1

Vulnerability Management Specialist Jobs (NOW HIRING)

$82 - $105.42/hr

Als Spezialist:in oder auch als Generalist:in. Alles mit besten Karrierechancen, viel Raum für ... an den Standorten Münster oder Hannover einen Vulnerability Management Architect ...

New

The Patch Management Specialist, Junior supports the patch management lifecycle for desktops ... Monitor vulnerability and patch compliance reports, interpret risk levels, and work with senior ...

Showing results 41-60

Vulnerability Management Specialist information

See salary details

$30K

$59.4K

$112.5K

How much do vulnerability management specialist jobs pay per year?

As of Sep 4, 2026, the average yearly pay for vulnerability management specialist in the United States is $59,408.00, according to ZipRecruiter salary data. Most workers in this role earn between $37,500.00 and $75,000.00 per year, depending on experience, location, and employer.

What is a vulnerability management specialist?

A Vulnerability Management Specialist is an IT security professional responsible for identifying, evaluating, prioritizing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They use specialized tools to scan for weaknesses, analyze risks, and coordinate with other teams to ensure timely remediation. Their work is crucial for protecting an organization against cyber threats and ensuring compliance with security standards.

What are the key skills and qualifications needed to thrive as a vulnerability management specialist, and why are they important?

To thrive as a Vulnerability Management Specialist, you need a solid understanding of cybersecurity principles, vulnerability assessment, and risk analysis, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), patch management systems, and certifications like CISSP or CEH is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify threats and collaborate with IT teams. These skills are crucial for proactively reducing security risks and ensuring an organization’s systems remain protected against emerging threats.

What are some common challenges faced by vulnerability management specialists when coordinating remediation efforts across multiple teams?

Vulnerability Management Specialists often encounter challenges when collaborating with various IT and business units to address and remediate security vulnerabilities. These challenges can include aligning priorities across teams, managing communication barriers, and ensuring timely remediation while minimizing operational disruptions. Specialists must balance technical urgency with business constraints and often need to educate stakeholders about the risks and compliance requirements. Effective coordination, clear reporting, and relationship-building are key to overcoming these obstacles.

What is the difference between Vulnerability Management Specialist vs Security Analyst?

AspectVulnerability Management SpecialistSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, GIAC Security Essentials
Work EnvironmentFocus on vulnerability scanning, patch management, and remediationMonitor security alerts, analyze threats, and respond to incidents
Employer & Industry UsageUsed in cybersecurity teams across various industries to identify and mitigate vulnerabilitiesCommon in security operations centers (SOCs) to analyze and respond to security issues

While both roles are vital in cybersecurity, a Vulnerability Management Specialist primarily focuses on identifying and fixing system vulnerabilities, whereas a Security Analyst monitors and responds to security threats. Understanding these differences helps organizations assign the right roles for comprehensive security coverage.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires technical skills, knowledge of security tools, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and demand for qualified professionals.

What is the salary of vulnerability management specialist?

The average salary for a vulnerability management specialist typically ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Professionals with skills in cybersecurity tools and vulnerability assessment often earn higher salaries.
More about Vulnerability Management Specialist jobs
Infographic showing various Vulnerability Management Specialist job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $59,408 per year, or $28.6 per hour.

Senior Security Specialist, Vulnerability Management

Viasat, Inc.

Carlsbad, CA • On-site

Full-time

Re-posted 9 days ago


Viasat rating

7.0

Company rating: 7.0 out of 10

Based on 12 frontline employees who took The Breakroom Quiz

69th of 101 rated telecommunications companies


Job description

About us
One team. Global challenges. Infinite opportunities. At Viasat, we're on a mission to deliver connections with the capacity to change the world. For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries around the globe communicate. We're looking for people who think big, act fearlessly, and create an inclusive environment that drives positive impact to join our team.
What you'll do
  • Vulnerability Prioritization: Efficiently evaluate and respond to the daily influx of newly disclosed CVEs, cutting through the noise to separate theoretical risks from immediate, real-world threats to our business
  • Determine the Optimal Mitigation Path: Prioritize what needs to be fixed and how to do it efficiently-whether that means coordinating a full software/OS update, deploying a temporary configuration workaround, or implementing compensating security controls.
  • Navigate System Ownership: Track down and identify the exact system owners and engineering teams responsible for vulnerable assets, ensuring every high-priority vulnerability is routed to the right person for swift remediation.
  • Scale the Program via Automation: Design concepts and build them with fellow security engineers to automate the process allowing us to handle a high volume of threats without increasing manual overhead.
  • Assist with Audits and Regulatory Alignment: Function as the technical representative during internal and external audit reviews.
  • Collaborate directly with auditors to illustrate program maturity and detail vulnerability scanning methodologies.
  • Create automated dashboards to track operational efficiency metrics, including Mean Time to Detect (MTTD) relevant CVEs and Mean Time to Remediate (MTTR).
  • Lead Zero-Day Assessments: Serve as the VM initial responder during urgent, zero-day vulnerability revelations. Quickly scope our exposure, assess the blast radius across infrastructure and codebases, and coordinate response efforts.
  • Develop automated data visualizations and reporting tools. These tools retrieve audit evidence on demand, such as proof of patching SLA adherence, historical scanning cadences, and approved risk exceptions. This reduces time spent on manual preparation.

The day-to-day
  • Tactical Threat Triage: Analyze internal data against advisories to identify critical risks relevant to our infrastructure and work to mitigate them.
  • Lead Zero-Day Assessments: Function as the VM first-responder during critical, zero-day disclosures. Rapidly determine our exposure, evaluate the blast radius throughout infrastructure and codebases, and coordinate response efforts.
  • Scale Reporting Metrics: Design automated dashboards that track operational efficiency metrics, such as Mean Time to Detect (MTTD) relevant CVEs and Mean Time to Remediate (MTTR).
  • Support Audits & Regulatory Compliance: Serve as the technical point of contact during internal and external audits. Interface directly with auditors to demonstrate program maturity and explain vulnerability scanning methodologies.

What you'll need
  • Experience: 5+ years of experience in Vulnerability Management, with at least 3 years dedicated specifically to tactical vulnerability management.
  • Risk-Prioritization: In-depth knowledge of modern vulnerability evaluation frameworks, including EPSS, CVSS, SSVC, and KEV.
  • Audit Defense: Demonstrable experience preparing for and participating in external third-party security audits (e.g., ISO 27001, PCI, or CMMC).
  • Defending Technical Risk Decisions: Demonstrated ability to confidently explain vulnerability prioritizations, technical workarounds, and formal risk acceptance/exception decisions to both internal compliance teams and external auditors.
  • Tooling Proficiency: Deep hands-on experience with enterprise scanners and cloud-native security platforms.
  • Technical Depth: Good understanding of operating system internals, container environments, and cloud security fundamentals.
  • Communication & Influence: Demonstrable ability to translate complex vulnerability details into clear, actionable technical instructions for engineering partners without direct authority.
    • Tactical Threat Triage: Analyze internal data against new CVEs and vulnerability disclosures to identify critical risks relevant to our infrastructure and work to mitigate them.
    • Lead Zero-Day Assessments: Act as the VM first-responder during critical, zero-day disclosures. Quickly scope our exposure, assess the blast radius across infrastructure and codebases, and coordinate response efforts.
    • Scale Reporting Metrics: Design automated dashboards that track operational efficiency metrics, such as Mean Time to Detect (MTTD) relevant CVEs and Mean Time to Remediate (MTTR).
    • Support Audits & Regulatory Compliance: Serve as the technical point of contact during internal and external audits. Interface directly with auditors to demonstrate program maturity and explain vulnerability scanning methodologies.
    • Build automated reports and dashboards that pull audit evidence on demand. Examples include proof of patching SLA alignment, historical scanning cadences, and approved risk exceptions. This reduces manual preparation time.

What will help you on the job
  • Artificial Intelligence: Familiarity/Experience with AI technologies, with a strong preference for knowledge in AI risk and governance frameworks (experience applying these concepts to vulnerability management is a major plus).
  • Penetration Testing: Experience with penetration testing methodologies and tools to help validate vulnerability exploitability and assist with remediation prioritization.
    • Workflow Automation: Prior experience building security pipelines inside automation and orchestration platforms.
    • CI/CD: Familiarity with CI/CD tools and automated configuration/deployment environments.
    • Active Security Community Engagement: A passion for following emerging threats, exploit trends, and security research.
    • Industry Certifications: SANS GPEN or GEVA.
    • Web Applications: experience in assessments or penetration testing of web applications and Internet-facing tech stacks.

Salary range
$121,000.00 - $191,000.00 / annually.For specific work locations within San Jose, the San Francisco Bay area and New York City metropolitan area, the base pay range for this role is $150,000.00- $225,000.00/ annually
At Viasat, we consider many factors when it comes to compensation, including the scope of the position as well as your background and experience. Base pay may vary depending on job-related knowledge, skills, and experience. Additional cash or stock incentives may be provided as part of the compensation package, in addition to a range of medical, financial, and/or other benefits, dependent on the position offered. Learn more about Viasat's comprehensive benefit offerings that are focused on your holistic health and wellness at https://careers.viasat.com/benefits.
EEO Statement
Viasat is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, ancestry, physical or mental disability, medical condition, marital status, genetics, age, or veteran status or any other applicable legally protected status or characteristic. If you would like to request an accommodation on the basis of disability for completing this on-line application, please click here.

What Viasat employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


ViaSat logo

About ViaSat

Sourced by ZipRecruiter

At Viasat, we're on a mission to deliver connections with the capacity to change the world. For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries around the globe communicate.

Industry

Telecommunications

Company size

5,001 - 10,000 Employees

Headquarters location

Carlsbad, CA, US

Year founded

1986