1

Vulnerability Jobs (NOW HIRING)

Vulnerability Management Analyst Job Location - Alpharetta, GA Duration - 11 Months Experience level - 3+ Mandatory Skills - Vulnerability Management Analyst - Vulnerability Management Analyst Key ...

Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and ...

New

Prepare and deliver vulnerability reports, compliance dashboards, and metrics for leadership and inspection readiness (e.g., CCRI/CORA). * Support the development and maintenance of asset groupings ...

Showing results 41-60

Vulnerability information

See salary details

$37.5K

$107.9K

$143K

How much do vulnerability jobs pay per year?

As of Aug 6, 2026, the average yearly pay for vulnerability in the United States is $107,902.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,000.00 and $117,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals working in vulnerability management roles?

Professionals in vulnerability management often face the challenge of keeping up with constantly evolving threats and newly discovered vulnerabilities. Prioritizing which vulnerabilities to address first, especially in large environments with thousands of potential risks, can be demanding. Collaborating with IT, development, and security teams to ensure timely remediation and maintaining clear communication about risk levels are also essential parts of the role. Additionally, balancing the need for quick patching with the risk of disrupting business operations requires careful judgment.

What is the difference between Vulnerability vs Penetration Tester?

AspectVulnerabilityPenetration Tester
Primary FocusIdentifying security weaknesses and vulnerabilities in systemsSimulating cyberattacks to exploit vulnerabilities and test defenses
CertificationsCompTIA Security+, CEH, OSCP (for some roles)OSCP, CEH, GPEN, CISSP (often overlapping)
Work EnvironmentSecurity analysis, vulnerability scanning, reportingActive testing, exploitation, reporting
Industry UsageSecurity assessment, risk managementSecurity testing, red teaming

Vulnerability specialists focus on identifying weaknesses in systems, while penetration testers actively exploit those vulnerabilities to assess security effectiveness. Both roles require similar certifications and work in cybersecurity, but their methods and objectives differ: vulnerability analysts aim to find issues, whereas penetration testers simulate attacks to evaluate defenses.

What are the key skills and qualifications needed to thrive as a vulnerability analyst?

To thrive as a Vulnerability Analyst, you need a solid understanding of network security, operating systems, and vulnerability assessment methodologies, typically supported by a degree in cybersecurity or IT and relevant certifications like CompTIA Security+ or CEH. Familiarity with tools such as Nessus, OpenVAS, Metasploit, and vulnerability management platforms is essential. Strong analytical thinking, attention to detail, and effective communication help in identifying risks and explaining findings to diverse stakeholders. These skills ensure timely detection and remediation of security weaknesses, protecting organizations from cyber threats.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires skills in security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers steady demand and opportunities for advancement. Overall, it is considered a good career for those interested in cybersecurity and protecting digital assets.

What is a vulnerability analyst?

Vulnerability analysts are cybersecurity professionals who identify, assess, and help remediate security weaknesses in computer systems, networks, and software. They use various tools and techniques to scan for vulnerabilities, analyze threats, and recommend solutions to mitigate risks. Their work is crucial in preventing cyberattacks and ensuring the security of organizational assets. Vulnerability analysts often collaborate with IT and security teams to prioritize and address vulnerabilities based on their potential impact.
More about Vulnerability jobs
What cities are hiring for Vulnerability jobs? Cities with the most Vulnerability job openings:
What are the most commonly searched types of Vulnerability jobs? The most popular types of Vulnerability jobs are:
What states have the most Vulnerability jobs? States with the most job openings for Vulnerability jobs include:
Infographic showing various Vulnerability job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 3% Part Time, and 8% Contract. Highlights an 82% Physical, 6% Hybrid, and 12% Remote job distribution, with an average salary of $107,902 per year, or $51.9 per hour.

Manager, Vulnerability Management

Pfizer

Collegeville, PA • Hybrid

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 2 days ago

New


Pfizer rating

8.3

Company rating: 8.3 out of 10

Based on 124 frontline employees who took The Breakroom Quiz

24th of 86 rated pharmaceutical


Job description

ROLE SUMMARY

Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.

The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the enterprise. This role oversees daytoday vulnerability management operations, including scanning, analysis, prioritization, and remediation coordination. The role partners closely with engineering, infrastructure, cloud services, application, and security teams to ensure vulnerabilities are addressed in a timely, riskbased, and compliant manner to reduce overall cyber exposure.


ROLE RESPONSIBILITIES

  • Lead the daytoday execution of the vulnerability management program, ensuring consistent identification, assessment, and prioritization of vulnerabilities across enterprise environments.

  • Manage and develop a team of vulnerability management analysts, providing technical guidance, prioritization, coaching, and performance feedback.

  • Oversee vulnerability scanning activities across infrastructure, endpoints, cloud platforms, and applications, ensuring coverage and data quality.

  • Translate vulnerability findings into clear, actionable remediation guidance for technical owners, aligned to risk, exploitability, and business impact.

  • Coordinate remediation efforts with Infrastructure, Cloud Services, Engineering, Endpoint Security, and other technology teams to drive timely risk reduction.

  • Partner with Threat Intelligence, Threat Remediation, and Incident Response teams to incorporate threat context and active exploitation signals into prioritization decisions.

  • Track remediation progress, validate closure, and identify recurring issues or systemic control gaps requiring escalation or broader corrective action.

  • Ensure vulnerability management activities align with internal policies, regulatory requirements, and audit expectations.

  • Maintain reporting and metrics on vulnerability trends, remediation performance, and risk posture for Cyber Defense leadership.

  • Drive continuous improvement of vulnerability management processes, tooling, and workflows to increase efficiency, accuracy, and impact.

BASIC QUALIFICATIONS

  • Applicant must have a bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field with at least 4 years of experience in cybersecurity, with a strong focus on vulnerability management, security operations, or exposure management; OR a master's degree with at least 2 years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience.

  • Demonstrated responsibility for executing or overseeing vulnerability scanning, assessment, prioritization, and remediation tracking across infrastructure, endpoints, cloud platforms, or applications.

  • Experience translating vulnerability findings into riskbased remediation guidance for infrastructure, cloud, application, or platform engineering teams.

  • Prior responsibility for coordinating remediation activities, including tracking ownership, validating fixes, managing exceptions, and escalating blocked or overdue items.

  • Familiarity with vulnerability severity, exploitability concepts, and compensating controls used to manage risk when immediate remediation is not feasible.

  • Experience leading analysts or serving as a technical lead responsible for task prioritization, quality assurance, and daytoday delivery.

  • Strong analytical, organizational, and problemsolving skills.

  • Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.

PREFERRED QUALIFICATIONS

  • Familiarity with vulnerability management in cloud or hybrid enterprise environments.

  • Understanding of integrating threat context, exploitability, or attack paths into vulnerability prioritization.

  • Exposure to operating in regulated or highly controlled environments such as healthcare, life sciences, or manufacturing.

  • Experience supporting audit, compliance, or regulatory activities related to vulnerability management.

  • Ability to identify trends and drive process or control improvements over time.

  • Relevant professional certifications in cybersecurity or vulnerability management (e.g., CISSP, CISM, Security+, etc.)


PHYSICAL/MENTAL REQUIREMENTS

  • No special physical requirements.

  • Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.

NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS

  • Travel as required by the business (less than 5% domestic and/or international)

  • Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business

  • This role is NOT remote

OTHER JOB DETAILS

  • Last Date to Apply for Job: August 17. 2026

  • Work Location Assignment:Must be able to work from assigned Pfizer office 2-3 days per week, or as needed by the business

The annual base salary for this position ranges from $116,000.00 to $193,400.00. In addition, this position is eligible for participation in Pfizer's Global Performance Plan with a bonus target of 15.0% of the base salary and eligibility to participate in our share based long term incentive program. We offer comprehensive and generous benefits and programs to help our colleagues lead healthy lives and to support each of life's moments. Benefits offered include a 401(k) plan with Pfizer Matching Contributions and an additional Pfizer Retirement Savings Contribution, paid vacation, holiday and personal days, paid caregiver/parental and medical leave, and health benefits to include medical, prescription drug, dental and vision coverage. Learn more at Pfizer Candidate Site - U.S. Benefits | (uscandidates.mypfizerbenefits.com). Pfizer compensation structures and benefit packages are aligned based on the location of hire. The United States salary range provided does not apply to Tampa, FL or any location outside of the United States. This role is posted in multiple locations. If you are applying for the role in an secondary job posting location where pay transparency regulations apply, your Talent Advisor will share the local pay information with you during the first interview.

Relocation assistance may be available based on business needs and/or eligibility.

Candidates must be authorized to be employed in the U.S. by any employer.

U.S. work visa sponsorship (such as TN, O-1, H-1B, etc.) is not available for this role now or in the future.

Sunshine Act

Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care provider's name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative.

EEO & Employment Eligibility

Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status. Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.

Pfizer endeavors to makewww.pfizer.com/careersaccessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please emaildisabilityrecruitment@pfizer.com. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.

To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available onPfizer Careers.

Information & Business Tech

What Pfizer employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Pfizer logo

About Pfizer

Sourced by ZipRecruiter

All over the world, Pfizer colleagues work together to positively impact health for everyone, everywhere. Our colleagues have the opportunity to grow and develop a career that offers both individual and company success; be part of an ownership culture that values diversity and where all colleagues are energized and engaged; and the ability to impact the health and lives of millions of people. Pfizer, a global leader in the biopharmaceutical industry, is continuously seeking top talent who are inspired by our purpose to innovate to bring therapies to patients that significantly improve their lives. Our Health and Science System Specialists Team provides leadership across patient care settings in the complex Hospital, Health System, and Key Medical Group environment to bring value to our customers and patients in this dynamic ecosystem.

Industry

Pharmaceutical and medicine manufacturing

Company size

10,000+ Employees

Headquarters location

New York, NY, US

Year founded

1849