Vulnerability Assessor
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Alexandria, VA · Hybrid
Vulnerability Assessor Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required) Clearance: Active Secret Position Overview ASRC Federal is seeking a Vulnerability ...
Fairfax, VA · On-site
$100K - $130K/yr
Vulnerability Analyst Location: Fairfax, VA (On-site, full-time) Employment Type: Full-time Status: Contingent upon contract award Signal Hill Technologies is seeking a highly skilled Vulnerability ...
Fairfax, VA · On-site
$100K - $130K/yr
Vulnerability Analyst Location: Fairfax, VA (On-site, full-time) Employment Type: Full-time Status: Contingent upon contract award Signal Hill Technologies is seeking a highly skilled Vulnerability ...
Alexandria, VA · On-site
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...
Alexandria, VA · On-site
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...
Reston, VA · On-site
Vulnerability Analyst Top 5 Technical Skills: * Tenable * Qualys * MS Office * Experience with CVE * Experience with Vulnerabilty Management Top 2 Soft Skills: * Great written and verbal ...
Reston, VA · On-site
Vulnerability Analyst Top 5 Technical Skills: * Tenable * Qualys * MS Office * Experience with CVE * Experience with Vulnerabilty Management Top 2 Soft Skills: * Great written and verbal ...
Alexandria, VA · On-site +1
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...
Alexandria, VA · On-site +1
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...
Alexandria, VA · On-site +1
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...
Quick apply
Alexandria, VA · On-site +1
AnaVation is searching for a Vulnerability Manager to assist client leadership with the enterprise vulnerability management program, administering scanning platforms (Tenable and/or Qualys), driving ...
Stafford, VA · Remote
$90K - $118K/yr
As a Vulnerability Analyst, you will conduct continuous vulnerability scanning across hundreds of applications and drive remediation within defined timelines on Amazon Web Services (AWS) GovCloud.
Stafford, VA · Remote
$90K - $118K/yr
As a Vulnerability Analyst, you will conduct continuous vulnerability scanning across hundreds of applications and drive remediation within defined timelines on Amazon Web Services (AWS) GovCloud.
Stafford, VA · On-site +1
$90K - $118K/yr
As a Vulnerability Analyst, you will conduct continuous vulnerability scanning across hundreds of applications and drive remediation within defined timelines on Amazon Web Services (AWS) GovCloud.
Stafford, VA · On-site +1
$90K - $118K/yr
As a Vulnerability Analyst, you will conduct continuous vulnerability scanning across hundreds of applications and drive remediation within defined timelines on Amazon Web Services (AWS) GovCloud.
Chantilly, VA · On-site
$70K - $85K/yr
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...
Quick apply
Chantilly, VA · On-site
$70K - $85K/yr
We are seeking a Vulnerability Management Analyst (Tenable/Nessus & Metrics ) to support vulnerability tracking, remediation coordination, and security metrics reporting in a federal technology ...
They are seeking a highly skilled Mobile Vulnerability Researcher to support advanced mobile-focused research and development efforts across Android platforms, responsible for the full lifecycle of ...
They are seeking a highly skilled Mobile Vulnerability Researcher to support advanced mobile-focused research and development efforts across Android platforms, responsible for the full lifecycle of ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
They are seeking a self-motivated Senior Vulnerability Researcher to solve challenging technical problems in a fast-paced environment supporting national security, applying advanced skills in ...
They are seeking a self-motivated Senior Vulnerability Researcher to solve challenging technical problems in a fast-paced environment supporting national security, applying advanced skills in ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Quick apply
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Our teams lead advanced vulnerability analysis and develop tailored cyber solutions to meet the demands of rapidly evolving mission space. With offices in Northern Virginia, Melbourne, Florida, Tel ...
Reston, VA · On-site
Leverage expertise in reverse engineering, vulnerability research, and software development to address established needs and investigate solutions to emerging requirements * Apply software ...
Reston, VA · On-site
Leverage expertise in reverse engineering, vulnerability research, and software development to address established needs and investigate solutions to emerging requirements * Apply software ...
$86K - $198K/yr
Vulnerability Scanner The Opportunity: As a cyber professional, you know that understanding adversary tactics, techniques, and procedures is vital to producing the intel that enables the success of ...
$86K - $198K/yr
Vulnerability Scanner The Opportunity: As a cyber professional, you know that understanding adversary tactics, techniques, and procedures is vital to producing the intel that enables the success of ...
Herndon, VA · On-site +1
$86K - $198K/yr
Share Vulnerability Scanner The Opportunity: As a cyber professional, you know that understanding adversary tactics, techniques, and procedures is vital to producing the intel that enables the ...
Herndon, VA · On-site +1
$86K - $198K/yr
Share Vulnerability Scanner The Opportunity: As a cyber professional, you know that understanding adversary tactics, techniques, and procedures is vital to producing the intel that enables the ...
Reston, VA · On-site +1
Leverage expertise in reverse engineering, vulnerability research, and software development to address established needs and investigate solutions to emerging requirements * Apply software ...
Reston, VA · On-site +1
Leverage expertise in reverse engineering, vulnerability research, and software development to address established needs and investigate solutions to emerging requirements * Apply software ...
$37.2K - $46.7K
1% of jobs
$46.7K - $56.2K
5% of jobs
$56.2K - $65.7K
3% of jobs
$65.7K - $75.2K
0% of jobs
$75.2K - $84.7K
9% of jobs
$90.2K is the 25th percentile. Wages below this are outliers.
$84.7K - $94.2K
11% of jobs
$94.2K - $103.7K
5% of jobs
$103.7K - $113.2K
1% of jobs
The median wage is $116.2K / yr.
$113.2K - $122.8K
46% of jobs
$122.8K - $132.3K
13% of jobs
$132.3K - $141.8K
5% of jobs
$37.2K
$107K
$141.8K
| Aspect | Vulnerability | Penetration Tester |
|---|---|---|
| Primary Focus | Identifying security weaknesses and vulnerabilities in systems | Simulating cyberattacks to exploit vulnerabilities and test defenses |
| Certifications | CompTIA Security+, CEH, OSCP (for some roles) | OSCP, CEH, GPEN, CISSP (often overlapping) |
| Work Environment | Security analysis, vulnerability scanning, reporting | Active testing, exploitation, reporting |
| Industry Usage | Security assessment, risk management | Security testing, red teaming |
Vulnerability specialists focus on identifying weaknesses in systems, while penetration testers actively exploit those vulnerabilities to assess security effectiveness. Both roles require similar certifications and work in cybersecurity, but their methods and objectives differ: vulnerability analysts aim to find issues, whereas penetration testers simulate attacks to evaluate defenses.

Other
Posted 16 days ago
Location: Alexandria, VA (Hybrid – Telework with periodic on-site support as required)
Clearance: Active Secret
ASRC Federal is seeking a Vulnerability Assessor to support the Department of War Education Activity (DoWEA) Enterprise Cyber Program. The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organization’s cybersecurity posture and ensure compliance with DoD Risk Management Framework (RMF) requirements. This role supports Continuous Monitoring (ConMon) activities and works closely with cybersecurity and system teams to enhance DoWEA’s enterprise-wide security operations.
Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools.
Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs, and DoDI 8510.01 (RMF).
Collaborate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), and system administrators to track remediation and update Plans of Action and Milestones (POA&Ms).
Prepare and maintain vulnerability assessment reports and risk summaries for leadership.
Support RMF Steps 3–6 and Continuous Monitoring documentation within eMASS.
Research and evaluate emerging technologies to identify new or evolving risks and recommend mitigation strategies.
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline (four additional years of equivalent experience may substitute).
Minimum 5+ years of cybersecurity or vulnerability management experience.
Active DoD Secret clearance
DoD 8570.01-M IAT Level II certification (e.g., Security+ CE, CySA+, CCNA-Security).
Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.
Strong analytical, documentation, and communication skills.
Working knowledge of vulnerability scanning, risk assessment methodologies, and remediation tracking.
Familiarity with DoW (DoD) RMF, eMASS, and DISA STIG/SRG compliance.
Understanding of NIST SP 800-53, CNSSI 1253, and DoDI 8510.01 frameworks.
Knowledge of common cybersecurity threats, exploits, and attack vectors.
Experience supporting federal or DoD IT environments.
Positive, proactive approach and ability to collaborate effectively across remote and on-site teams.