Senior Consultant | Application Security | Vulnerability Management
Expedite Talent Solutions · Boston, MA · 1 wk ago
On-siteOTHRFull-time
Work location: Hybrid – three days per week in the client’s Springfield, Boston, or New York office.
Start date: 25 August 2026 Duration: 1-year contract Rate: *** USD/hour
Responsibilities
- Define proof-of-technology (PoT) scope, success criteria, and test plans for automated mobile vulnerability scanning (agent-based, agentless, MDM-integrated, API-driven).
- Evaluate candidate tools for coverage (OS, app, certificate, profile), detection accuracy, scalability, device impact, privacy controls, and reporting fidelity.
- Execute pilots across representative device populations to validate:
- Vulnerability detection (OS versions, CVEs, patch levels, risky apps).
- Configuration compliance checks (encryption, jailbreak/root, screen lock, OS hardening).
- Integration readiness (Intune, Workspace ONE, Jamf; SIEM; ITSM; CMDB).
- Produce PoT outcomes: findings, risk analysis, cost/benefit, architecture decision record, and go/no-go recommendation.
- Coordinate with InfoSec and Compliance teams to ensure SaaS platform posture aligns with regulatory requirements (NYDFS).
- Build and run mobile vulnerability lifecycle processes: discovery, assessment, prioritization, remediation, validation, reporting.
- Establish severity/risk scoring tuned for mobile (exposure, device role, app risk, compliance impact).
- Coordinate remediation with endpoint engineering, mobility admins, app owners, and operations teams.
- Validate remediation effectiveness using scanner re-runs, policy compliance, and audit evidence.
- Develop, deploy, and continuously improve baseline security configurations for iOS/iPadOS and Android.
- Translate requirements into enforceable policies (password/biometrics, encryption, OS update controls, app controls, certificate/profile constraints, VPN/Wi-Fi security, logging settings).
- Implement compliance monitoring and drift detection; drive automated or semi-automated corrective actions.
- Build automation scripts and APIs to normalize and enrich findings.
- Support change management and communications for new controls impacting device behavior and user experience.
- Provide technical guidance and training to operations teams for ongoing support.
Requirements
- 8–10 years of hands-on experience designing, validating, and operationalizing automated mobile device vulnerability scanning and configuration compliance across enterprise-issued iOS/iPadOS and Android endpoints.
- 8–10 years of overall work experience in cyber security.
Preferred Certifications
- CompTIA Security+, CySA+
- GIAC: GSEC, GMON, or related
- Qualys, Rapid7, Tenable, or equivalent vulnerability platform certifications
- CISSP, CISM, CCSP (Governance / Risk / Architecture)
- ITIL Foundation (for ITSM integration and operations maturity)
Interview Process
Virtual interview – 1 or 2 rounds.