1

Vulnerability Researcher Contractor Jobs in Florida

Request and monitor vulnerability scanning, incident response, and remediation of physical and ... Research and integrate cybersecurity tools, techniques, and technologies to strengthen enterprise ...

Request and monitor vulnerability scanning, incident response, and remediation of physical and ... Research and integrate cybersecurity tools, techniques, and technologies to strengthen enterprise ...

Responds to Qualys vulnerability scans and collaborates with security teams to mitigate risks ... Research, plan, and implement software service rollouts to users. • Manage users, groups, OUs ...

Request and monitor vulnerability scanning, incident response, and remediation of physical and ... Research and integrate cybersecurity tools, techniques, and technologies to strengthen enterprise ...

Request and monitor vulnerability scanning, incident response, and remediation of physical and ... Research and integrate cybersecurity tools, techniques, and technologies to strengthen enterprise ...

Request and monitor vulnerability scanning, incident response, and remediation of physical and ... Research and integrate cybersecurity tools, techniques, and technologies to strengthen enterprise ...

ISSO

Tampa, FL · On-site

Primarily, the Senior ISSO provides cybersecurity assessment support, STIG and ACAS vulnerability ... The Contractor shall provide cost/benefit analysis proposals for Government review for any ...

Showing results 21-40

Vulnerability Researcher Contractor information

What does a vulnerability researcher contractor do?

A Vulnerability Researcher Contractor is an information security professional who specializes in identifying, analyzing, and documenting security vulnerabilities in software, systems, or networks. They are often hired on a temporary or project basis to assess the security posture of an organization or specific products. Their responsibilities may include conducting penetration tests, reverse engineering software, developing proof-of-concept exploits, and providing recommendations for mitigating discovered vulnerabilities. Contractors in this role typically work independently or as part of a security team and may present their findings to stakeholders or assist in developing security patches.

What are the key skills and qualifications needed to thrive as a vulnerability researcher contractor?

To thrive as a Vulnerability Researcher Contractor, you need a deep understanding of computer systems, networking, programming languages (such as C/C++, Python), and a strong background in cybersecurity, often supported by relevant degrees or certifications like OSCP or CEH. Familiarity with vulnerability assessment tools (e.g., IDA Pro, Burp Suite, Metasploit), reverse engineering platforms, and bug tracking systems is typically required. Analytical thinking, attention to detail, and effective written communication are vital soft skills in this role. These skills ensure the accurate identification, documentation, and mitigation of security vulnerabilities, which are crucial for protecting organizational assets.

What are the typical collaboration dynamics for a vulnerability researcher contractor within cybersecurity teams?

As a Vulnerability Researcher Contractor, you’ll often work closely with internal security teams, developers, and sometimes external clients to identify, analyze, and document security flaws. Despite being a contractor, you’ll participate in regular team meetings, share findings, and sometimes assist in developing proof-of-concept exploits or remediation guidance. The role requires strong communication skills, as you’ll need to clearly explain technical vulnerabilities to both technical and non-technical stakeholders. Contract positions may also require rapid onboarding and adaptability to different workflows, making flexibility and proactive communication essential.

What is the difference between Vulnerability Researcher Contractor vs Penetration Tester?

AspectVulnerability Researcher ContractorPenetration Tester
CredentialsCertifications like OSCP, CEH, CISSP often preferredSimilar certifications, often including OSCP, CEH, GPEN
Work EnvironmentResearch-focused, analyzing vulnerabilities in systems and softwarePractical testing, simulating attacks to identify security gaps
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesSecurity firms, internal security teams, consulting roles
Search & Comparison IntentUnderstanding research vs active testing rolesDistinguishing between research and hands-on attack simulation

While both roles involve cybersecurity expertise, Vulnerability Researcher Contractors focus on discovering and analyzing vulnerabilities through research, whereas Penetration Testers actively simulate attacks to evaluate security defenses. Both roles often require similar certifications and work in related environments, but their core activities differ: research versus practical testing.

What are popular job titles related to Vulnerability Researcher Contractor jobs in Florida?

For Vulnerability Researcher Contractor jobs in Florida, the most frequently searched job titles are:

What job categories do people searching Vulnerability Researcher Contractor jobs in Florida look for?

The top searched job categories for Vulnerability Researcher Contractor jobs in Florida are:

What cities in Florida are hiring for Vulnerability Researcher Contractor jobs?

Cities in Florida with the most Vulnerability Researcher Contractor job openings:

Infographic showing various Vulnerability Researcher Contractor job openings in Florida as of June 2026, with employment types broken down into 6% Locum Tenens, 80% Full Time, 11% Part Time, and 3% Contract. Highlights an 91% Physical, 1% Hybrid, and 8% Remote job distribution.

Cybersecurity Specialist

Pensacola, FL • On-site

SAIC
IT Services • 10K+ employees

Full-time

Re-posted 6 days ago


SAIC rating

7.7

Company rating: 7.7 out of 10

Based on 82 frontline employees who took The Breakroom Quiz


Job description

Job Description
Description
SAIC is hiring a Cybersecurity Specialist located in Pensacola, FL. This position will be supporting Training & Education Management Systems for Naval Education and Training Command (NETC). The role will support our Programs of Record; Corporate Enterprise Training Activity Resource Systems (CeTARS) for both schoolhouse & corporate, Navy & Joint MyEducation (MyED), Naval Education and Training Future Officer and Citizenship User System (NETFOCUS), Navy Inspector General Hotline Tracking System (NIGHTS), Navy Enlisted Advancement System (NEAS), Authoring Instructional Materials (AIM), and Learning Assessment System (LAS). As a Cybersecurity Specialist, you'll be responsible for maintaining systems' Authority to Operate by ensuring compliance and security posture, coordinating secure access for all systems and subsystems, and integrating robust security measures into the DevSecOps software development lifecycle to safeguard organizational assets.
The Cybersecurity Specialist will require:
  • Maintaining All Systems Authority to Operate (ATO)
    • Request and monitor vulnerability scanning, incident response, and remediation of physical and cybersecurity systems using COTS/GOTS and custom tools.
    • Manage Continuous Monitoring Risk Scoring (CMRS) for classified and unclassified systems, ensuring compliance with DoW risk management, reporting tools (e.g., DCS, COAMS, CMRS, PPSM Registry, and eMASS), and DoD CIO/CISO portals (NIPR/SIPR).
    • Prepare comprehensive technical reports summarizing security assessments, mitigation activities, and remedial actions while supporting audits, scorecards, FISMA, and CSWF reporting.
    • Research and integrate cybersecurity tools, techniques, and technologies to strengthen enterprise security architecture and support ongoing military cyberspace operations.
  • Coordinating All System and Subsystem Accesses
    • Collaborate with external customers, multidisciplinary teams, and vendors (e.g., Armis partnership for architecture implementation and issue resolution).
    • Lead incident investigations, coordinate with system owners to restore systems to secure baselines, and liaise with contracted vendors for incident control and resolution.
    • Monitor and analyze systems for abnormal events using COTS/GOTS tools, threat intelligence, and forensic applications to identify potential security incidents or malicious activities.
    • Actively participate in policy alignment initiatives, pre-CISO meetings, CCMD Cyber Scorecard Syncs, and other stakeholder engagements to ensure consistent compliance and operational effectiveness.
  • Supporting the Security Portion of the DevSecOps Software Development Model
    • Research, evaluate, and recommend new security tools, techniques, and technologies to align enterprise security architecture with DevSecOps objectives.
    • Implement application and data migration strategies that prioritize simplicity, security compliance, scalability, and alignment with short- and long-term operational needs.
    • Assist in selecting, deploying, and managing software, and cloud service providers, including assessing and authoring SLAs with vendors to align with security standards.
    • Support cyber metrics development, reporting, and maintenance for managed tools, ensuring accuracy and alignment with enterprise DevSecOps models and security controls.

Qualifications
Required Experience, Certification, and Education: (IAW DoD 8140 for the 631 work role)
  • Bachelor's Degree in Software Engineering, Information Technology, Cybersecurity, Data Science, Information Systems, Computer Science, or any of the 40+ other accepted degrees identified at cyber.mil that are from an ABET accredited or NCAE-C designated institution.
- or-
  • SecurityX/CASP+, CCSP, Cloud+, CSC, GCLD, GCSA, GSEC, CISSP-ISSEP, or GFITSP-D
Required Skills:
  • Maintaining All Systems Authority to Operate (ATO)
    • Leverage expertise in cloud security architecture and enterprise security tools (e.g., firewalls, IDS/IPS, SIEMs) to secure IT infrastructures through vulnerability scanning, incident response, and modernization efforts.
    • Develop and maintain highly technical cybersecurity documentation (e.g., assessment reports, solution designs) while adhering to NIST, NICE Framework, and other industry standards.
  • Coordinating All System and Subsystem Accesses
    • Balance multiple projects and collaborate with stakeholders to provide technical solutions for complex cybersecurity challenges in government and enterprise environments.
    • Independently analyze and implement solutions to ensure effective risk management, compliance with cybersecurity frameworks, and alignment with organizational goals.
  • Supporting the Security Portion of the DevSecOps Software Development Model
    • Design, evaluate, and integrate modern cybersecurity technologies and cloud-based solutions into DevSecOps processes to ensure secure application development and deployment.
    • Implement risk-informed approaches, combining thorough risk management practices with actionable methods to address factors affecting security posture.
Preferred Qualifications (Nice-to-Have):
  • Strong understanding of Cloud, DevOps, and Digital Workplace technologies, including cloud security principles, deployment, and management in dynamic environments.
  • Industry-recognized certifications such as Security+, CEH (Certified Ethical Hacker), GCIH (GIAC Certified Incident Handler), BTL2 (Blue Team Leader Level 2), CASP (CompTIA Advanced Security Practitioner), or GSEC (GIAC Security Essentials Certification).
  • ITIL v4 certification (Foundation or above) to demonstrate knowledge of IT service management best practices.
  • Experience in contributing to the successful completion of specific government or enterprise cybersecurity programs and projects, including addressing technical challenges.
  • Proficiency with advanced toolsets, including Armis (201 or higher certifications), SIEM platforms (e.g., Splunk, QRadar), and cloud-based security tools.
  • Familiarity with standard frameworks and guidelines, such as NIST 800-53, ISO/IEC 27001, and NICE Cybersecurity Workforce Framework (NICE Framework), and their application in real-world scenarios.
  • Strong communication skills with the ability to present cybersecurity strategies and incident findings to technical and non-technical stakeholders concisely and clearly.
  • Advanced defensive cybersecurity skills in areas such as threat intelligence utilization, incident investigation, forensic analysis, and vulnerability management.
  • Practical experience with DevSecOps tools and workflows, including CI/CD pipelines, container security (e.g., Docker or Kubernetes), and secure software development practice.
Clearance Required:
  • Secret Clearance is required.

Overview
SAIC accepts applications on an ongoing basis and there is no deadline.
SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

What SAIC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom