Senior Consultant | Application Security | Vulnerability Management

Expedite Talent Solutions

Boston (MA)

Hybrid

USD 140,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Expedite Talent Solutions seeks a Vulnerability Management and Configuration Assurance (VMCA) Engineer in a hybrid capacity, with work locations including Springfield, MA, Boston, MA, or New York, NY. The role demands 8–10 years of experience in managing vulnerabilities, configurations, and risk across diverse environments.

You will lead tooling, integrations, and automation efforts, build dashboards, and deliver executive-level reports on risk posture and remediation progress.

Qualifications

  • This role requires 8–10 years of experience in vulnerability management and configuration risk across on-prem, cloud, and hybrid environments.
  • Owns end-to-end tooling, integrations, and processes enabling visibility into vulnerabilities and configuration risks.
  • Develops and maintains scalable dashboards and executive reporting to show risk posture and remediation progress.

Responsibilities

  • Ensure data is accurate, complete, and actionable for risk-based prioritization and remediation.
  • Oversee vulnerability management platforms, troubleshoot tool issues, and collaborate with cross-functional teams to improve detection, reporting, and response.
  • Develop and maintain dashboards and metrics for vulnerability trends and remediation performance for technical and executive audiences.
  • Drive automation, process improvements, and governance to align with regulatory frameworks such as NIST, CIS, ISO, and NY Client.
  • Mentor and provide strategic guidance on translating technical risks into actionable insights for leadership.

Skills

Vulnerability management
Automation & scripting
Data analytics
Cross-functional collaboration
Regulatory compliance

Tools

Qualys
Wiz
Nessus
Rapid7
ServiceNow CMDB
SIEM
Python
PowerShell
AWS
Azure
GCP

Job description

Description: Job Title: Vulnerability Management and Configuration Assurance (VMCA) Engineer

Work Location & Reporting Address: The resource is required to work from Springfield, MA or Boston, MA or New York, NY office of client three days in a week. (Hybrid)

Vendor Rate: ***

Contract duration: 12 months

Target Start Date: 25 Aug 2026

Does this position require Visa independent candidates only? Yes

Interview mode - In person/Virtual: Virtual

How many rounds of interview: 1 or 2

Job Details:

Mandatory skills: This role is responsible for driving end-to-end ownership of tooling, integrations, and processes that enable comprehensive visibility into vulnerabilities and configuration risks across on-premises, cloud, and hybrid environments.

Minimum years of experience needed in the required skills: 8-10 years

Minimum over all work experience required: 8-10 years

Domain: Cyber Security

Any certification required: NA

Detailed Job Description:
  • The engineer ensures that vulnerability and configuration data is accurate, complete, and actionable, enabling risk-based prioritization and effective remediation across the enterprise.
  • This includes oversight of vulnerability management platforms, troubleshooting tool issues, and collaborating with cross-functional teams to enhance detection, reporting, and response capabilities.
  • In addition, the VMCA Engineer develops and maintains scalable dashboards, metrics, and executive reporting to provide transparency into risk posture, remediation progress, and control effectiveness.
  • The role is instrumental in driving automation, process improvement, and governance alignment, ensuring compliance with regulatory frameworks such as NIST, CIS, ISO, and NY Client.
  • As a senior technical resource, the engineer provides subject matter expertise, mentoring, and strategic guidance, translating complex technical risks into clear, actionable insights for both technical teams and executive leadership.
Technical Skills:
  • Vulnerability Management Platforms: Deep hands-on experience managing and optimizing enterprise tools (e.g., Qualys, Wiz, Nessus, Rapid7), including platform configuration, performance tuning, and data quality management.
  • Tooling Integration & Engineering: Experience designing and implementing integrations between vulnerability platforms and enterprise systems (e.g., ServiceNow CMDB, SecOps, SIEM) to support automated workflows and governance processes.
  • Automation & Scripting: Strong proficiency in automation and orchestration using scripting languages (e.g., Python, PowerShell) to streamline scanning, reporting, and remediation processes.
  • Configuration Assurance & Secure Baselines: Advanced understanding of operating systems, secure configuration baselines, and continuous compliance validation across enterprise infrastructure.
  • Data Analytics & Reporting: Ability to develop and maintain dashboards and metrics that provide insight into vulnerability trends, remediation performance, and risk posture for both technical and executive audiences.
  • Cloud & Infrastructure Security: Experience securing modern environments, including cloud platforms (AWS, Azure, GCP) and hybrid infrastructures, with a focus on vulnerability and configuration risk management.
  • Troubleshooting & Platform Optimization: Strong ability to identify tool defects, perform root cause analysis, and work with vendors to resolve issues and improve platform effectiveness.

Custom Fields:
Name: Intake Call Requested
Value: true
Name: Intake Call Completed
Value: true

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VMCA Engineer: Vulnerability & Config Risk Leader (Hybrid)
VMCA Engineer: Vulnerability & Config Risk Leader (Hybrid)

Expedite Talent Solutions • Boston (MA)

Hybrid
USD 140,000 - 180,000
Cybersecurity Solution Architect with vulnerability Management
Cybersecurity Solution Architect with vulnerability Management

Capgemini • New York (NY)

Hybrid
USD 140,000 - 180,000
Healthcare
401(k) plan
Paid time off
+2
cybersecurity Analyst with vulnerability management
cybersecurity Analyst with vulnerability management

Themesoft Inc. • Burlington (MA)

On-site
USD 70,000 - 90,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Optimum • Norwalk (CT)

On-site
USD 133,000 - 220,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Fortis Industries, Inc. DBA - LTS, Inc. • Atmore (AL)

On-site
USD 100,000 - 140,000
Vulnerability Response Engineer
Vulnerability Response Engineer

Matlen Silver • Chandler (AZ)

Hybrid
USD 90,000 - 120,000
Vulnerability Management Platform / Data Automation Engineer
Vulnerability Management Platform / Data Automation Engineer

DKKD Staffing • New York (NY)

Hybrid
USD 100,000 - 130,000
All expenses paid for travel, lodging, and per-diem
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Info Security Analyst for Vulnerability Remediation - locals only
Info Security Analyst for Vulnerability Remediation - locals only

Value Innovation Labs • San Antonio (TX)

On-site
USD 90,000 - 120,000
Vulnerability Management Analyst
Vulnerability Management Analyst

Soho Square Solutions • New York (NY)

On-site
USD 90,000 - 130,000