1

Vulnerability Specialist Jobs (NOW HIRING)

Partner with Vulnerability Management, Engineering, Infrastructure, Cloud, and ServiceNow teams to enable risk based remediation at scale. Key Responsibilities Security Automation and Engineering ...

Partner with Vulnerability Management, Engineering, Infrastructure, Cloud, and ServiceNow teams to enable risk based remediation at scale. Key Responsibilities Security Automation and Engineering ...

next page

Showing results 1-20

Vulnerability Specialist information

See salary details

$30K

$59.4K

$112.5K

How much do vulnerability specialist jobs pay per year?

As of Sep 14, 2026, the average yearly pay for vulnerability specialist in the United States is $59,408.00, according to ZipRecruiter salary data. Most workers in this role earn between $37,500.00 and $75,000.00 per year, depending on experience, location, and employer.

What is the difference between Vulnerability Specialist vs Penetration Tester?

AspectVulnerability SpecialistPenetration Tester
CertificationsCompTIA Security+, CISSP, CEHOSCP, CEH, GPEN
Work EnvironmentSecurity teams, risk management, vulnerability assessmentsEthical hacking, simulated attacks, security testing
Industry UsageIT security, compliance, risk mitigationSecurity consulting, offensive security, testing firms

Vulnerability Specialists focus on identifying and managing security weaknesses within systems, often working with security teams to prioritize fixes. Penetration Testers actively simulate cyberattacks to find exploitable vulnerabilities. While both roles require similar certifications and work in cybersecurity, Vulnerability Specialists emphasize assessment and mitigation, whereas Penetration Testers focus on offensive security testing.

What is a vulnerability specialist?

A vulnerability specialist is a cybersecurity professional who identifies, assesses, and prioritizes security weaknesses in computer systems, networks, and applications. They use tools like vulnerability scanners and may hold certifications such as CISSP or CEH to perform risk analysis and recommend mitigation strategies.

What cities are hiring for Vulnerability Specialist jobs?

Cities with the most Vulnerability Specialist job openings:

What states have the most Vulnerability Specialist jobs?

States with the most job openings for Vulnerability Specialist jobs include:

What are popular job titles related to Vulnerability Specialist jobs?

For Vulnerability Specialist jobs, the most frequently searched job titles are:

Infographic showing various Vulnerability Specialist job openings in the United States as of September 2026, with employment types broken down into 78% Full Time, 20% Part Time, and 2% Contract. Highlights an 77% Physical, 2% Hybrid, and 21% Remote job distribution, with an average salary of $59,408 per year, or $28.6 per hour.

IT Security Vulnerability Specialist (0036)

Suitland, MD โ€ข On-site

OCT Consulting, LLC
Business Management Consultingย โ€ขย 51 - 200 employees

$110K - $130K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 22 days ago


Job description

Associate / IT Security Vulnerability Specialist (0036)

OCT Consulting is a management and technology consulting firm that supports Federal Government clients. We provide consulting services in the areas of Data Analytics, Change Management, Program and Project Management, Acquisition/Procurement, and Information Technology.

OCT is currently looking for an Associate to join our growing Cybersecurity practice. This position will primarily support a federal client as an IT Security Vulnerability Specialist, which is a hybrid position requiring at least 3 days per week onsite in Suitland, MD. The ideal candidate will be proficient in key areas of security such as: Vulnerability Management, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web filtering, and Advanced Threat Protection.

Responsibilities will include, but are not limited to:

  • Lead and drive remediation efforts within government environment to increase the efficiency of vulnerability management processes.
  • Articulate risk and impact to product, engineering and other business leaders with the ability to convey the urgency and need to remediate a vulnerability commensurate with the risk it presents to the enterprise.
  • Conduct internal vulnerability assessments and vulnerability analysis upon external vulnerability reports, zero-day announcements, security incidents etc.
  • Monitor and maintain vulnerability and code scanning, security configuration and other vulnerability management tools.
  • Develop, maintain, and recommend security policies, procedures, and standards related to vulnerability management.
  • Participate in security audits and assessments to ensure compliance with regulatory requirements and industry standards.
  • Perform vulnerability re-production and fix validation of vulnerabilities where required.
  • Maintain strong knowledge of ongoing security threats, remediations and operational best practices in the threat and vulnerability management.
  • Create reports and dashboards to drive vulnerability remediation efforts and process improvements.
  • Drive regular operational and business reviews for threat and vulnerability management activities.
  • Support other security operation activities as needed (e.g. detection and response).
  • Participate in the Security Incident response.
  • Review, evaluate, refine, release and maintain Configuration Management Plans in support of program requirements.
  • Provide recommendations and guidance for the identification of Configuration Items (CI) and Computer Software Configuration Items (CSCI).
  • Provide guidance and expertise in the establishment, monitoring and maintenance of configuration baselines on assigned programs.
  • Monitor effectiveness and compliance on assigned programs.

Requirements

Requirements:

  • 7+ years of experience with A&A support.
  • Proficient in all steps in the NIST RMF framework
  • Knowledgeable in NIST special publications such as 800-53 & 800-53A
  • Bachelor's degree or equivalent experience
  • In-depth understanding and hands-on experience with multiple vulnerability scanning platforms, to include scanning with Security Technical Information Guides (STIG) and CIS benchmarks.
  • MS Excel proficiency.
  • A related industry certification such as GIAC GEVA, CASP, CAP, CISSP, CISM, GSEC, GMON, Security+.
  • Must be a US Citizen.
  • SECRET clearance required

Benefits

Benefits

 The position includes competitive compensation and a full suite of benefits:

  • Medical, Dental, and Vision insurance
  • Retirement savings 401K plan provided by an industry-leading provider with 3% employer contributions.
  • Paid Time Off
  • Life Insurance, Short- and Long-Term Disability benefits
  • Training Benefits

Salary: $110,000-$130,000 to commensurate with experience, education, etc. 

About OCT Consulting

OCT Consulting LLC is a Small Business (SB) providing professional services and information technology solutions to the Federal government and commercial clients. Founded in 2013, we bring the agility of operations and a management team with a track record of leading successful engagements at major Federal government agencies.
At OCT we believe in creating a work environment where employees can thrive based on their abilities, skills, and achievements. We are dedicated to providing career growth and professional development based on individual merit and fostering a workplace where everyone’s contributions are valued and recognized.