Vulnerability Management and Configuration Assurance Engineer

2 weeks ago


New York NY United States MassMutual Full time
The TeamThe Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization's infrastructure, applications, and systems. Our team plays a critical role in maintaining the security posture of the company by proactively managing vulnerabilities that could be exploited by attackers.The ImpactVMCA is motivated by a shared sense of responsibility to protect the organization's assets and reputation by knowing our work directly mitigates security threats and prevents potential breaches, strong collaboration with other security and IT teams, continuous learning, innovation, and problem-solving. The culture of VMCA consists of proactive and preventative mindsets, collaboration, cross-disciplinary communication, accountability, ownership, agility, adaptability, inclusivity, knowledge sharing, and transparency.Roles & Responsibilities:Key responsibilities will consist of the following to ensure digital assets are resilient against emerging threats, reducing potential financial and reputation damage from security incidents:
  • Collaborate with internal architecture teams to continuously improve the vulnerability management tool(s) architecture and strategies tailored to enterprise needs.
  • Collaborate with internal solution architects to design scalable, efficient solutions that integrate with existing IT and security infrastructures.
  • Oversee the vulnerability management tool(s) and its integrations ensuring minimal impact to end-users, data accuracy and completeness, and visibility.
  • Design, implement, and optimize the enterprise vulnerability management tool.
  • Continuously evaluate current and potential toolset, ensuring we are meeting requirements, identifying gaps, and planning for resolutions.
  • Develop and maintain security metrics and reporting dashboards to track tool effectiveness.
  • Provide expert guidance and mentorship to junior members of the team.
  • Ensure compliance with relevant regulations and security frameworks (e.g., NIST, ISO 27001, NY DFS, etc.)
  • Identify issues and/or defects with tools, perform troubleshooting, and engage with vendors as needed for resolution.
  • Focus on continuous process improvement and identify opportunities for automation.
  • Develop and manage standard operating procedures for maintaining the operation of the vulnerability management tool(s) and integrations.
  • Work in a dynamic cross-function environment, partnering with technology and security teams to align practices and tools.The Minimum Qualifications
    • Bachelor's degree
    • Minimum of 5+ years of expertise in cybersecurity with a focus on vulnerability and configuration management tools or similar disciplines.The Ideal Qualifications
      • Advanced degree in engineering, computer science, information security, or a related field.
      • Relevant security certifications such as CISSP, CEH, CVA, Security+, OSCP, etc., from an industry recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2, etc.)Strong knowledge of vulnerability scanning tools (Qualys, Nessus, Rapid7, etc.).
      • Experience with using vulnerability remediation workflow automation tools (e.g., ServiceNow CMDB and SecOps module).
      • Knowledge of cybersecurity concepts and methods including, but not limited to secure configuration management, data protection, security monitoring, incident response, patch management, governance, enterprise security strategies and architecture.
      • Deep understanding of security vulnerabilities, exploits, and mitigation techniques.
      • Strong understanding of risk analysis, vulnerability assessment methodologies, and securing baselines.
      • Clear understanding of various operating systems (Windows, Unix, etc.,), secure configuration and build images.
      • Experience with cloud platforms (AWS, Azure, GCP) and security frameworks specific to cloud environment.
      • Familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NIST, ISO, CIS, etc.,).
      • Experience with automation, scripting, and orchestration (Python, PowerShell, etc.)
      • Strong knowledge of networking protocols, firewalls, VPNs, and security measures.
      • Strong analytical, problem-solving, communication, and technical writing skills.
      • Experience working with in large, complex environments.
      • Ability to manage multiple projects and tasks effectively, with a proactive and detail-oriented approach.
      • Able to translate complex technical issues into simple, easy to understand concepts.What to Expect as Part of MassMutual and the Team
        • Regular meetings with the Vulnerability Management and Configuration Assurance team.
        • Focused one-on-one meetings with your manager.
        • Access to mentorship opportunities.
        • Networking opportunities including access to Asian, Hispanic/Latinx, African American, women, LGBTQIA+, veteran and disability-focused Business Resource Groups.
        • Access to learning content on Degreed and other informational platforms.
        • Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits.#LI-SC1MassMutual is an Equal Employment Opportunity employer Minority/Female/Sexual Orientation/Gender Identity/Individual with Disability/Protected Veteran. We welcome all persons to apply. Note: Veterans are welcome to apply, regardless of their discharge status.

          If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.


  • New York City, NY, United States MassMutual Full time

    The TeamThe Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization’s infrastructure, applications, and systems. Our team plays a critical role in maintaining the security...


  • New York, United States MassMutual Full time

    p>The TeamThe Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization’s infrastructure, applications, and systems. Our team plays a critical role in maintaining the...


  • New York, New York, United States Tech Tammina Full time

    Role: Cyber Security Engineer for Vulnerability ManagementConsolidate ENS and Rapid7 capabilities into the Vulnerability Management program.Ensure Public Safety VM program supports the NG9-1-1 system and manages the primary interface between McAfee Team and Agency Support Groups via weekly Endpoint Committee meetings.Support the ELCS program through...


  • New York, New York, United States CyberTec Full time

    Job DescriptionAt CyberTec, we are seeking a highly skilled Quality Assurance Manager to join our team. As a key member of our Agile Development team, you will be responsible for ensuring the highest quality of our software products.Key Responsibilities:Design, set up, and configure automated testing frameworksIntegrate automated testing tools into the CI/CD...

  • Engineer Analyst

    6 months ago


    New York, United States Assurant Full time

    Engineer Analyst (Linux OS) Vulnerability Management / Analyst Linux Server United Kingdom (Virtual) Who are we? Assurant, Inc. is a global leader in business services for the connected world. Our lifestyle and housing solutions help leading brands grow revenue, manage risk and provide a great experience for their customers. We support, connect...

  • Configuration Manager

    4 weeks ago


    New York, NY, United States TEKsystems Full time

    As Manager of Network Security, you will be responsible for designing, implementing, and maintaining robust network security solutions to protect our organization's digital infrastructure from cyber threats. As such, you will be focused on protecting the organization and will be responsible for enterprise firewall and network security estate including...

  • Mechanical Engineer

    4 weeks ago


    New Bedford, Massachusetts, United States SAIC Full time

    Job Summary:This position assists in preparing all Engineering Change Proposals (ECPs) in accordance with MIL-HDBK-61B and EIA-649. The selected candidate will induct the ECPs into the configuration management software for MCH PMO Change Control Board review/approval and provide all supplemental information requested to aid the MCH PMO in the review of...

  • Configuration Manager

    4 weeks ago


    New York, New York, United States TechFlow Full time

    Job DescriptionJob Title: Configuration ManagerJob Summary: TechFlow, Inc. is seeking an experienced Configuration Manager to support our Platform Services team. The ideal candidate will have a strong understanding of CMMS software and be able to configure and maintain the system to meet organizational needs.Key Responsibilities:Configure the CMMS system to...


  • Alexandria, VA, United States Tyto Athene, LLC Full time

    Tyto Athene is searching for a Senior Vulnerability Management Analyst to assist our law enforcement customer in the development and maintenance of the full lifecycle of vulnerability management services from discovery, triage, advising, remediation, and validation. This is an on-site role with expectations of being on the client site in Alexandria, VA five...


  • Marysville, OH, United States Honda Development and Manufacturing of America Full time

    What Makes a Honda, is Who makes a Honda Honda has a clear vision for the future, and it's a joyful one. -We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record...

  • Cyber Engineer

    2 weeks ago


    Colorado Springs, CO, United States Randstad Digital Americas Full time

    MUST hold a Secret Security Clearance Client job descriptionThe position requires security engineering skills with a working knowledge of Information Assurance (IA) technology, NIST standards, DoDI 8500.2, and Risk Management Framework (RMF) Security Controls. The successful candidate must have experience in the Agile Development Lifecycle to include...

  • Configuration Manager

    2 weeks ago


    Dallas, TX, United States Engtal Full time

    Configuration Manager / Data ManagerDallas, TexasOn-site My client is a propulsion-focused aerospace and defense company based in the Dallas, TX area. We are seeking a highly motivated individual, whose primary responsibilities will center around product life cycle management processes and the configuration management and data management for the company....


  • Marysville, OH, United States Honda Development and Manufacturing of America Full time

    What Makes a Honda, is Who makes a HondaHonda has a clear vision for the future, and it's a joyful one. We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record...


  • Marysville, OH, United States Honda Development and Manufacturing of America Full time

    What Makes a Honda, is Who makes a HondaHonda has a clear vision for the future, and it's a joyful one. We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record...


  • Marysville, OH, United States Honda Development and Manufacturing of America Full time

    What Makes a Honda, is Who makes a HondaHonda has a clear vision for the future, and it’s a joyful one.  We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record...


  • Marysville, OH, United States Honda Development and Manufacturing of America Full time

    What Makes a Honda, is Who makes a HondaHonda has a clear vision for the future, and it’s a joyful one.  We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record...


  • New York, New York, United States Stratford Solutions Inc. Full time

    Job Title: Quality Assurance Engineer with SecDevOps ExpertiseWe are seeking a skilled Quality Assurance Engineer with a strong background in SecDevOps to contribute to the development of secure software products. In this role, you will be responsible for designing and implementing comprehensive test plans, integrating security practices into the testing...


  • Baltimore, MD, United States Middle River Aerostructure Systems Full time

    Position Title: Lead Configuration Management Location: Baltimore, MD, US, 21220 Date: Fri, 25 Oct :04:04 CDT Company Name: STENAHCM20 Description: About Us:ST Engineering MRAS is a world-leading manufacturer of complex aerostructures including nacelle systems and specialized structural components of the airframe. It supplies and supports these products for...

  • Security Engineer

    2 weeks ago


    Dublin, CA, United States Intelliswift Software Full time

    Job Overview:We are looking for a committed Vulnerability Management Specialist to join our team. This role involves conducting regular vulnerability assessments, acting as the technical authority, and leading the efforts in vulnerability scanning and remediation for desktops, servers, and various devices across multiple sites, networks, and standalone...


  • New York, New York, United States MANAGEMENT APPLICATIONS, INC. Full time

    Job Title: Network Engineers for W. Orange NJ EntityManagement Applications, Inc., a leading provider of Managed IT Services and Network Design and Implementation, is seeking Network Engineers for a West Orange, NJ Entity.Job SummaryThe entity has 300+ full-time and up to 200 part-time employees. MAI requires Network Engineers to provide high-quality...