Unknown Company

Senior Consultant | Application Security | Vulnerability Management

boston, ma • Posted 1 weeks ago
Hybrid Contract IT & Technology

Description: Job Title: Vulnerability Management and Configuration Assurance (VMCA) Engineer

Work Location & Reporting Address: The resource is required to work from Springfield, MA or Boston, MA or New York, NY office of client three days in a week. (Hybrid)

Vendor Rate: ***

Contract duration: 12 months

Target Start Date: 25 Aug 2026

Does this position require Visa independent candidates only? Yes

Interview mode - In person/Virtual: Virtual

How many rounds of interview: 1 or 2

Job Details:

Mandatory skills: This role is responsible for driving end-to-end ownership of tooling, integrations, and processes that enable comprehensive visibility into vulnerabilities and configuration risks across on-premises, cloud, and hybrid environments.

Minimum years of experience needed in the required skills: 8-10 years

Minimum over all work experience required: 8-10 years

Domain: Cyber Security

Any certification required: NA

Detailed Job Description:

  • The engineer ensures that vulnerability and configuration data is accurate, complete, and actionable, enabling risk-based prioritization and effective remediation across the enterprise.
  • This includes oversight of vulnerability management platforms, troubleshooting tool issues, and collaborating with cross-functional teams to enhance detection, reporting, and response capabilities.
  • In addition, the VMCA Engineer develops and maintains scalable dashboards, metrics, and executive reporting to provide transparency into risk posture, remediation progress, and control effectiveness.
  • The role is instrumental in driving automation, process improvement, and governance alignment, ensuring compliance with regulatory frameworks such as NIST, CIS, ISO, and NY Client.
  • As a senior technical resource, the engineer provides subject matter expertise, mentoring, and strategic guidance, translating complex technical risks into clear, actionable insights for both technical teams and executive leadership.

Technical Skills:

  • Vulnerability Management Platforms: Deep hands-on experience managing and optimizing enterprise tools (e.g., Qualys, Wiz, Nessus, Rapid7), including platform configuration, performance tuning, and data quality management.
  • Tooling Integration & Engineering: Experience designing and implementing integrations between vulnerability platforms and enterprise systems (e.g., ServiceNow CMDB, SecOps, SIEM) to support automated workflows and governance processes.
  • Automation & Scripting: Strong proficiency in automation and orchestration using scripting languages (e.g., Python, PowerShell) to streamline scanning, reporting, and remediation processes.
  • Configuration Assurance & Secure Baselines: Advanced understanding of operating systems, secure configuration baselines, and continuous compliance validation across enterprise infrastructure.
  • Data Analytics & Reporting: Ability to develop and maintain dashboards and metrics that provide insight into vulnerability trends, remediation performance, and risk posture for both technical and executive audiences.
  • Cloud & Infrastructure Security: Experience securing modern environments, including cloud platforms (AWS, Azure, GCP) and hybrid infrastructures, with a focus on vulnerability and configuration risk management.
  • Troubleshooting & Platform Optimization: Strong ability to identify tool defects, perform root cause analysis, and work with vendors to resolve issues and improve platform effectiveness.

Custom Fields:
Name: Intake Call Requested
Value: true
Name: Intake Call Completed
Value: true

#J-18808-Ljbffr

Senior Consultant | Application Security | Vulnerability Management in boston at Unknown Company

This position is listed as contract and hybrid.

Back to Job Search