Rapid7 Vulnerability Management Engineer
Position:Rapid7 Vulnerability Management Engineer
Experience:2–4 years
Location:Dubai, UAE – Onsite
Role Summary:
We are looking for a Cybersecurity Engineer with2–4 years of hands-on experience in Vulnerability Management, with strong practical experience inRapid7 InsightVM. The engineer will support the day-to-day operation, administration, monitoring, tuning, and optimization of the Rapid7 vulnerability management environment.
Key Responsibilities:
- Administer, operate, monitor, and maintainRapid7 InsightVMand associated components.
- Configure and manageSecurity Console, Scan Engines, Sites, Scan Templates, Credentials, Asset Groups and Insight Agents. The proposed architecture specifically includes Security Console, distributed Scan Engines, and optional Insight Agents.
- Plan, configure, schedule, and monitor authenticated and unauthenticated vulnerability scans.
- Perform regular vulnerability assessments across servers, network devices, applications, cloud and other IT environments.
- Analyze vulnerabilities, prioritize risks, identify false positives, and support remediation teams.
- Track vulnerabilities through remediation and performrevalidation/rescanningto confirm closure.
- Monitor platform health, scanning performance, coverage, failed scans, authentication failures, and overall operational performance.
- Support integration of Rapid7 withITSM/incident management, SIEM, GRC, Active Directory/LDAP and credential-management solutions.
- Configure automated ticketing/remediation workflows and vulnerability reporting.
- Prepareweekly/monthly vulnerability reports, dashboards, SLA/KPI reports and remediation status reports.
- Participate in platform health checks, troubleshooting, upgrades, tuning and continuous service improvement.
- Coordinate with infrastructure, application, network and security teams to drive vulnerability remediation.
- Maintain operational documentation, SOPs, scan configurations and remediation tracking.
Required Skills & Experience:
- 2–4 years of total cybersecurity / vulnerability management experience.
- Minimum1–2 years of hands-on Rapid7 InsightVM experiencestrongly preferred.
- Practical experience managing vulnerability scanning in medium/large enterprise environments.
- Good understanding ofCVEs, CVSS, vulnerability prioritization, remediation and risk management.
- Knowledge of Windows/Linux, networking, Active Directory and common enterprise infrastructure.
- Experience with authenticated vulnerability scanning and troubleshooting scan/credential issues.
- Understanding of APIs and integration with SIEM/ITSM platforms is an advantage.
- Good reporting, documentation and customer-facing communication skills.
- Ability to workonsite in Dubaiand operate as part of a managed-services team.
Preferred Certifications:
Rapid7 certification/training is highly preferred. Security certifications such asSecurity+, CEH, eJPT or equivalentwould be advantageous but should not be mandatory for a 2–4 year profile.
Important screening requirement:Candidates should havereal hands-on Rapid7 InsightVM administration experience, not only experience consuming vulnerability reports.