402 vulnerability analyst jobs at 267 companies in United States
4d
Save
Mark Applied
Hide
4d
Vulnerability Analyst
Atlanta, Georgia, United States
$107k-$126k/yrOnsiteFull Time
The Coca-Cola CompanyNYSE: KO: Global beverage refreshing the world.
2+ YOERequires 2+ years in vulnerability management, application security, SOC, or related security operations; knowledge of OWASP Top 10, vulnerability validation, severity assessment, tracking platforms, and remediation workflows.
Dragos: Private industrial cybersecurity providing OT/ICS software, threat intelligence, and services to critical-infrastructure operators.
5+ YOERequires 5+ years developing or evaluating vulnerability proof-of-concept code, reverse engineering expertise, networking knowledge, technical writing experience, and proficiency with Python or C# automation.
ARUP Laboratories: National reference laboratory and nonprofit enterprise of University of Utah.
6+ YOEBachelor’s degree in cybersecurity, information technology, or related field; six years of cybersecurity experience, including four years in vulnerability analysis, penetration testing, or cyber risk management.
Covington & Burling LLP: International law firm advising sophisticated clients on complex corporate, litigation, regulatory, and policy matters.
3+ YOE3+ years vulnerability analysis (or 5+ years infosec) with hands-on scanner experience, knowledge of CVEs and risk frameworks, strong analysis and communication skills, and US export-control eligibility.
Quantum Research International: Privately held defense engineering and technology contractor serving U.S. and allied governments, armed forces, and industry customers.
Perform vulnerability assessments, track and remediate findings, analyze vulnerability and STIG data, prioritize remediation, and apply cybersecurity and privacy principles for NGA systems.
Tharros: Private cybersecurity and vulnerability-research contractor serving U.S. federal government and defense agencies.
2+ YOEBachelor's in CS/cybersecurity, 2+ years vulnerability analysis experience, knowledge of vulnerability lifecycle and scoring frameworks, ability to analyze software dependencies, strong communication, proficiency with Microsoft Office/Teams.
CVE, CWE, CVSS, Microsoft Office Suite, Microsoft Teams, AI/LLM
Xtreme Solutions: Woman-owned, service-disabled-veteran-owned IT and cybersecurity contractor serving government and commercial clients.
3+ YOE3+ years vulnerability management/scan analysis experience; proficiency with enterprise scanners; strong analytical skills for false-positive triage and risk prioritization.
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
4+ YOERequires 4+ years in vulnerability analysis, 2+ years administering Windows and UNIX, cloud security experience, vulnerability tools, networking knowledge, and ability to obtain Secret clearance.
Tenable Cloud Security, Tenable Security Center, AWS, Microsoft Azure, Google Cloud Platform, Nessus, Qualys, Splunk, OWASP, TCP, IP, UDP, HTTP, HTTPS, SSH, DNS, Windows, UNIX
ShorePoint: Privately held cybersecurity services firm helping federal civilian, defense, and intelligence agencies protect missions and critical assets.
5+ YOE5+ years experience in vulnerability management, risk assessment, scanning, and security control evaluation; bachelor’s degree required; ability to obtain and maintain U.S. security clearance.
Risk Management Framework (RMF), Authorization to Operate (ATO)
Themis Insight: Private consulting firm providing business, IT, and analytics solutions to National Security clients.
5+ YOERequires TS/SCI with polygraph, relevant degree, and vulnerability analysis, penetration testing, or computer forensics experience. Level 2 or 3 experience and Information Assurance certification may be required.
Hanscom Air Force Base, Massachusetts, United States
OnsiteFull Time
Centuria: Service-disabled veteran-owned government contractor delivering IT, engineering, scientific, cybersecurity, and managed services to federal agencies.
2+ YOERequires DoD Secret clearance, Security+ CE or higher, 2+ years in vulnerability, patch, or systems management, Windows expertise, and PowerShell, Active Directory, Group Policy, and ITSM experience.
ACAS, Nessus, Security Center, ARAD, Tanium, PowerShell, Active Directory, Windows Server, ServiceNow, HBSS, MECM, Microsoft Excel, RMF, STIG, DISA, NIST 800-53, Power BI, ServiceNow Performance Analytics
Arizona or North Carolina or Texas or Virginia or Plano or Raleigh or Reston or Richardson or Tempe
OnsiteFull Time
InfosysNYSE: INFY: Global leader in next-generation digital services and consulting.
Bachelor's degree or equivalent experience; expertise in vulnerability governance, risk assessment, compliance monitoring, reporting, workflow documentation, remediation tracking, and technical writing. US work authorization required.
DigiFlight: Veteran-owned minority U.S. defense contractor providing aviation, aerospace, intelligence, cybersecurity, and IT services.
4+ YOERequires security clearance, a relevant computer science or engineering degree, and 4–10 years of relevant experience in vulnerability analysis, penetration testing, computer forensics, or related cybersecurity fields.
Joint Cyber Analysis Course (JCAC), Undergraduate Cyber Training (UCT), Network Warfare Bridge Course (NWBC), Intermediate Network Warfare Training (INWT)
North American Bancard: Private fintech providing payment processing, POS systems, and merchant services to businesses.
3+ YOEBachelor’s degree or equivalent, 3+ years in cybersecurity, IT, system administration, or risk management, and hands-on Wiz and Tenable experience. Requires vulnerability lifecycle, CVSS, cloud, OS, and networking knowledge.
RYAN Consulting Group: Private IT consulting firm providing cybersecurity, cloud, software, data, and program-management services to government and commercial clients.
5+ YOEActive Secret clearance, 5+ years of related experience, SOC and DoD experience, vulnerability scanning expertise, cyber kill chain knowledge, and DoD IAT II and CSSP Auditor certifications.
SOC, Information Assurance Vulnerability Management (IAVM), Information Security Continuous Monitoring (ISCM), NIST SP 800-40, Microsoft Excel
The Swift Group: Invisible by Design. Impossible to Ignore.
2+ YOEPerform vulnerability assessments and security analysis of systems, networks, hardware and software; recommend mitigations. Requires OS/network knowledge, risk analysis skills, and active TS/SCI with Polygraph and U.S. citizenship.
AnaVation: Private federal IT contractor serving U.S. government agencies with intelligence, cloud, big-data, cybersecurity, and software-engineering services.
4+ YOEU.S. citizenship, TS/SCI clearance, bachelor's degree, DoD 8570 IAT Level II certification, and 4+ years of related experience. Requires ACAS, vulnerability remediation, cybersecurity operations, and communication skills.