1

Vulnerability Scanner Jobs in California (NOW HIRING)

Senior Security Engineer

Palo Alto, CA · On-site

$180 - $260/hr

Support Vulnerability Management activities, including scanner operations, asset coverage, vulnerability validation, risk prioritization, remediation tracking, exception handling, and reporting.

Prepare and deliver documentation-including monthly vulnerability scan reports, risk mitigation strategies, and policy updates-to government stakeholders to achieve mission milestones. * Process ...

Perform vulnerability scans, penetration testing, and security evaluations. * Collaborate with development and operations teams to integrate security into software development life cycles. Required ...

Vulnerability Scanning * Security Requirements Analysis * Security Awareness Programs * Cyber Metrics Development * Incident Response Cycle Knowledge Soft Skills * Mentoring * Communication * Problem ...

New

The Cyber Defense team manages security controls spanning vulnerability scanning, security patching, penetration testing, application security, cloud security, and lab security across all Intel ...

Showing results 41-60

Vulnerability Scanner information

See California salary details

$9

$15

$22

How much do vulnerability scanner jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for vulnerability scanner in California is $15.95, according to ZipRecruiter salary data. Most workers in this role earn between $13.99 and $17.07 per hour, depending on experience, location, and employer.

What is a vulnerability scanner?

Vulnerability scanners are specialized software tools designed to automatically identify security weaknesses in computer systems, networks, and applications. They work by scanning for known vulnerabilities, misconfigurations, and outdated software that could be exploited by cyber attackers. These tools help organizations proactively find and fix security issues before they can be compromised. Regular use of vulnerability scanners is a key part of maintaining strong cybersecurity defenses.

What are the key skills and qualifications needed to thrive as a vulnerability scanner?

To thrive as a Vulnerability Scanner, you need a solid understanding of cybersecurity principles, network protocols, and operating systems, often supported by relevant certifications like CompTIA Security+ or CEH. Familiarity with vulnerability scanning tools such as Nessus, OpenVAS, and Qualys, as well as knowledge of ticketing systems and reporting platforms, is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for identifying risks and sharing findings with technical and non-technical stakeholders. These skills are crucial to accurately detect vulnerabilities, prioritize threats, and help organizations strengthen their security posture.

How does a vulnerability scanner typically collaborate with IT and security teams during a vulnerability assessment?

Vulnerability Scanners work closely with both IT and security teams to ensure comprehensive assessments of network and application vulnerabilities. They often coordinate with system administrators to schedule scans, minimize disruptions, and gain necessary access. After identifying vulnerabilities, they discuss findings with security analysts to prioritize remediation efforts and provide actionable recommendations. Effective communication and teamwork are essential, as scanners must translate technical results into understandable risks for various stakeholders.

What is the difference between Vulnerability Scanner vs Penetration Tester?

AspectVulnerability ScannerPenetration Tester
CredentialsCertifications like CompTIA Security+, CEH, CISSP often preferredCertifications like OSCP, CEH, GPEN often required
Work EnvironmentPrimarily software-based, automated scanning toolsHands-on testing, manual exploitation, on-site or remote
Industry UsageUsed by security teams for vulnerability assessmentEngaged for in-depth security testing and exploitation

While vulnerability scanners automatically identify security weaknesses, penetration testers perform manual testing to exploit vulnerabilities. Both roles are essential for comprehensive security, but they differ in approach and depth of testing.

Infographic showing various Vulnerability Scanner job openings in California as of August 2026, with employment types broken down into 66% Full Time, 31% Part Time, 2% Contract, and 1% Nights. Highlights an 100% Physical job distribution, with an average salary of $33,168 per year, or $15.9 per hour.

Senior Software Engineer, Application Security

Anduril Industries

Costa Mesa, CA • On-site

$191K - $253K/yr

Full-time

Re-posted 25 days ago


Anduril rating

9.1

Company rating: 9.1 out of 10

Anduril

Based on 17 frontline employees who took The Breakroom Quiz

7.4

Company rating compared to similar companies: 7.4 out of 10

Manufacturers average

Based on 75,610 frontline employees who took The Breakroom Quiz


Job description

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
Team Overview
The Security Applications & Tools (SAT) team within Lattice Platform Security builds custom software systems that detect, manage, and remediate vulnerabilities across Anduril's product ecosystem at scale. We don't just deploy scanners - we design and build distributed scanning infrastructure, policy enforcement engines, and vulnerability management platforms from the ground up. Our stack includes event-driven architectures on AWS, custom Go services, policy-as-code systems, and integrations that span CI pipelines to production environments.
Job Description
We're looking for a senior software engineer to design and build the systems that keep Anduril's software secure. This is a software engineering role first - you'll architect distributed systems, write production Go and Python, build APIs, and operate services at scale. The domain is security, but the work is building real software: custom scanning orchestration pipelines, policy engines that evaluate thousands of configurations against security rules, and data systems that track vulnerabilities across an entire product ecosystem. If you want to write code that solves hard engineering problems in the security space rather than configure off-the-shelf tools, this is the role.
Key Responsibilities
  • Design and build distributed services for vulnerability scanning, policy enforcement, and remediation workflows
  • Develop and extend the team's scanning orchestration platform - an event-driven architecture built on AWS (SQS, Lambda, S3, ECR) that processes scan events at org-wide scale
  • Build and maintain policy-as-code systems that programmatically enforce security policy in CI/CD pipelines and deployment configurations
  • Design APIs and CLIs that integrate security tooling into developer workflows without creating friction
  • Develop data pipelines that aggregate, normalize, and route findings from multiple scanning engines into vulnerability management systems
  • Collaborate with engineering teams across Anduril to understand their security needs and build tooling that addresses them
  • Evaluate third-party security tools and build custom integrations or replacements where needed
  • Participate in on-call rotation for security tooling infrastructure
Required Qualifications
  • 5+ years of experience designing and developing production software systems
  • Strong proficiency in Go - this is the team's primary language for backend services
  • Experience building distributed systems or data pipelines (event-driven architectures, message queues, APIs, worker systems)
  • Proficiency with Python for scripting, automation, and tooling
  • Experience with cloud infrastructure (AWS preferred: Lambda, SQS, S3, ECR, or equivalent)
  • Ability to read and understand security tool output (vulnerability reports, SBOMs, static analysis results) and build systems around it
  • Strong communication skills with the ability to work across teams
  • Eligible to obtain and maintain active U.S. Secret security clearance
Preferred Qualifications
  • Experience with CI/CD systems (CircleCI, GitHub Actions) and building integrations for developer workflows
  • Familiarity with container security concepts, SBOM generation tools (Syft), and vulnerability scanners (Trivy, Grype, Semgrep)
  • Experience with Terraform and infrastructure-as-code
  • Experience with policy-as-code frameworks (OPA/Rego, Conftest)
  • Background in application security or product security engineering
  • Experience with Kubernetes and container orchestration
  • Familiarity with Nix build systems

US Salary Range
$191,000-$253,000 USD
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:
Benefits
At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you're supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.
Protecting Yourself from Recruitment Scams
Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.
To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:
  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.
  • Please always verify communications:
    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to contact@anduril.com.
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links.
  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy
To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.
By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.

Working at Anduril

About Anduril, in their own words

From Anduril

As the world enters an era of strategic competition, Anduril delivers cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the warfighter in months, not years.


What Anduril employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Anduril Industries logo

About Anduril Industries

Sourced by ZipRecruiter

Anduril Industries is a trailblazer in the technology industry based in Costa Mesa, CA, US. Founded in 2017 by Palmer Luckey, the creator of Oculus VR, the company focuses on developing innovative technology to equip and empower those in the defense sector. Its primary products include cutting-edge autonomous systems and AI software that assist in combating threats to national and global security. The mission of Anduril Industries is to integrate technology and defense by building transformative, scalable solutions that ensure a safer world.

Industry

Guided missile and space vehicle manufacturing

Company size

501 - 1,000 Employees

Headquarters location

Costa Mesa, CA, US

Year founded

2017

Social media