Vulnerability Assessor
Alexandria, VA ยท Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA ยท Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA ยท Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA ยท Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA ยท Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Mclean, VA ยท On-site
$131K/yr
Mobile Vulnerability Researcher DESCRIPTION: We are seeking a highly skilled and motivated Vulnerability Researcher with a strong focus on the Apple iPhone or Google Android ecosystem. The ideal ...
Mclean, VA ยท On-site
$131K/yr
Mobile Vulnerability Researcher DESCRIPTION: We are seeking a highly skilled and motivated Vulnerability Researcher with a strong focus on the Apple iPhone or Google Android ecosystem. The ideal ...
Mclean, VA ยท On-site
$131K/yr
Mobile Vulnerability Researcher DESCRIPTION: We are seeking a highly skilled and motivated Vulnerability Researcher with a strong focus on the Apple iPhone or Google Android ecosystem. The ideal ...
Mclean, VA ยท On-site
$131K/yr
Mobile Vulnerability Researcher DESCRIPTION: We are seeking a highly skilled and motivated Vulnerability Researcher with a strong focus on the Apple iPhone or Google Android ecosystem. The ideal ...
Chantilly, VA ยท On-site
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Chantilly, VA ยท On-site
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Alexandria, VA ยท On-site
The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organization's cybersecurity posture and ensure compliance with DoD Risk Management Framework ...
Alexandria, VA ยท On-site
The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organization's cybersecurity posture and ensure compliance with DoD Risk Management Framework ...
Mclean, VA ยท On-site +1
$45 - $48/hr
Vulnerability Management Consultant Location: Washington, DC; Virginia; Dallas, TX; or Boston, MA (Remote with occasional onsite requirements and up to 10% travel) Clearance Requirements: None ...
Mclean, VA ยท On-site +1
$45 - $48/hr
Vulnerability Management Consultant Location: Washington, DC; Virginia; Dallas, TX; or Boston, MA (Remote with occasional onsite requirements and up to 10% travel) Clearance Requirements: None ...
Chantilly, VA ยท Hybrid
$70K - $85K/yr
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...
Quick apply
Chantilly, VA ยท Hybrid
$70K - $85K/yr
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...
Herndon, VA ยท On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Herndon, VA ยท On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Herndon, VA ยท On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Herndon, VA ยท On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
$80K - $128K/yr
Execute vulnerability scans (ACAS, Forescout, Nessus, etc.), review results, and validate findings to identify weaknesses across systems, networks, cloud services, and applications. * Confirm ...
$80K - $128K/yr
Execute vulnerability scans (ACAS, Forescout, Nessus, etc.), review results, and validate findings to identify weaknesses across systems, networks, cloud services, and applications. * Confirm ...
Chantilly, VA ยท On-site
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Chantilly, VA ยท On-site
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Quick apply
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Chantilly, VA ยท On-site
The role involves the full lifecycle of vulnerability research, including assessing, analyzing, and deploying capabilities against modern mobile devices and systems, while collaborating with ...
Chantilly, VA ยท On-site
The role involves the full lifecycle of vulnerability research, including assessing, analyzing, and deploying capabilities against modern mobile devices and systems, while collaborating with ...
Everforth ECS is seeking a Junior Vulnerability Management Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent ...
Everforth ECS is seeking a Junior Vulnerability Management Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent ...
$80K - $128K/yr
Execute vulnerability scans (ACAS, Forescout, Nessus, etc.), review results, and validate findings to identify weaknesses across systems, networks, cloud services, and applications. * Confirm ...
$80K - $128K/yr
Execute vulnerability scans (ACAS, Forescout, Nessus, etc.), review results, and validate findings to identify weaknesses across systems, networks, cloud services, and applications. * Confirm ...
Herndon, VA ยท On-site
$80K - $128K/yr
Execute vulnerability scans (ACAS, Forescout, Nessus, etc.), review results, and validate findings to identify weaknesses across systems, networks, cloud services, and applications. * Confirm ...
Herndon, VA ยท On-site
$80K - $128K/yr
Execute vulnerability scans (ACAS, Forescout, Nessus, etc.), review results, and validate findings to identify weaknesses across systems, networks, cloud services, and applications. * Confirm ...
Our fast-growing roster of government customers relies on us to deliver advanced security solutions, and we're seeking a Lead Vulnerability Researcher to help us continue pushing the boundaries. If ...
Our fast-growing roster of government customers relies on us to deliver advanced security solutions, and we're seeking a Lead Vulnerability Researcher to help us continue pushing the boundaries. If ...
$37.2K - $46.7K
1% of jobs
$46.7K - $56.2K
5% of jobs
$56.2K - $65.7K
3% of jobs
$65.7K - $75.2K
0% of jobs
$75.2K - $84.7K
9% of jobs
$90.2K is the 25th percentile. Wages below this are outliers.
$84.7K - $94.2K
11% of jobs
$94.2K - $103.7K
5% of jobs
$103.7K - $113.2K
1% of jobs
The median wage is $116.2K / yr.
$113.2K - $122.8K
46% of jobs
$122.8K - $132.3K
13% of jobs
$132.3K - $141.8K
5% of jobs
$37.2K
$107K
$141.8K
| Aspect | Vulnerability | Penetration Tester |
|---|---|---|
| Primary Focus | Identifying security weaknesses and vulnerabilities in systems | Simulating cyberattacks to exploit vulnerabilities and test defenses |
| Certifications | CompTIA Security+, CEH, OSCP (for some roles) | OSCP, CEH, GPEN, CISSP (often overlapping) |
| Work Environment | Security analysis, vulnerability scanning, reporting | Active testing, exploitation, reporting |
| Industry Usage | Security assessment, risk management | Security testing, red teaming |
Vulnerability specialists focus on identifying weaknesses in systems, while penetration testers actively exploit those vulnerabilities to assess security effectiveness. Both roles require similar certifications and work in cybersecurity, but their methods and objectives differ: vulnerability analysts aim to find issues, whereas penetration testers simulate attacks to evaluate defenses.

Other
Posted 17 days ago
Location: Alexandria, VA (Hybrid โ Telework with periodic on-site support as required)
Clearance: Active Secret
ASRC Federal is seeking a Vulnerability Assessor to support the Department of War Education Activity (DoWEA) Enterprise Cyber Program. The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organizationโs cybersecurity posture and ensure compliance with DoD Risk Management Framework (RMF) requirements. This role supports Continuous Monitoring (ConMon) activities and works closely with cybersecurity and system teams to enhance DoWEAโs enterprise-wide security operations.
Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools.
Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs, and DoDI 8510.01 (RMF).
Collaborate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), and system administrators to track remediation and update Plans of Action and Milestones (POA&Ms).
Prepare and maintain vulnerability assessment reports and risk summaries for leadership.
Support RMF Steps 3โ6 and Continuous Monitoring documentation within eMASS.
Research and evaluate emerging technologies to identify new or evolving risks and recommend mitigation strategies.
Bachelorโs degree in Cybersecurity, Computer Science, Information Technology, or related discipline (four additional years of equivalent experience may substitute).
Minimum 5+ years of cybersecurity or vulnerability management experience.
Active DoD Secret clearance
DoD 8570.01-M IAT Level II certification (e.g., Security+ CE, CySA+, CCNA-Security).
Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.
Strong analytical, documentation, and communication skills.
Working knowledge of vulnerability scanning, risk assessment methodologies, and remediation tracking.
Familiarity with DoW (DoD) RMF, eMASS, and DISA STIG/SRG compliance.
Understanding of NIST SP 800-53, CNSSI 1253, and DoDI 8510.01 frameworks.
Knowledge of common cybersecurity threats, exploits, and attack vectors.
Experience supporting federal or DoD IT environments.
Positive, proactive approach and ability to collaborate effectively across remote and on-site teams.