1

Vulnerability Manager Jobs in Virginia (NOW HIRING)

AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...

AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...

AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...

Vulnerability Analyst

Fairfax, VA · On-site

$100K - $130K/yr

Contingent upon contract award Signal Hill Technologies is seeking a highly skilled Vulnerability Analyst to support our federal client's vulnerability management program. The position is contingent ...

Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as ... Collaborate with Information System Security Managers (ISSMs), Information System Security Officers ...

Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as ... Collaborate with Information System Security Managers (ISSMs), Information System Security Officers ...

Vulnerability Management Lead

Alexandria, VA · Hybrid

$109K - $144K/yr

RiVidium is seeking a Vulnerability Management Lead to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data ...

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

next page

Showing results 1-20

Vulnerability Manager information

See Virginia salary details

$9

$21

$53

How much do vulnerability manager jobs pay per hour?

As of Jul 27, 2026, the average hourly pay for vulnerability manager in Virginia is $21.71, according to ZipRecruiter salary data. Most workers in this role earn between $17.16 and $20.96 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Manager, and why are they important?

To thrive as a Vulnerability Manager, you need expertise in risk assessment, vulnerability scanning, and cybersecurity fundamentals, typically supported by a degree in information security or a related field. Familiarity with tools like Nessus, Qualys, and vulnerability management platforms, as well as certifications such as CISSP or CEH, is often required. Strong analytical skills, attention to detail, and clear communication are crucial soft skills for effectively identifying issues and coordinating remediation efforts. These abilities ensure that organizations can proactively manage security risks and maintain robust defense against cyber threats.

What is the difference between Vulnerability Manager vs Security Analyst?

AspectVulnerability ManagerSecurity Analyst
CertificationsCertified Vulnerability Assessor (CVA), CISSP, CEHCISSP, Security+, CEH
Work EnvironmentOversees vulnerability assessments, manages teams, develops strategiesMonitors security systems, analyzes threats, responds to incidents
Employer & Industry UsageUsed in cybersecurity teams across industries to manage vulnerabilitiesCommonly employed in security operations centers (SOCs) to analyze threats

While both roles focus on cybersecurity, Vulnerability Managers primarily oversee vulnerability assessments and strategy, whereas Security Analysts focus on monitoring and incident response. Both roles require relevant certifications and work within cybersecurity teams, but their daily responsibilities and focus areas differ.

What does a Vulnerability Manager do?

A Vulnerability Manager is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They oversee vulnerability scanning, analyze the results, prioritize risks, and work with various teams to implement remediation strategies. Their goal is to reduce the organization's exposure to cyber threats by ensuring that security weaknesses are addressed promptly and effectively.

What are some common challenges faced by Vulnerability Managers when prioritizing remediation efforts?

Vulnerability Managers often encounter challenges in balancing limited resources with a high volume of identified vulnerabilities. Prioritizing remediation efforts requires close collaboration with IT, development, and business teams to assess the potential impact and exploitability of each vulnerability. Additionally, they must stay updated on emerging threats, ensure compliance with industry standards, and communicate risk effectively to both technical and non-technical stakeholders. Navigating these complexities is essential for maintaining a strong security posture while minimizing disruption to business operations.
What cities in Virginia are hiring for Vulnerability Manager jobs? Cities in Virginia with the most Vulnerability Manager job openings:
Infographic showing various Vulnerability Manager job openings in Virginia as of July 2026, with employment types broken down into 83% Full Time, 14% Part Time, 2% Temporary, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $45,147 per year, or $21.7 per hour.
Vulnerability Manager

Vulnerability Manager

AnaVation

Alexandria, VA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 20 days ago


Job description

Be Challenged and Make a Difference
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.
Description of Task to be Performed:
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving vulnerability analysis and risk prioritization, and delivering reporting to leadership and compliance stakeholders.
Responsibilities:
  • Administer and maintain scanning platforms such as Tenable.SC, Qualys and/or application-based scanners, which may include activities such as scan policies, asset groups, credentials scanning, and agent deployment.
  • Lead enterprise-wide vulnerability scanning cadence across the network, systems, applications and other dependent assets.
  • Analyze scan data, validate findings and false positives, and prioritize based on CVSS, exploitability, and business risk.
  • Own and manage POA&M lifecycle, tracking remediation timelines, risk acceptance documentation, and closure validation.
  • Develop and deliver weekly vulnerability metrics/dashboards and executive reporting (trend analysis, SLA compliance, risk posture).
  • Support ATO and continuous monitoring activities in alignment with NIST 800-53.
  • Coordinate remediation with system owners, IT operations, and patch management teams.
  • Manage scanner tuning, plugin/signature updates, and platform health.
  • Support FISMA reporting requirements. • Interacting with GRC tool (e.g., CSAM) to perform daily/weekly vulnerability analysis.
  • Flexible with other security related tasks as needed by the customer.

This position is hybrid, with the potential for periodic onsite attendance at our customer location in Alexandria, VA.
Applicants who do not currently reside within commuting distance should describe how they would satisfy this requirement. Remote status is subject to change at the customer's direction.
This position requires a Public Trust
Required Qualifications:
  • Bachelor's degree in a related field or equivalent demonstrated experience and knowledge.
  • 6 years of experience as a Security Administrator, Vulnerability Manager or equivalent knowledge.
  • Hands-on administration experience with Tenable or Qualys.
  • Performing vulnerability scans with tools such as Tenable, Qualys, Burpsuite.
  • Deep familiarity with CVSS scoring, risk based prioritization methodologies.
  • Excellent oral and written communication skills.
  • Familiarity with multi-tiered network applications, common ports and protocols used in those communications, the Common Vulnerability System (CVS) and the exploitation mechanisms of common vulnerability types (e.g., buffer overflows, cross-site-scripting, SQL injection).
  • Certifications: Security + required

Preferred Qualifications:
  • Self-Starter - ability to quickly become competent with new security-related tools and processes.
  • Ability to conduct Deep Dive analysis to determine root cause assessment of various network scanning agents' scanning or communication failures.
  • Ability to coordinate remediation strategies with agency's department technical staff through completion.
  • Familiarity with the various use cases and alignment of data from each tool to various security disciplines in configuration management, vulnerability management, risk management and incident management.
  • Understanding of the role of interactive training such as phishing exercises for assessment of organizational abilities.
  • Familiarity with the use of data analysis tools, including the use of Microsoft Excel or PowerBI to combine data from multiple sources.
  • Familiarity with information security terminology and being able to develop or select technical training in the discipline of information security geared to an organization.
  • Familiarity with data management and reporting of training data and statistics using common tools such as Microsoft Excel and Word.
  • Certifications: CISSP

Benefits
  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short-term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance

About AnaVation
AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.
If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!
AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.