Vulnerability Management and Configuration Assurance Analyst
2 weeks ago
The Opportunity We are seeking an experienced Vulnerability Management and Configuration Assurance Engineer to join our Vulnerability Management and Configuration Assurance team. The ideal candidate will have a deep understanding of security principles, vulnerability management and secure baseline configuration monitoring and designing, implementing, and optimizing vulnerability assessment solutions for MassMutual. As an advanced-level engineer, you will collaborate with cross-functional teams to ensure the security posture of our organization meets industry standards and regulatory requirements.The TeamThe Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization’s infrastructure, applications, and systems. Our team plays a critical role in maintaining the security posture of the company by proactively managing vulnerabilities that could be exploited by attackers.VMCA is motivated by a shared sense of responsibility to protect the organization’s assets and reputation by knowing our work directly mitigates security threats and prevents potential breaches, strong collaboration with other security and IT teams, continuous learning, innovation, and problem-solving. The culture of VMCA consists of proactive and preventative mindsets, collaboration, cross-disciplinary communication, accountability, ownership, agility, adaptability, inclusivity, knowledge sharing, and transparency.The Impact:Your key responsibilities will consist of the following to ensure digital assets are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.Vulnerability ManagementLead the design, implementation, and continuous improvement of the enterprise vulnerability management program.Hands on experience using automated scanning tools (e.g., Qualys, Tenable, Rapid7, Wiz) to identify, assess, report, and track vulnerabilities detected on operating systems, databases, network devices, mobile devices, and cloud services.Perform advanced vulnerability assessments across on-premises, cloud, containerized, and hybrid environments.Analyze vulnerability scan results, prioritize findings based on risk, exploitability, and business impact.Integrate threat intelligence and MITRE ATT&CK mapping to contextualize vulnerabilities and enhance prioritization.Collaborate with infrastructure and business information security officers (BISO) teams to drive timely remediation and mitigation.Identify and recommend compensating controls when immediate remediation is not feasible.Develop and maintain metrics and dashboards to report on vulnerability trends, remediation progress, and risk posture.Configuration AssuranceUtilize automated compliance tools to assess and validate configuration compliance for operating systems, databases, network devices, and cloud services.Partner with IT and engineering teams to remediate configuration drift and ensure continuous compliance.Map configuration assurance controls to regulatory frameworks (e.g., NIST, CIS, ISO 27001, PCI-DSS, HIPAA).Maintain documentation of configuration standards and exceptions.Data Analytics & VisualizationLeverage data analytics to identify trends, anomalies, and risk concentrations across vulnerability and configuration data.Build and maintain dashboards and visualizations using tools such as Tableau, etc.Present actionable insights to technical and executive stakeholders to support risk-based decision-making.Tooling & AutomationDevelop scripts and automation workflows to streamline scanning, reporting, and remediation tracking.Integrate vulnerability and configuration data into SIEM, GRC, and ticketing systems.Governance & ReportingProvide executive-level reporting and risk analysis to support strategic decision-making.Participate in internal and external audits, ensuring evidence of vulnerability and configuration assurance controls.Stay current with emerging threats, vulnerabilities, and security technologies.The Minimum QualificationsBachelor's or master's degree in computer science, Cybersecurity, or related field.8+ years of experience in vulnerability management, configuration assurance, or related security engineering roles.Relevant security certifications such as CISSP, CISM, OSCP, GIAC (GSEC, GCIH, GCIA, etc.) from an industry recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2, etc.)The Ideal QualificationsHands on experience with vulnerability scanning tools and configuration assessment platforms.Familiar with advanced vulnerability management techniques such as continuous threat and exposure management and external attack surface management.Deep understanding of CVSS, MITRE ATT&CK, threat modeling, and risk-based prioritization.Experience implementing and validating compensating controls in enterprise environments.Knowledge of cybersecurity concepts and methods including secure configuration management, data protection, security monitoring, incident response, patch management, governance, enterprise security strategies, and architecture.Deep understanding of security vulnerabilities, exploits, and mitigation techniques.Strong understanding of risk analysis, vulnerability assessment methodologies, and securing baselines.Clear understanding of various operating systems (Windows, Unix, etc.,), secure configuration and build images.Experience with cloud platforms (AWS, Azure, GCP), container security (Docker, Kubernetes), and security frameworks specific to cloud environment.Familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NIST, ISO, CIS, etc.).Strong scripting skills (Python, PowerShell, Bash) for automation and data manipulation.Strong knowledge of networking protocols, firewalls, VPNs, and security measures.Strong analytical, problem-solving, communication, and technical writing skills.Excellent communication skills and ability to influence cross-functional teams.Experience working in large, complex environments.Ability to manage multiple projects and tasks effectively, with a proactive and detail-oriented approach.Able to translate complex technical issues into simple, easy to understand concepts.What to Expect as Part of MassMutual and the TeamRegular meetings with the Vulnerability Management and Configuration Assurance team.Focused one-on-one meetings with your manager.Access to mentorship opportunities.Networking opportunities including access to Asian, Hispanic/Latinx, African American, women, LGBTQIA+, veteran and disability-focused Business Resource Groups.Access to learning content on Degreed and other informational platforms.Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits.Salary Range:$134,400.00-$176,400.00At MassMutual, we focus on ensuring fair equitable pay, by providing competitive salaries, along with incentive and bonus opportunities for all employees. Your total compensation package includes either a bonus target or in a sales-focused role a Variable Incentive Compensation component.
-
Vulnerability Management Analyst
6 days ago
New York, New York, United States Jobs via Dice Full timeSoftware Guidance & Assistance, Inc., (SGA), is searching for aVulnerability Management Analystfor aCONTRACT assignmentwith one of our premierFinancial Services clientsin lower Manhattan, NYC. He or she will need to be onsite for 3 days/week (most likely 5 days/week for 1 st few weeks) and be able to work alternating shifts on occasion - 7:00 am-3:30 pm or...
-
Vulnerability Management Analyst
5 days ago
New Bedford, Massachusetts, United States Centuria Full time $60,000 - $120,000 per yearJob Title: Vulnerability Management AnalystLocation: Hanscom AFB, MAClearance: SecretProgram: BLITS 3.0Company/ Program Description: Centuria, a Service-Disabled Veteran-Owned Small Business (SDVOSB), has been delivering IT, Engineering, and Scientific solutions to the Federal Government since 2002. During our two decades of service, we have earned the trust...
-
Engineer Analyst
2 weeks ago
New York, United States Assurant Full timeEngineer Analyst (Windows OS) Vulnerability Management / Analyst Windows Server Vulnerability Engineer United Kingdom (Virtual)The Opportunity:Reporting to the Global Director of Infrastructure and Products, the Analyst Windows Server Vulnerability Engineer, will be responsible for remediation and support of distributed computing systems with reference to...
-
Quality Assurance Manager
2 weeks ago
New York, NY, United States Northern Base Full timeMust Have Skills for the Quality Assurance Manager: #1. 7+ years background in IT (preferably in Quality Assurance, Agile Development, and DevOps) #2. Software Development and Automated Test Script development experience. #3. Experience maintaining Test Environments running on Windows and VMWare #4. Prior experience with both Manual and Automated Test...
-
Quality Assurance Manager
5 days ago
New York, New York, United States Cyfle Full time $126,500 per yearSalary: $ 126,500.00We have partnered with a large non-profit organization in the New York, NY area to provide them with a Quality Assurance Manager. Please review the below description and let us know if you are interested. Must Have Skills for the Quality Assurance Manager:#1. 7+ years background in IT (preferably in Quality Assurance, Agile Development,...
-
New York, United States Natixis Corporate & Investment Banking Full timeNatixis CIB Americas IT is seeking a dynamic and experienced VP, Software Obsolescence and Vulnerability Analyst. This leadership role is critical in ensuring the effective management of software obsolescence and vulnerabilities, including business applications and SaaS solutions. The successful candidate will monitor end-of-life statuses, assess software...
-
Vulnerability Management and Cyber Controls Lead
4 weeks ago
New York, United States Apollo Global Management Full timeVulnerability Management and Cyber Controls Lead Company: Apollo Global Management, Inc. | Location: New York, NY Position Overview At Apollo, were a global team of alternative investment managers passionate about delivering uncommon value to our investors and shareholders. With more than 30 years of proven expertise across Private Equity, Credit, and Real...
-
New York, NY, United States Natixis Corporate & Investment Banking Full timeNatixis CIB Americas IT is seeking a dynamic and experienced VP, Software Obsolescence and Vulnerability Analyst. This leadership role is critical in ensuring the effective management of software obsolescence and vulnerabilities, including business applications and SaaS solutions. The successful candidate will monitor end-of-life statuses, assess software...
-
Vulnerability Management Specialist
4 weeks ago
New York, United States Open Systems Technologies Full timeA financial firm is looking for a Vulnerability Management Specialist in Iselin, NJ or NYC. Compensation: $105-110k Responsibilities: As part of the IT Security team, develop and implement firm IT Strategy in consultation with the IT teams, ensuring that all initiatives are mirrored in respective strategies including the overall firm Strategy Research new...
-
Vulnerability Management Specialist
4 weeks ago
New York, United States Open Systems Technologies Full timeA financial firm is looking for a Vulnerability Management Specialist in Iselin, NJ or NYC. Compensation: $105-110k Responsibilities: As part of the IT Security team, develop and implement firm IT Strategy in consultation with the IT teams, ensuring that all initiatives are mirrored in respective strategies including the overall firm Strategy Research new...