1

Vulnerability Manager Jobs in Reston, VA (NOW HIRING)

Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as ... Collaborate with Information System Security Managers (ISSMs), Information System Security Officers ...

Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as ... Collaborate with Information System Security Managers (ISSMs), Information System Security Officers ...

We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...

Vulnerability Management Lead

Alexandria, VA ยท Hybrid

$109K - $144K/yr

RiVidium is seeking a Vulnerability Management Lead to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data ...

Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...

Vulnerability Analyst, Senior

Herndon, VA ยท On-site

$104K - $166K/yr

Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...

Vulnerability Analyst, Senior

Herndon, VA ยท On-site

$104K - $166K/yr

Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...

next page

Showing results 1-20

Vulnerability Manager information

See Reston, VA salary details

$10

$22

$56

How much do vulnerability manager jobs pay per hour?

As of Jun 28, 2026, the average hourly pay for vulnerability manager in Reston, VA is $22.78, according to ZipRecruiter salary data. Most workers in this role earn between $18.03 and $22.02 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Manager, and why are they important?

To thrive as a Vulnerability Manager, you need expertise in risk assessment, vulnerability scanning, and cybersecurity fundamentals, typically supported by a degree in information security or a related field. Familiarity with tools like Nessus, Qualys, and vulnerability management platforms, as well as certifications such as CISSP or CEH, is often required. Strong analytical skills, attention to detail, and clear communication are crucial soft skills for effectively identifying issues and coordinating remediation efforts. These abilities ensure that organizations can proactively manage security risks and maintain robust defense against cyber threats.

What is the difference between Vulnerability Manager vs Security Analyst?

AspectVulnerability ManagerSecurity Analyst
CertificationsCertified Vulnerability Assessor (CVA), CISSP, CEHCISSP, Security+, CEH
Work EnvironmentOversees vulnerability assessments, manages teams, develops strategiesMonitors security systems, analyzes threats, responds to incidents
Employer & Industry UsageUsed in cybersecurity teams across industries to manage vulnerabilitiesCommonly employed in security operations centers (SOCs) to analyze threats

While both roles focus on cybersecurity, Vulnerability Managers primarily oversee vulnerability assessments and strategy, whereas Security Analysts focus on monitoring and incident response. Both roles require relevant certifications and work within cybersecurity teams, but their daily responsibilities and focus areas differ.

What does a Vulnerability Manager do?

A Vulnerability Manager is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They oversee vulnerability scanning, analyze the results, prioritize risks, and work with various teams to implement remediation strategies. Their goal is to reduce the organization's exposure to cyber threats by ensuring that security weaknesses are addressed promptly and effectively.

What are some common challenges faced by Vulnerability Managers when prioritizing remediation efforts?

Vulnerability Managers often encounter challenges in balancing limited resources with a high volume of identified vulnerabilities. Prioritizing remediation efforts requires close collaboration with IT, development, and business teams to assess the potential impact and exploitability of each vulnerability. Additionally, they must stay updated on emerging threats, ensure compliance with industry standards, and communicate risk effectively to both technical and non-technical stakeholders. Navigating these complexities is essential for maintaining a strong security posture while minimizing disruption to business operations.
What cities near Reston, VA are hiring for Vulnerability Manager jobs? Cities near Reston, VA with the most Vulnerability Manager job openings:
Infographic showing various Vulnerability Manager job openings in Reston, VA as of June 2026, with employment types broken down into 71% Full Time, 24% Part Time, and 5% Contract. Highlights an 83% Physical, 3% Hybrid, and 14% Remote job distribution, with an average salary of $47,376 per year, or $22.8 per hour.

Vulnerability Assessor

asrcfh

Alexandria, VA โ€ข Hybrid

Other

Posted 17 days ago


Job description

Vulnerability Assessor

Location: Alexandria, VA (Hybrid โ€“ Telework with periodic on-site support as required)
Clearance: Active Secret


Position Overview

ASRC Federal is seeking a Vulnerability Assessor to support the Department of War Education Activity (DoWEA) Enterprise Cyber Program. The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organizationโ€™s cybersecurity posture and ensure compliance with DoD Risk Management Framework (RMF) requirements. This role supports Continuous Monitoring (ConMon) activities and works closely with cybersecurity and system teams to enhance DoWEAโ€™s enterprise-wide security operations.


Responsibilities
  • Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools.

  • Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs, and DoDI 8510.01 (RMF).

  • Collaborate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), and system administrators to track remediation and update Plans of Action and Milestones (POA&Ms).

  • Prepare and maintain vulnerability assessment reports and risk summaries for leadership.

  • Support RMF Steps 3โ€“6 and Continuous Monitoring documentation within eMASS.

  • Research and evaluate emerging technologies to identify new or evolving risks and recommend mitigation strategies.


Basic Qualifications
  • Bachelorโ€™s degree in Cybersecurity, Computer Science, Information Technology, or related discipline (four additional years of equivalent experience may substitute).

  • Minimum 5+ years of cybersecurity or vulnerability management experience.

  • Active DoD Secret clearance

  • DoD 8570.01-M IAT Level II certification (e.g., Security+ CE, CySA+, CCNA-Security).

  • Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.

  • Strong analytical, documentation, and communication skills.

  • Working knowledge of vulnerability scanning, risk assessment methodologies, and remediation tracking.


Preferred Qualifications
  • Familiarity with DoW (DoD) RMF, eMASS, and DISA STIG/SRG compliance.

  • Understanding of NIST SP 800-53, CNSSI 1253, and DoDI 8510.01 frameworks.

  • Knowledge of common cybersecurity threats, exploits, and attack vectors.

  • Experience supporting federal or DoD IT environments.

  • Positive, proactive approach and ability to collaborate effectively across remote and on-site teams.