> Markdown version of [/jobs/ext/2553926-vulnerability-scan-analyst](https://www.wearedevelopers.com/jobs/ext/2553926-vulnerability-scan-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Scan Analyst - **Company:** Xtreme Inc - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Open Source Technology, Comptia Pentest+ CE, Software Vulnerability Management, Web Applications, Nessus, Network Server, Qualys, Vulnerability Analysis - **Published:** August 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=52358ba072633d0c ## About the Role * 3+ years of vulnerability management or scan analysis experience. * Proficiency with enterprise vulnerability scanners (Tenable/Nessus, Qualys, Rapid7, or equivalent). * Strong analytical skills for false-positive triage and risk prioritization. Preferred Qualifications * GVMA, CompTIA PenTest+, or Security+ certification. * Experience coordinating scan timing with client IT teams to minimize operational impact. Travel Fully remote; must remain within the continental United States. ## Description Runs and analyzes automated vulnerability scans across servers, workstations, web applications, and general devices, then validates, filters, and prioritizes results into actionable, management-ready findings., * Configure and run vulnerability scanning tools without causing system disruption or service degradation. * Validate scan results, eliminate false positives, and prioritize critical/high/moderate findings. * Produce both filtered curated reports and raw/unfiltered native scan output as required by the RFP. * Document whether tools used are commercial, proprietary, or open source. ## Related Videos - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [tRPC: API schemas are pure overhead](https://www.wearedevelopers.com/videos/796-trpc-api-schemas-are-pure-overhead) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Building Better with Nuxt 3](https://www.wearedevelopers.com/videos/320-building-better-with-nuxt-3) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)