1

Vulnerability Researcher Contractor Jobs in Colorado

... Security Researcher, Software Reverse Engineer, Vulnerability Researcher, Forensic Analyst ... We are a growing small business and a trusted federal contractor offering full scope consulting ...

Together with our nonprofit research institute and foundation, we tune in, step up, and are a force ... Enhance and automate the vulnerability management lifecycle, including intake, prioritization ...

... research, development and implementation of information security initiatives, such as policy ... Enhance and automate the vulnerability management lifecycle, including intake, prioritization ...

Desktop Endpoint Specialist

Boulder, CO · On-site

$92K - $122K/yr

The role combines end-user support with endpoint lifecycle, inventory, vulnerability, software ... Equal Opportunity & Compliance Statement This contractor and subcontractor shall abide by the ...

next page

Showing results 1-20

Vulnerability Researcher Contractor information

What does a vulnerability researcher contractor do?

A Vulnerability Researcher Contractor is an information security professional who specializes in identifying, analyzing, and documenting security vulnerabilities in software, systems, or networks. They are often hired on a temporary or project basis to assess the security posture of an organization or specific products. Their responsibilities may include conducting penetration tests, reverse engineering software, developing proof-of-concept exploits, and providing recommendations for mitigating discovered vulnerabilities. Contractors in this role typically work independently or as part of a security team and may present their findings to stakeholders or assist in developing security patches.

What are the key skills and qualifications needed to thrive as a vulnerability researcher contractor?

To thrive as a Vulnerability Researcher Contractor, you need a deep understanding of computer systems, networking, programming languages (such as C/C++, Python), and a strong background in cybersecurity, often supported by relevant degrees or certifications like OSCP or CEH. Familiarity with vulnerability assessment tools (e.g., IDA Pro, Burp Suite, Metasploit), reverse engineering platforms, and bug tracking systems is typically required. Analytical thinking, attention to detail, and effective written communication are vital soft skills in this role. These skills ensure the accurate identification, documentation, and mitigation of security vulnerabilities, which are crucial for protecting organizational assets.

What are the typical collaboration dynamics for a vulnerability researcher contractor within cybersecurity teams?

As a Vulnerability Researcher Contractor, you’ll often work closely with internal security teams, developers, and sometimes external clients to identify, analyze, and document security flaws. Despite being a contractor, you’ll participate in regular team meetings, share findings, and sometimes assist in developing proof-of-concept exploits or remediation guidance. The role requires strong communication skills, as you’ll need to clearly explain technical vulnerabilities to both technical and non-technical stakeholders. Contract positions may also require rapid onboarding and adaptability to different workflows, making flexibility and proactive communication essential.

What is the difference between Vulnerability Researcher Contractor vs Penetration Tester?

AspectVulnerability Researcher ContractorPenetration Tester
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, often including OSCP, CEH, GPEN
Work EnvironmentResearch-focused, analyzing vulnerabilities in systems and softwarePractical testing, simulating attacks to identify security gaps
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesSecurity firms, internal security teams, consulting roles
Search & Comparison IntentUnderstanding research vs active testing rolesDistinguishing between research and hands-on attack simulation

While both roles involve cybersecurity expertise, Vulnerability Researcher Contractors focus on discovering and analyzing vulnerabilities through research, whereas Penetration Testers actively simulate attacks to evaluate security defenses. Both roles often require similar certifications and work in related environments, but their core activities differ: research versus practical testing.

What are popular job titles related to Vulnerability Researcher Contractor jobs in Colorado?

For Vulnerability Researcher Contractor jobs in Colorado, the most frequently searched job titles are:

What job categories do people searching Vulnerability Researcher Contractor jobs in Colorado look for?

The top searched job categories for Vulnerability Researcher Contractor jobs in Colorado are:

Infographic showing various Vulnerability Researcher Contractor job openings in Colorado as of September 2026, with employment types broken down into 1% Internship, 76% Full Time, 12% Part Time, and 11% Contract. Highlights an 88% Physical, 1% Hybrid, and 11% Remote job distribution.

Cyber Vulnerability Assessment Analyst - Intermediate

Colorado Springs, CO • On-site

NewSat North America LLC
Guided Missile and Space Vehicle Manufacturing • 11 - 50 employees

$130K - $140K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 22 days ago

Be Seen First

After you apply to this job, you can share why you’re interested to jump to the top of the candidate list.


Job description

POSITION SUMMARY

NewSat is seeking an Intermediate-level Vulnerability Assessment Analyst to support our U.S. Space Force (USSF) customer. This position performs vulnerability assessment and remediation-tracking activities across a platform spanning more than 42 deployed environments across approximately 900 servers at multiple classification levels.


Working with only periodic high-level guidance, the Intermediate VAA executes recurring and ad hoc assessments, validates findings, and supports remediation and continuous monitoring activities in non-routine and sometimes complicated situations. This role supports the task order’s Continuous Cyber Monitoring, Threat Assessment and Risk Mitigation, and Body of Evidence artifact management service areas.

KEY RESPONSIBILITIES

•      Execute scheduled and ad hoc vulnerability scans across the existing environment and during assessment of new connections using ACAS/Nessus and DoD-approved assessment tooling.

•      Apply DISA STIGs and SCAP benchmarks; validate compliance results and research findings to confirm or dismiss false positives.

•      Analyze scan output, correlate findings across environments, and document results in standardized assessment reports.

•      Track remediation actions to closure with system owners; support POA&M entry, updates, and supporting evidence.

•      Assemble Body of Evidence (BoE) artifacts supporting Certificate to Field (CtF), Authority to Connect (ATC) and continuous monitoring requirements.

•      Support assessment of cloud and container workloads, including AWS tenant spaces and EKS-hosted services.

•      Escalate complex, high-risk, or disputed findings to the Advanced VAA or Security Architect for adjudication.

•      Maintain assessment documentation, scan configurations, and reporting cadence in accordance with program procedures.

REQUIRED QUALIFICATIONS

•      Active TS clearance with SCI eligibility; ability to meet program-directed access requirements.

•      Minimum 4 years of cybersecurity experience with direct vulnerability assessment or vulnerability management responsibility.

•      Security+ CE or equivalent DoD 8140 / 8570 baseline certification current at time of hire.

•      Hands-on experience with ACAS/Nessus or comparable scanning platforms and with STIG/SCAP compliance checking.

•      Familiarity with RMF, NIST SP 800-53 control families, and POA&M processes.

•      Ability to work non-routine assessment tasks with only periodic high-level supervision.

PREFERRED QUALIFICATIONS

•      Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.

•      Experience supporting DoD, IC, or space ground system programs.

•      Certifications such as CySA+, CEH, GCIH, or GSEC.

•      Exposure to containerized or cloud environments (Kubernetes/EKS, AWS).

•      Scripting familiarity (Python, PowerShell, Bash) for reporting and data reduction.

Company Description

NewSat provides cost-competitive, best-of-breed, global C5ISR solutions to ensure mission success for our customers. Our small business provides solutions to many industry partners, both as a prime contractor and value-added subcontractor.