VULNERABILITY MANAGEMENT & CONFIGURATION ASSURANCE (VMCA) ENGINEER
VeriiPro · Boston, NY · Today
EngineeringContract
About the role
We are seeking a Senior Vulnerability Management & Configuration Assurance (VMCA) Engineer to take end-to-end ownership of vulnerability management tooling, integrations, configuration assurance, and security reporting across on-premises, cloud, and hybrid environments.
Responsibilities
- Own and optimize enterprise vulnerability management platforms and ensure accurate, complete, and actionable vulnerability data.
- Manage and troubleshoot tools such as Qualys, Wiz, Nessus, and Rapid7.
- Design and maintain integrations between vulnerability platforms and enterprise systems such as ServiceNow CMDB, SecOps, and SIEM.
- Develop automation and orchestration using Python, PowerShell, or similar scripting technologies.
- Improve vulnerability scanning, reporting, remediation workflows, and data quality through automation.
- Drive configuration assurance and continuous compliance against secure configuration baselines.
- Support vulnerability and configuration risk management across AWS, Azure, GCP, on-premises, and hybrid environments.
- Develop dashboards, KPIs, metrics, and executive-level reporting to communicate security posture and remediation progress.
- Perform troubleshooting, root-cause analysis, platform optimization, and vendor coordination for tool-related issues.
- Establish risk-based prioritization and remediation processes across the enterprise.
- Ensure security processes align with frameworks and regulations such as NIST, CIS, ISO, and NY DFS.
- Provide technical leadership, mentoring, and subject matter expertise to security and infrastructure teams.
- Translate complex technical vulnerabilities and configuration risks into clear, actionable recommendations for technical and executive stakeholders.
Requirements
- 8–10+ years of experience in Cyber Security, Vulnerability Management, Configuration Management, or a related field.
- Strong hands-on experience with Qualys, Wiz, Nessus, and/or Rapid7.
- Experience integrating vulnerability platforms with ServiceNow CMDB, SecOps, SIEM, or similar enterprise platforms.
- Strong scripting and automation skills using Python and/or PowerShell.
- Advanced knowledge of secure configuration baselines and continuous compliance validation.
- Strong understanding of Windows/Linux operating systems and enterprise infrastructure security.
- Experience with AWS, Azure, GCP, and hybrid infrastructure security.
- Strong experience developing security dashboards, metrics, KPIs, and executive reports.
- Excellent troubleshooting, root-cause analysis, and platform optimization skills.
- Knowledge of NIST, CIS, ISO, and NY DFS security and compliance requirements.