1

Vulnerability Management Specialist Jobs (NOW HIRING)

Cybersecurity Analyst III Vulnerability Management Specialist Information Security | Cybersecurity Operations On-Site, Full-Time About the Role This position is the senior technical owner of our ...

Cybersecurity Analyst III Vulnerability Management Specialist Information Security | Cybersecurity Operations On-Site, Full-Time About the Role This position is the senior technical owner of our ...

Cybersecurity Analyst III Vulnerability Management Specialist Information Security | Cybersecurity Operations On-Site, Full-Time About the Role This position is the senior technical owner of our ...

next page

Showing results 1-20

Vulnerability Management Specialist information

See salary details

$30K

$59.4K

$112.5K

How much do vulnerability management specialist jobs pay per year?

As of Jul 26, 2026, the average yearly pay for vulnerability management specialist in the United States is $59,408.00, according to ZipRecruiter salary data. Most workers in this role earn between $37,500.00 and $75,000.00 per year, depending on experience, location, and employer.

What is the difference between Vulnerability Management Specialist vs Security Analyst?

AspectVulnerability Management SpecialistSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, GIAC Security Essentials
Work EnvironmentFocus on vulnerability scanning, patch management, and remediationMonitor security alerts, analyze threats, and respond to incidents
Employer & Industry UsageUsed in cybersecurity teams across various industries to identify and mitigate vulnerabilitiesCommon in security operations centers (SOCs) to analyze and respond to security issues

While both roles are vital in cybersecurity, a Vulnerability Management Specialist primarily focuses on identifying and fixing system vulnerabilities, whereas a Security Analyst monitors and responds to security threats. Understanding these differences helps organizations assign the right roles for comprehensive security coverage.

What are the key skills and qualifications needed to thrive as a Vulnerability Management Specialist, and why are they important?

To thrive as a Vulnerability Management Specialist, you need a solid understanding of cybersecurity principles, vulnerability assessment, and risk analysis, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), patch management systems, and certifications like CISSP or CEH is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify threats and collaborate with IT teams. These skills are crucial for proactively reducing security risks and ensuring an organization’s systems remain protected against emerging threats.

What are some common challenges faced by Vulnerability Management Specialists when coordinating remediation efforts across multiple teams?

Vulnerability Management Specialists often encounter challenges when collaborating with various IT and business units to address and remediate security vulnerabilities. These challenges can include aligning priorities across teams, managing communication barriers, and ensuring timely remediation while minimizing operational disruptions. Specialists must balance technical urgency with business constraints and often need to educate stakeholders about the risks and compliance requirements. Effective coordination, clear reporting, and relationship-building are key to overcoming these obstacles.

What is a Vulnerability Management Specialist?

A Vulnerability Management Specialist is an IT security professional responsible for identifying, evaluating, prioritizing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They use specialized tools to scan for weaknesses, analyze risks, and coordinate with other teams to ensure timely remediation. Their work is crucial for protecting an organization against cyber threats and ensuring compliance with security standards.
More about Vulnerability Management Specialist jobs
Infographic showing various Vulnerability Management Specialist job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, 1% Temporary, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $59,408 per year, or $28.6 per hour.

Vulnerability Management Specialist

Core Specialty

Cincinnati, OH • Hybrid

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 7 hours ago


Job description

-

The Vulnerability Management Specialist is a hands-on individual contributor responsible for executing Core Specialty's vulnerability management program across endpoints, servers, cloud resources, and applications. This role focuses on continuous vulnerability scanning, risk analysis, remediation coordination, and reporting, working closely with IT, Infrastructure, Endpoint, and Threat teams.

The ideal candidate is highly analytical, detail-oriented, and comfortable operating in a metrics-driven, SLA-based environment, with the ability to translate technical findings into actionable remediation guidance.

The selected candidate will be required to work a hybrid schedule (3 days in office/2 remote) out of our Dallas, TX, or Cincinnati, OH office. No relocation assistance is being offered with this role.

Key Accountabilities/Deliverables:

  • Conduct continuous vulnerability scanning across enterprise assets using Qualys and related tools.

  • Analyze scan results to validate findings, remove false positives, and assess exploitability.

  • Prioritize vulnerabilities using CVSS, Qualys Detection Score (QDS), asset criticality, and business impact.

  • Enforce remediation SLAs aligned to severity levels: Critical: 7 days, High: 30 days, Medium: 60 days, Low: 180 days.

  • Partner with Infrastructure, EUC, Cloud, and Application teams to drive timely remediation.

  • Support remediation activities using Qualys, Intune, JAMF, PolicyPak, and Microsoft Defender.

  • Ensure vulnerability management activities aligned with NIST, CIS Controls, ISO 27001, and insurance regulatory expectations.

  • Partner with Threat Intelligence and SOC teams to assess vulnerability exposure related to active threats.

  • Develop scripts (PowerShell) and workflows to support remediation, reporting, and validation.


Technical Knowledge and Understanding:

  • Strong understanding of: CVSS scoring and risk prioritization, patch management and remediation workflows, endpoint, server, and cloud security fundamentals.

  • Ability to analyze technical findings and communicate risk clearly to non-security teams.

  • Strong documentation and organizational skills.


Experience required:

  • 4+ years of experience in vulnerability management, security engineering, or threat operations.

  • Hands-on experience with vulnerability scanning platforms (Qualys preferred; Tenable/Rapid7 acceptable).

  • Experience working with Intune, JAMF, or similar endpoint management tools.


Certifications (Preferred):

  • CompTIA Security+

  • Qualys Vulnerability Management certifications

  • GIAC certifications (e.g., GSEC, GCIH)

  • CISSP (or progress toward certification)


Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa for this position.
#LI-Hybrid

-

At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement. We offer medical, dental, vision, and life insurances; short and long-term disability; a Company-match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program