What are the responsibilities and job description for the Vulnerability Management Engineer position at Mindlance?
Position: Vulnerability Management Engineer / Analyst
Location: Springfield, MA (Preferred) or New York, NY
Duration: 06 Months (Contract, with potential extension or conversion)
Work Model: Hybrid – Approximately 3 days onsite per week
Job Description:
We are seeking an experienced Vulnerability Management Engineer / Analyst to strengthen and enhance enterprise vulnerability management and configuration assurance capabilities. In this role, you will be responsible for managing vulnerability assessment platforms, configuring and troubleshooting security scans, supporting remediation efforts, and improving the organization's overall security posture across on-premises, cloud, and hybrid environments.
The ideal candidate will have strong hands-on experience with vulnerability management tools, automation, security reporting, and cross-functional collaboration to ensure vulnerabilities are identified, prioritized, and remediated efficiently.
Key Responsibilities:
- Configure, manage, and optimize enterprise vulnerability scanning platforms, with a strong focus on Qualys.
- Perform vulnerability assessments across on-premises, cloud, and hybrid environments.
- Troubleshoot scan failures, platform issues, and data quality concerns.
- Monitor vulnerability remediation activities and partner with infrastructure, cloud, and application teams to ensure timely remediation.
- Guide remediation teams by providing technical recommendations and risk prioritization.
- Develop dashboards, reports, and security metrics that provide visibility into vulnerability trends and remediation progress.
- Design and implement integrations between vulnerability management platforms and enterprise security tools.
- Automate scanning, reporting, and remediation workflows using scripting and automation technologies.
- Maintain secure configuration baselines and support continuous compliance validation.
- Perform root cause analysis for platform or tooling issues and work with vendors when necessary.
- Improve vulnerability management processes through automation, standardization, and operational enhancements.
- Support compliance initiatives aligned with security frameworks such as NIST, CIS, and ISO.
- Communicate technical risks effectively to both technical teams and leadership.
- Provide technical guidance and mentorship on vulnerability management best practices.
Required Qualifications:
- Strong hands-on experience with Qualys.
- Experience managing enterprise vulnerability management programs.
- Deep understanding of vulnerability scanning, configuration, and remediation.
- Experience troubleshooting vulnerability scanning platforms.
- Knowledge of vulnerability prioritization and security remediation processes.
- Experience with security reporting, dashboards, and metrics.
- Familiarity with secure configuration baselines and continuous compliance validation.
- Excellent analytical, troubleshooting, and problem-solving skills.
- Strong communication and collaboration abilities.
Preferred Qualifications:
- Experience with additional vulnerability management platforms such as Wiz, Nessus, or Rapid7.
- Experience integrating security platforms with ServiceNow CMDB, SecOps, SIEM, or similar enterprise systems.
- Proficiency in Python and/or PowerShell for automation.
- Experience securing cloud environments including AWS, Azure, and GCP.
- Knowledge of hybrid infrastructure security.
- Experience with dashboard development and executive reporting.
- Familiarity with regulatory and security frameworks including NIST, CIS, and ISO.
- Experience driving process improvement, automation, and operational excellence.
- Ability to mentor junior team members and provide technical leadership.
Technical Skills:
Required:
- Qualys
- Vulnerability Management
- Vulnerability Scanning
- Scan Configuration
- Security Remediation
- Troubleshooting
- Configuration Assurance
- Risk Prioritization
Preferred:
- Wiz
- Nessus
- Rapid7
- ServiceNow CMDB
- SecOps
- SIEM
- Python
- PowerShell
- AWS
- Azure
- GCP
- Hybrid Infrastructure Security
- Dashboard & Metrics Development
- Root Cause Analysis
- Secure Configuration Baselines
- Continuous Compliance Validation
- Process Automation
- NIST
- CIS
- ISO
Ideal Candidate:
The ideal candidate is a security professional with strong expertise in vulnerability management platforms, enterprise security operations, and automation. They are comfortable working across infrastructure, cloud, and application teams, can troubleshoot complex security issues, drive remediation efforts, and improve operational processes through automation and best practices. They possess excellent communication skills and can effectively translate technical security risks into actionable insights for both technical and business stakeholders.
Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.
Salary : $60 - $65