qualifications needed to thrive as a vulnerability management project manager, and why are they important?

To thrive as a Vulnerability Management Project Manager, you need expertise in cybersecurity frameworks, risk assessment, and project management, often supported by a bachelor’s degree and certifications like CISSP or PMP. Familiarity with vulnerability scanning tools (e.g., Qualys, Nessus), ticketing systems, and remediation tracking software is essential. Strong communication, leadership, and problem-solving skills help coordinate cross-functional teams and drive remediation efforts. These skills ensure vulnerabilities are identified, prioritized, and resolved efficiently, reducing organizational risk and ensuring compliance.

What is the difference between Vulnerability Management Project Manager vs Vulnerability Analyst?

AspectVulnerability Management Project ManagerVulnerability Analyst
CertificationsCompTIA Security+, PMP, CISSP (preferred)CompTIA Security+, GIAC Security Essentials (GSEC)
Work EnvironmentOversees projects, coordinates teams, manages timelinesPerforms vulnerability assessments, analyzes security data
Industry UsageUsed in cybersecurity teams across various industriesCommonly found in security operations centers (SOCs)

The Vulnerability Management Project Manager focuses on leading and coordinating vulnerability management projects, ensuring timely remediation. In contrast, the Vulnerability Analyst conducts technical assessments and analyzes vulnerabilities. Both roles require cybersecurity certifications and work within similar environments, but their responsibilities differ in scope and focus.

What cities are hiring for Vulnerability Management Project Manager jobs?

Cities with the most Vulnerability Management Project Manager job openings:

What states have the most Vulnerability Management Project Manager jobs?

States with the most job openings for Vulnerability Management Project Manager jobs include:

What are popular job titles related to Vulnerability Management Project Manager jobs?

For Vulnerability Management Project Manager jobs, the most frequently searched job titles are:

Infographic showing various Vulnerability Management Project Manager job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 83% Physical, 2% Hybrid, and 15% Remote job distribution, with an average salary of $103,024 per year, or $49.5 per hour.

Vulnerability Management Analyst

Remote

Full-time

Re-posted 11 days ago


Job description

Overview
DecisionPoint seeks a Vulnerability Management Analyst to support enterprise cybersecurity operations across a federal and DoD-aligned mission environment. This role conducts vulnerability scanning, patch verification, security analysis, prioritization of findings, mitigation tracking, and updates to Plan of Action and Milestones (POA&Ms). The analyst will help ensure systems remain compliant with DoD and federal cybersecurity controls by continuously identifying, validating, and monitoring vulnerabilities across cloud and on-premise environments.
The Vulnerability Management Analyst plays a key role in enhancing the security posture of mission systems by providing actionable insights, collaborating with engineering teams, and maintaining visibility into risk trends and remediation progress.
This position is fully remote.
Note: By applying to this position, you acknowledge and consent to having your resume included in an active competitive government contract bid.
Duties & Responsibilities
The Vulnerability Management Analyst will:
  • Conduct ACAS vulnerability scans across enterprise systems, applications, and cloud workloads.
  • Validate vulnerability scan results, confirm patch levels, and verify remediation status across environments.
  • Analyze vulnerabilities for exploitability, potential impact, and relevance to mission systems.
  • Prioritize vulnerabilities based on severity, risk scoring, operational context, and DoD guidance.
  • Coordinate with engineering, system administration, and cloud teams on mitigation steps and remediation timelines.
  • Update, track, and maintain POA&Ms with accurate vulnerability details and milestone progress.
  • Provide vulnerability summaries, dashboards, and reporting to cybersecurity leadership and government stakeholders.
  • Support continuous monitoring activities and reporting cycles in accordance with DoD RMF requirements.
  • Validate STIG-related findings and support configuration compliance checks.
  • Maintain ACAS scanning schedules, asset coverage, and scan completeness across environments.
  • Contribute to incident response efforts when vulnerabilities are linked to active threats.
  • Document vulnerability processes, scanning standards, and remediation workflows.

Qualifications
Clearance Requirement
Must hold an active Top Secret clearance, supported by a Tier 5 background investigation.
Education (Required)
Bachelor's degree in Cybersecurity, Information Technology, or a related field.
Experience (Required)
  • Minimum 5 years of experience in vulnerability management, cybersecurity operations, or system security analysis.
  • Experience running ACAS/Nessus scans and validating vulnerability data.
  • Experience analyzing vulnerabilities, prioritizing risk, and coordinating remediation with technical teams.
  • Experience updating POA&Ms, tracking mitigation progress, and supporting RMF continuous monitoring.
  • Experience performing patch verification and configuration-compliance checks.

Technical Knowledge (Required)
  • Proficiency with ACAS and Nessus scanning tools.
  • Knowledge of vulnerability scoring (CVSS), exploitability assessment, and prioritization frameworks.
  • Understanding of DoD RMF continuous monitoring requirements and POA&M processes.
  • Knowledge of STIGs, secure configuration baselines, and compliance validation.
  • Familiarity with SIEM platforms, log analysis, and threat context enumeration.

Technical Knowledge (Preferred)
  • Experience with cloud security scanning tools, especially AWS-native or container security scanners.
  • Experience with automation or scripting (Python, PowerShell) for data extraction or report generation.
  • Familiarity with enterprise asset management and CMDB tools.

Certifications
Required:
  • Security+
  • ACAS Certification
  • CEH

Preferred:
  • Additional DoD 8570/8140 cybersecurity certifications

Skills
  • Strong analytical and investigative abilities for evaluating vulnerabilities and identifying true risk.
  • Excellent written and verbal communication skills for producing reports and collaborating with technical teams.
  • High attention to detail for validating scan results, documenting findings, and maintaining POA&M accuracy.
  • Ability to manage multiple priorities and operate in a fast-paced, mission-critical environment.
  • Strong organizational and documentation skills to support tracking, reporting, and compliance workflows.

Our Equal Employment Opportunity Policy
  • EEO and Affirmative Action Policy: DecisionPoint Corporation is an Equal Employment Opportunity and Affirmative Action employer. It is the policy of DecisionPoint Corporation to provide equal employment opportunity in accordance with all applicable Equal Employment Opportunity/Affirmative Action laws, directives and regulations to all employees and qualified applicants without regard to race, ethnicity, color, religion, national origin, sex, age, disability status, pregnancy, sexual orientation, gender identity, genetic information, protected veteran status, or any other protected status under Federal, State or Local laws.
  • Pay Transparency Policy: In accordance with Presidential Executive Order 13665, DecisionPoint Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.
  • Authorization to Share Resume and Personal Information: By expressing your interest and submitting your resume for this position, you authorize DecisionPoint Corporation to share your resume, as well as personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should DecisionPoint Corporation. or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.