1

Vulnerability Jobs in Wisconsin (NOW HIRING)

Partner with IT teams to enhance patching, vulnerability management, and system hardening * Identify, prioritize, and remediate vulnerabilities across a hybrid environment * Monitor systems and ...

This position is not responsible for incident response, vulnerability review, or minimizing the attack surface of the university. A successful individual will have information security expertise as ...

... vulnerability scanning, patch/remediation tracking, and alert tuning to reduce false positives while preserving detection coverage. Identity & Microsoft 365 Security • Help administer Microsoft ...

Review findings from tabletop exercises, vulnerability scans and penetration testing to identify weaknesses or gaps in existing security controls and assist in providing recommendations where ...

Showing results 41-60

Vulnerability information

See Wisconsin salary details

$37.9K

$108.9K

$144.3K

How much do vulnerability jobs pay per year?

As of Aug 6, 2026, the average yearly pay for vulnerability in Wisconsin is $108,911.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,900.00 and $118,600.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals working in vulnerability management roles?

Professionals in vulnerability management often face the challenge of keeping up with constantly evolving threats and newly discovered vulnerabilities. Prioritizing which vulnerabilities to address first, especially in large environments with thousands of potential risks, can be demanding. Collaborating with IT, development, and security teams to ensure timely remediation and maintaining clear communication about risk levels are also essential parts of the role. Additionally, balancing the need for quick patching with the risk of disrupting business operations requires careful judgment.

What is the difference between Vulnerability vs Penetration Tester?

AspectVulnerabilityPenetration Tester
Primary FocusIdentifying security weaknesses and vulnerabilities in systemsSimulating cyberattacks to exploit vulnerabilities and test defenses
CertificationsCompTIA Security+, CEH, OSCP (for some roles)OSCP, CEH, GPEN, CISSP (often overlapping)
Work EnvironmentSecurity analysis, vulnerability scanning, reportingActive testing, exploitation, reporting
Industry UsageSecurity assessment, risk managementSecurity testing, red teaming

Vulnerability specialists focus on identifying weaknesses in systems, while penetration testers actively exploit those vulnerabilities to assess security effectiveness. Both roles require similar certifications and work in cybersecurity, but their methods and objectives differ: vulnerability analysts aim to find issues, whereas penetration testers simulate attacks to evaluate defenses.

What are the key skills and qualifications needed to thrive as a vulnerability analyst?

To thrive as a Vulnerability Analyst, you need a solid understanding of network security, operating systems, and vulnerability assessment methodologies, typically supported by a degree in cybersecurity or IT and relevant certifications like CompTIA Security+ or CEH. Familiarity with tools such as Nessus, OpenVAS, Metasploit, and vulnerability management platforms is essential. Strong analytical thinking, attention to detail, and effective communication help in identifying risks and explaining findings to diverse stakeholders. These skills ensure timely detection and remediation of security weaknesses, protecting organizations from cyber threats.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires skills in security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers steady demand and opportunities for advancement. Overall, it is considered a good career for those interested in cybersecurity and protecting digital assets.

What is a vulnerability analyst?

Vulnerability analysts are cybersecurity professionals who identify, assess, and help remediate security weaknesses in computer systems, networks, and software. They use various tools and techniques to scan for vulnerabilities, analyze threats, and recommend solutions to mitigate risks. Their work is crucial in preventing cyberattacks and ensuring the security of organizational assets. Vulnerability analysts often collaborate with IT and security teams to prioritize and address vulnerabilities based on their potential impact.
What are the most commonly searched types of Vulnerability jobs in Wisconsin? The most popular types of Vulnerability jobs in Wisconsin are:
What are popular job titles related to Vulnerability jobs in Wisconsin? For Vulnerability jobs in Wisconsin, the most frequently searched job titles are:
What job categories do people searching Vulnerability jobs in Wisconsin look for? The top searched job categories for Vulnerability jobs in Wisconsin are:
Infographic showing various Vulnerability job openings in Wisconsin as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $108,911 per year, or $52.4 per hour.

Security Architect - Cloud & DevSecOps

VIVA USA INC

Madison, WI • On-site, Remote

$65.50 - $84.75/hr

Contractor

This job post has expired today. Applications are no longer accepted.


Job description

The client is looking for one (1) Certified Cloud Architect
Purpose and Objective
The client requires an expert senior technical leader and engineer to serve as a strategic advisor to the CISO and drive the statewide implementation of the Accelerated Exposure Reduction Plan.
This role balances high-level strategic advisory with hands on engineering, operating on a "teach-by-doing" knowledge transfer model. The primary objective is to build long-term internal capabilities while operationalizing and enforcing the client's newly updated Flaw Remediation (SI-2) Standard. This initiative transitions the client from reactive, manual vulnerability management to an AI-accelerated, continuous authorization, and automated DevSecOps posture.
Scope
The consultant shall perform hands-on engineering, deliver strategic CISO advisory, and provide direct mentoring across the following core operational pillars:
CISO Strategic Advisory and Engineering
Act as a direct technical advisor to the CISO, translating federal mandates, emerging AI threat models, and architectural gaps into actionable enterprise security directives.
Execute a hands-on knowledge transfer model, co-engineering data pipelines and security automation alongside internal client staff to institutionalize elite technical skills.
Deliver real time training and co-develop automation playbooks within the security operations (SecOps) using live demonstration approach.
Flaw Remediation (SI-2) Standard Operationalization
Tier Optimization & Enforcement: Architect automated tracking, logging, and validation mechanisms to implement compliance with the client's updated SI-2 timeframes:
Tier 1 (Highest Urgency): Ensure all public-facing vulnerabilities, CISA KEV listings, active exploits, and identity/privileged system flaws implement approved mitigations or compensating controls within 24 hours, with full remediation closed inside 7 calendar days.
Tier 2 (High-Risk/Internal): Configure alerting and metric reporting to validate mitigation within 48 hours and full remediation within 15 calendar days.
Tier 3 (Moderate/Low): Establish repeatable monthly scheduling to ensure remediation within 30 calendar days.
Clean Deployment Architectures: Partner with client development teams to pivot away from manual, in-place patching. Author and implement automated templates for clean deployments using virtualized system images, containers, and cloud-native configurations.
DevSecOps Integration: Embed secure builds, automated software testing, code scanning, and dependency updates natively into client deployment pipelines.
AI Capability Deployment & Toolchain Integration
Operationalize Gemini Government and Google Codemender or equivalent directly inside active workflows, showing security analysts and application developers how to leverage generative AI to automate log parsing, threat hunting, and source-code remediation.
Engineer automated data pipelines to feed the centralized enterprise platform (incorporating telemetry from Tenable.io, Google Mandiant ASM, Microsoft Azure Arc, Splunk, and Google SecOps) to maintain a single, authoritative pane of glass.
Ensure all AI-assisted capabilities comply strictly with client privacy, data classification, and logging safeguards, preventing non-public vulnerability metrics from leaking into unvetted environments.
Governance Safeguards & Escalation Automation
Build automated low-code workflows to manage the SI-2 time-bound exception lifecycle, ensuring every granted exception maps back to a named owner, specific compensating controls, and an explicit financial tiedown capturing technical debt.
Configure automated alert thresholds and workflow routing for significant business risks that exceed normal management tolerance, ensuring rapid escalation in line with the SI-2 update.
Minimum Qualifications and Core Competencies
The designated expert must demonstrate a unique blend of strategic advisory presence and deep, practical engineering capability:
Executive Advisory: Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
Teach-by-Doing Expertise: Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
Security Control Mastery (SI-2): Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
Advanced Tooling Fluency: enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
Performance Monitoring & Safeguards
Knowledge Transfer Auditing: Progress will be measured not only by technical deployment velocity but also by the documented proficiency gains of internal client staff who assume ownership of the deployed tools.
Data Isolation Guardrails: The consultant is strictly forbidden from utilizing public or unvetted commercial AI models for analyzing client code, logs, or asset data. All engineering must occur exclusively within authorized, client-managed enterprise security instances.
Top Required Skills & Years of Experience:
Must be able to demonstrate prior experience doing the following in a large/complex environment:
Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
Cloud Architecture & DevSecOps Engineering
Nice to have Skills:
Federated/Government environment
Tech Stack to include: Google, Microsoft, AWS, Splunk
Notes:
This position can work 100% remote with occasional onsite visits 1-2 times required
VIVA is an equal opportunity employer. All qualified applicants have an equal opportunity for placement, and all employees have an equal opportunity to develop on the job. This means that VIVA will not discriminate against any employee or qualified applicant on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.