Talent.com
Vulnerability Management and Configuration Assurance Analyst
Vulnerability Management and Configuration Assurance AnalystMassMutual • Springfield, MA, US
Vulnerability Management and Configuration Assurance Analyst

Vulnerability Management and Configuration Assurance Analyst

MassMutual • Springfield, MA, US
14 hours ago
Job type
  • Full-time
Job description

Job Description

The Opportunity

We are seeking an experienced Vulnerability Management and Configuration Assurance Engineer to join our Vulnerability Management and Configuration Assurance team. The ideal candidate will have a deep understanding of security principles, vulnerability management and secure baseline configuration monitoring and designing, implementing, and optimizing vulnerability assessment solutions for MassMutual. As an advanced-level engineer, you will collaborate with cross-functional teams to ensure the security posture of our organization meets industry standards and regulatory requirements.

The Team

The Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization’s infrastructure, applications, and systems. Our team plays a critical role in maintaining the security posture of the company by proactively managing vulnerabilities that could be exploited by attackers.

VMCA is motivated by a shared sense of responsibility to protect the organization’s assets and reputation by knowing our work directly mitigates security threats and prevents potential breaches, strong collaboration with other security and IT teams, continuous learning, innovation, and problem-solving. The culture of VMCA consists of proactive and preventative mindsets, collaboration, cross-disciplinary communication, accountability, ownership, agility, adaptability, inclusivity, knowledge sharing, and transparency.

The Impact :

Your key responsibilities will consist of the following to ensure digital assets are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.

Vulnerability Management

Lead the design, implementation, and continuous improvement of the enterprise vulnerability management program.

Hands on experience using automated scanning tools (e.g., Qualys, Tenable, Rapid7, Wiz) to identify, assess, report, and track vulnerabilities detected on operating systems, databases, network devices, mobile devices, and cloud services.

Perform advanced vulnerability assessments across on-premises, cloud, containerized, and hybrid environments.

Analyze vulnerability scan results, prioritize findings based on risk, exploitability, and business impact.

Integrate threat intelligence and MITRE ATT&CK mapping to contextualize vulnerabilities and enhance prioritization.

Collaborate with infrastructure and business information security officers (BISO) teams to drive timely remediation and mitigation.

Identify and recommend compensating controls when immediate remediation is not feasible.

Develop and maintain metrics and dashboards to report on vulnerability trends, remediation progress, and risk posture.

Configuration Assurance

Utilize automated compliance tools to assess and validate configuration compliance for operating systems, databases, network devices, and cloud services.

Partner with IT and engineering teams to remediate configuration drift and ensure continuous compliance.

Map configuration assurance controls to regulatory frameworks (e.g., NIST, CIS, ISO 27001, PCI-DSS, HIPAA).

Maintain documentation of configuration standards and exceptions.

Data Analytics & Visualization

Leverage data analytics to identify trends, anomalies, and risk concentrations across vulnerability and configuration data.

Build and maintain dashboards and visualizations using tools such as Tableau, etc.

Present actionable insights to technical and executive stakeholders to support risk-based decision-making.

Tooling & Automation

Develop scripts and automation workflows to streamline scanning, reporting, and remediation tracking.

Integrate vulnerability and configuration data into SIEM, GRC, and ticketing systems.

Governance & Reporting

Provide executive-level reporting and risk analysis to support strategic decision-making.

Participate in internal and external audits, ensuring evidence of vulnerability and configuration assurance controls.

Stay current with emerging threats, vulnerabilities, and security technologies.

The Minimum Qualifications

Bachelor's or master's degree in computer science, Cybersecurity, or related field.

8+ years of experience in vulnerability management, configuration assurance, or related security engineering roles.

Relevant security certifications such as CISSP, CISM, OSCP, GIAC (GSEC, GCIH, GCIA, etc.) from an industry recognized certifier (e.g., SANS / GIAC, CompTIA, ISACA, ISC2, etc.)

The Ideal Qualifications

Hands on experience with vulnerability scanning tools and configuration assessment platforms.

Familiar with advanced vulnerability management techniques such as continuous threat and exposure management and external attack surface management.

Deep understanding of CVSS, MITRE ATT&CK, threat modeling, and risk-based prioritization.

Experience implementing and validating compensating controls in enterprise environments.

Knowledge of cybersecurity concepts and methods including secure configuration management, data protection, security monitoring, incident response, patch management, governance, enterprise security strategies, and architecture.

Deep understanding of security vulnerabilities, exploits, and mitigation techniques.

Strong understanding of risk analysis, vulnerability assessment methodologies, and securing baselines.

Clear understanding of various operating systems (Windows, Unix, etc.,), secure configuration and build images.

Experience with cloud platforms (AWS, Azure, GCP), container security (Docker, Kubernetes), and security frameworks specific to cloud environment.

Familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NIST, ISO, CIS, etc.).

Strong scripting skills (Python, PowerShell, Bash) for automation and data manipulation.

Strong knowledge of networking protocols, firewalls, VPNs, and security measures.

Strong analytical, problem-solving, communication, and technical writing skills.

Excellent communication skills and ability to influence cross-functional teams.

Experience working in large, complex environments.

Ability to manage multiple projects and tasks effectively, with a proactive and detail-oriented approach.

Able to translate complex technical issues into simple, easy to understand concepts.

What to Expect as Part of MassMutual and the Team

Regular meetings with the Vulnerability Management and Configuration Assurance team.

Focused one-on-one meetings with your manager.

Access to mentorship opportunities.

Networking opportunities including access to Asian, Hispanic / Latinx, African American, women, LGBTQIA+, veteran and disability-focused Business Resource Groups.

Access to learning content on Degreed and other informational platforms.

Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits.

MassMutual is an equal employment opportunity employer. We welcome all persons to apply.

If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.

California residents : For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.

Create a job alert for this search

Configuration Management Analyst • Springfield, MA, US

Related jobs
Risk Management Business Systems Analyst - Investment Management Technology

Risk Management Business Systems Analyst - Investment Management Technology

MassMutual • Springfield, MA, US
Full-time
Business Systems Analyst – Investment Management Technology (ETX).Do you want to be part of a team that encourages your growth, supports your ambitions and makes it a priority for you to reac...Show more
Last updated: 14 hours ago • Promoted • New!
Exposure Management NACP Lead Analyst

Exposure Management NACP Lead Analyst

Beazley Group • West Hartford, CT, United States
Full-time
Exposure Management, General Management.Exposure Management Property Risks Lead.Property Underwriting and Claims Operations (UCO), IT. North America Commercial Property (NACP).Analysts for Catastrop...Show more
Last updated: 30+ days ago • Promoted
Operational Risk Associate

Operational Risk Associate

PeoplesBank • Holyoke, MA, United States
Full-time
Welcome to PeoplesBank! We are the largest mutually chartered bank in Western Mass and Northern Connecticut, we are proud to lead the way in green values, sustainable energy financing, and charitab...Show more
Last updated: 6 days ago • Promoted
CT Scan Supervisor - Radiology

CT Scan Supervisor - Radiology

Charlotte Hungerford Hospital • Riverton, CT, United States
Full-time
Charlotte Hungerford Hospital (10115).FT first shift with every 3rd weekend requirement and rotating holidays.New Hires Eligible for Signing Bonus Up To $10,000! •. Every day, more than 40,000 Hartfo...Show more
Last updated: 11 days ago • Promoted
United States Border Patrol Agent

United States Border Patrol Agent

U.S. Customs and Border Protection • West Warren, Massachusetts, United States
Full-time
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show more
Last updated: 30+ days ago • Promoted
Border Patrol Agent - Experienced (GL9 / GS11)

Border Patrol Agent - Experienced (GL9 / GS11)

U.S. Customs and Border Protection • West Warren, Massachusetts, United States
Full-time
Check out these higher-salaried federal law enforcement opportunities with the U.Your current or prior law enforcement experience may qualify you for this career opportunity with the nation's premi...Show more
Last updated: 30+ days ago • Promoted
Identity and Access Management (IAM) Engineer

Identity and Access Management (IAM) Engineer

MassMutual • Springfield, MA, US
Full-time
Full Time Hybrid Onsite in Boston, NYC, or Springfield, MA.The Enterprise Technology Experience organization seeks an experienced and detail-oriented Identity and Access Engineer who can assist wit...Show more
Last updated: 14 hours ago • Promoted • New!
Construction Sales, Roofing and Solar

Construction Sales, Roofing and Solar

Trinity Solar • Chesterfield, MA, US
Full-time
At Trinity Solar, our Direct Sales team pay and benefits packages are tailored for your success!.Potential earnings range from . Attractive performance-based incentives.All sales employees are ...Show more
Last updated: 30+ days ago • Promoted
Loan Compliance Analyst

Loan Compliance Analyst

PeoplesBank • Holyoke, MA, United States
Full-time
Welcome to PeoplesBank! We are the largest mutually chartered bank in Western Mass and Northern Connecticut, we are proud to lead the way in green values, sustainable energy financing, and charitab...Show more
Last updated: 1 day ago • Promoted
Housing Inspector

Housing Inspector

Northampton Housing Authority • Northampton, MA, US
Full-time
The goal of the Housing Choice Voucher (HCV) program (Section 8) is to provide “decent, safe, and sanitary” housing to families. To accomplish this program regulation, the HCV Inspector is responsib...Show more
Last updated: 7 hours ago • Promoted • New!
Remote Opinion Analyst (Hiring Immediately)

Remote Opinion Analyst (Hiring Immediately)

Earn Haus • Amherst Center, Massachusetts, US
Remote
Full-time +1
We are urgently looking for people interested in taking online surveys for Fortune 500 brands.If you are a self-starter, looking for flexible hours throughout the week, this may be for you! Earn up...Show more
Last updated: 30+ days ago • Promoted
Border Patrol Agent

Border Patrol Agent

U.S. Customs and Border Protection • South Coventry, Connecticut, United States
Full-time
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show more
Last updated: 30+ days ago • Promoted
Financial Systems Analyst

Financial Systems Analyst

IT SOLUTIONS CONSULTING • Brimfield, MA, United States
Full-time
IT Solutions lives its values : .If your values align, we want you to be a part of a fast-growing Managed Service Provider specializing in providing high-end technology solutions to small and mid-mar...Show more
Last updated: 2 days ago • Promoted
Technical Specialist I

Technical Specialist I

UMass Amherst • Amherst, MA, United States
Full-time
The flagship of the Commonwealth, the University of Massachusetts Amherst is a nationally ranked public land-grant research university that seeks to expand educational access, fuel innovation and c...Show more
Last updated: 5 days ago • Promoted
Visual Inspector 2nd shift

Visual Inspector 2nd shift

SKF • Winsted, CT, United States
Full-time
SKF, reducing friction since 1907, re-imagining rotation for a better tomorrow!.SKF is an industry-leading manufacturer that has been a cornerstone in industrial life. Wherever there are machines or...Show more
Last updated: 30+ days ago • Promoted
Sr II Security Analyst Vulnerabilities

Sr II Security Analyst Vulnerabilities

NYU Langone Health • Farmington, CT, United States
Full-time
COME LEARN MORE ABOUT RN OPPORTUNITIES AT OUR FOOD TRUCK EVENT.Hiring Full Time Home Health Registered Nurses.We are offering $5,000 Sign-On Bonus for Full Time RNs. AS THE LARGEST HEALTHCARE EMPLOY...Show more
Last updated: 30+ days ago • Promoted
U.S. Border Patrol Agent

U.S. Border Patrol Agent

U.S. Customs and Border Protection • Coventry Lake, Connecticut, United States
Full-time
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show more
Last updated: 30+ days ago • Promoted
Campus Safety Security Member

Campus Safety Security Member

Smith College • Northampton, MA, United States
Full-time +2
If you have any questions about the position or our application process, reach out to us at.Smith College's Campus Safety department is hiring Casual Campus Safety Security Members.These are tempor...Show more
Last updated: 30+ days ago • Promoted