Talent.com
Vulnerability Management and Configuration Assurance Analyst
Vulnerability Management and Configuration Assurance AnalystMassMutual • New York, New York, US
Vulnerability Management and Configuration Assurance Analyst

Vulnerability Management and Configuration Assurance Analyst

MassMutual • New York, New York, US
Hace más de 30 días
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

The Opportunity

We are seeking an experienced Vulnerability Management and Configuration Assurance Engineer to join our Vulnerability Management and Configuration Assurance team. The ideal candidate will have a deep understanding of security principles, vulnerability management and secure baseline configuration monitoring and designing, implementing, and optimizing vulnerability assessment solutions for MassMutual. As an advanced-level engineer, you will collaborate with cross-functional teams to ensure the security posture of our organization meets industry standards and regulatory requirements.

The Team

The Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization’s infrastructure, applications, and systems. Our team plays a critical role in maintaining the security posture of the company by proactively managing vulnerabilities that could be exploited by attackers.

VMCA is motivated by a shared sense of responsibility to protect the organization’s assets and reputation by knowing our work directly mitigates security threats and prevents potential breaches, strong collaboration with other security and IT teams, continuous learning, innovation, and problem-solving. The culture of VMCA consists of proactive and preventative mindsets, collaboration, cross-disciplinary communication, accountability, ownership, agility, adaptability, inclusivity, knowledge sharing, and transparency.

The Impact:

Your key responsibilities will consist of the following to ensure digital assets are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.

Vulnerability Management

  • Lead the design, implementation, and continuous improvement of the enterprise vulnerability management program.

  • Hands on experience using automated scanning tools (e.g., Qualys, Tenable, Rapid7, Wiz) to identify, assess, report, and track vulnerabilities detected on operating systems, databases, network devices, mobile devices, and cloud services.

  • Perform advanced vulnerability assessments across on-premises, cloud, containerized, and hybrid environments.

  • Analyze vulnerability scan results, prioritize findings based on risk, exploitability, and business impact.

  • Integrate threat intelligence and MITRE ATT&CK mapping to contextualize vulnerabilities and enhance prioritization.

  • Collaborate with infrastructure and business information security officers (BISO) teams to drive timely remediation and mitigation.

  • Identify and recommend compensating controls when immediate remediation is not feasible.

  • Develop and maintain metrics and dashboards to report on vulnerability trends, remediation progress, and risk posture.

Configuration Assurance

  • Utilize automated compliance tools to assess and validate configuration compliance for operating systems, databases, network devices, and cloud services.

  • Partner with IT and engineering teams to remediate configuration drift and ensure continuous compliance.

  • Map configuration assurance controls to regulatory frameworks (e.g., NIST, CIS, ISO 27001, PCI-DSS, HIPAA).

  • Maintain documentation of configuration standards and exceptions.

Data Analytics & Visualization

  • Leverage data analytics to identify trends, anomalies, and risk concentrations across vulnerability and configuration data.

  • Build and maintain dashboards and visualizations using tools such as Tableau, etc.

  • Present actionable insights to technical and executive stakeholders to support risk-based decision-making.

Tooling & Automation

  • Develop scripts and automation workflows to streamline scanning, reporting, and remediation tracking.

  • Integrate vulnerability and configuration data into SIEM, GRC, and ticketing systems.

Governance & Reporting

  • Provide executive-level reporting and risk analysis to support strategic decision-making.

  • Participate in internal and external audits, ensuring evidence of vulnerability and configuration assurance controls.

  • Stay current with emerging threats, vulnerabilities, and security technologies.

The Minimum Qualifications

  • Bachelor's or master's degree in computer science, Cybersecurity, or related field.

  • 8+ years of experience in vulnerability management, configuration assurance, or related security engineering roles.

  • Relevant security certifications such as CISSP, CISM, OSCP, GIAC (GSEC, GCIH, GCIA, etc.) from an industry recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2, etc.)

The Ideal Qualifications

  • Hands on experience with vulnerability scanning tools and configuration assessment platforms.

  • Familiar with advanced vulnerability management techniques such as continuous threat and exposure management and external attack surface management.

  • Deep understanding of CVSS, MITRE ATT&CK, threat modeling, and risk-based prioritization.

  • Experience implementing and validating compensating controls in enterprise environments.

  • Knowledge of cybersecurity concepts and methods including secure configuration management, data protection, security monitoring, incident response, patch management, governance, enterprise security strategies, and architecture.

  • Deep understanding of security vulnerabilities, exploits, and mitigation techniques.

  • Strong understanding of risk analysis, vulnerability assessment methodologies, and securing baselines.

  • Clear understanding of various operating systems (Windows, Unix, etc.,), secure configuration and build images.

  • Experience with cloud platforms (AWS, Azure, GCP), container security (Docker, Kubernetes), and security frameworks specific to cloud environment.

  • Familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NIST, ISO, CIS, etc.).

  • Strong scripting skills (Python, PowerShell, Bash) for automation and data manipulation.

  • Strong knowledge of networking protocols, firewalls, VPNs, and security measures.

  • Strong analytical, problem-solving, communication, and technical writing skills.

  • Excellent communication skills and ability to influence cross-functional teams.

  • Experience working in large, complex environments.

  • Ability to manage multiple projects and tasks effectively, with a proactive and detail-oriented approach.

  • Able to translate complex technical issues into simple, easy to understand concepts.

What to Expect as Part of MassMutual and the Team

  • Regular meetings with the Vulnerability Management and Configuration Assurance team.

  • Focused one-on-one meetings with your manager.

  • Access to mentorship opportunities.

  • Networking opportunities including access to Asian, Hispanic/Latinx, African American, women, LGBTQIA+, veteran and disability-focused Business Resource Groups.

  • Access to learning content on Degreed and other informational platforms.

  • Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits.

#LI-SC1

Salary Range:

$137,800-$180,800

At MassMutual, we focus on ensuring fair equitable pay, by providing competitive salaries, along with incentive and bonus opportunities for all employees. Your total compensation package includes either a bonus target or in a sales-focused role a Variable Incentive Compensation component.

Crear una alerta de empleo para esta búsqueda

Vulnerability Management and Configuration Assurance Analyst • New York, New York, US

Ofertas similares
Senior Analyst, 15c3-3 Compliance Customer Protection

Senior Analyst, 15c3-3 Compliance Customer Protection

Royal Bank of Canada • Jersey City, NJ, United States
A tiempo completo
The Senior Analyst, Customer Protection Team is tasked with providing central governance and oversight of projects, change requests, and transactions which impact Possession and Control (SEA Rule 1...Mostrar más
Última actualización: hace 2 días • Oferta promocionada
Compliance Analyst

Compliance Analyst

Greystone • New York, NY, United States
A tiempo completo
Greystone is a private national commercial real estate finance company with an established reputation as a leader in multifamily and healthcare finance, with $13 billion in loan originations in 202...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Axiom UAT Analyst

Axiom UAT Analyst

Vidorra LLC • New York, NY, US
A tiempo completo
Axiom UAT Analyst || New York City, NY (Hybrid - 3 Days On-site) We are seeking a senior Axiom UAT Analyst to perform Functional Component Testing for the second phase of an Axiom Implementation.Th...Mostrar más
Última actualización: hace 2 días • Oferta promocionada
Compliance Analyst

Compliance Analyst

ApTask • New York, NY, United States
A tiempo completo
ApTask is a leading global provider of workforce solutions and talent acquisition services, dedicated to shaping the future of work.As an African American-owned and Veteran-owned company, ApTask of...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
VP, ServiceNow Vulnerability Response Architect

VP, ServiceNow Vulnerability Response Architect

MUFG • Jersey City, NJ, United States
A tiempo completo
A leading financial group in Jersey City seeks a ServiceNow Platform Architect to provide expert-level support for Vulnerability Response and Configuration Compliance.The candidate should have over...Mostrar más
Última actualización: hace 10 días • Oferta promocionada
Senior Analyst, 15c3-3 Compliance Customer Protection

Senior Analyst, 15c3-3 Compliance Customer Protection

RBC Capital Markets, LLC • Jersey City, NJ, United States
A tiempo completo
The Senior Analyst, Customer Protection Team is tasked with providing central governance and oversight of projects, change requests, and transactions which impact Possession and Control (SEA Rule 1...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Compliance Analyst, FIU

Compliance Analyst, FIU

BitGo, Inc. • New York, NY, United States
A tiempo completo
BitGo is the leading infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage.Since our foun...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Workday System Analyst

Workday System Analyst

Stellar Services • New York, NY, United States
A tiempo completo
Salary Depends on Experience: $60,000--$100,000.Job Category: Information Technology.Aims to enhance Workday's security and compliance by analyzing and migrating existing roles, implementing securi...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Senior Analyst, Cybersecurity Governance, Risk and Compliance

Senior Analyst, Cybersecurity Governance, Risk and Compliance

Next Step Systems LTD • New York, NY, United States
A tiempo completo
Senior Analyst, Cybersecurity Governance, Risk and Compliance, New York, NY.The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer the completion of compliance-related clien...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Compliance Analyst (3-6 YOE)

Compliance Analyst (3-6 YOE)

BizTek People, Inc. | APA International Placement Consultants • New York, NY, United States
A tiempo completo
BizTek People is in search of an experienced Compliance Analyst - ISO 20022 for our client in NYC!.We are seeking a detail-oriented professional to support ISO 20022 message testing and documentati...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Swift & vulnerability management sme

Swift & vulnerability management sme

Randstad • Jersey City, NJ, United States
A tiempo completo
This role is responsible for completing and tracking compliance deliverables to ensure applications adhere to applicable policies and standards as well as local laws, rules and regulations (LRR).Ke...Mostrar más
Última actualización: hace 10 días • Oferta promocionada
Lead, Cybersecurity Assurance Testing

Lead, Cybersecurity Assurance Testing

Guardian Life • New York City, NY, United States
A tiempo completo
Lead, Cyber Security Assurance Testing The Lead, Cyber Security Assurance Testing is a working‑lead / "player‑coach role" within Guardian's Cybersecurity Assurance organization.This role includes f...Mostrar más
Última actualización: hace 2 días • Oferta promocionada
Compliance Analyst

Compliance Analyst

Solar Landscape • Asbury Park, NJ, United States
A tiempo parcial
Solar Landscape is the leading commercial rooftop solar developer in the U.Only 4% of commercial rooftops host solar today we're changing that, fast.Commercial rooftop solar is the fastest, smartes...Mostrar más
Última actualización: hace 4 días • Oferta promocionada
Bilingual BSA/AML Compliance Analyst -OFAC

Bilingual BSA/AML Compliance Analyst -OFAC

Experis/Manpower Group • New York, NY, United States
Indefinido
Our client, an international bank, is seeking a Bilingual Jr.BSA/AML Compliance Analyst to join their team.As a Bilingual BSA/AML Compliance Analyst, you will be part of the Compliance Department s...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Cyber Command Vulnerability Management Specialist

Cyber Command Vulnerability Management Specialist

PRIORITY CARES HOME SERVICES • New York, NY, United States
A tiempo completo
Cyber Command Vulnerability Management Specialist.Job Title: Cyber Command Vulnerability Management Specialist.Job Summary: The Cyber Command Threat Management division within OTI is seeking a Vuln...Mostrar más
Última actualización: hace 10 días • Oferta promocionada
Vulnerability Engineer Remote

Vulnerability Engineer Remote

ESRhealthcare and EXEC STAFF RECRUITERS • New Jersey, New Jersey, United States
Teletrabajo
A tiempo completo
Quick Apply
Familiarity with Vulnerability scanning platforms and a good understanding of network fundamentals, firewalls, authentication, and encryption.Understanding of CVEs, CVSS scoring, zero day vulnerabi...Mostrar más
Última actualización: hace 20 días
Insurance Compliance Analyst (Mortgage Loans)

Insurance Compliance Analyst (Mortgage Loans)

Community Preservation Corporation • New York, NY, United States
A tiempo completo
The Community Preservation Corporation (CPC) believes stable and sustainable affordable housing is the foundation of strong communities and we strive to contribute to comprehensive neighborhood rev...Mostrar más
Última actualización: hace 3 días • Oferta promocionada
Principal Vulnerability Researcher

Principal Vulnerability Researcher

Zetier • New York, NY, United States
A tiempo completo
Principal Vulnerability Researcher.Zetier is seeking Principal Vulnerability Researchers to analyze and counter malicious software and develop operationally critical cyber capabilities.Candidates w...Mostrar más
Última actualización: hace 24 días • Oferta promocionada