Talent.com
Vulnerability Management and Configuration Assurance Analyst
Vulnerability Management and Configuration Assurance AnalystMassMutual • Springfield, Massachusetts, US
Vulnerability Management and Configuration Assurance Analyst

Vulnerability Management and Configuration Assurance Analyst

MassMutual • Springfield, Massachusetts, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

The Opportunity

We are seeking an experienced Vulnerability Management and Configuration Assurance Engineer to join our Vulnerability Management and Configuration Assurance team. The ideal candidate will have a deep understanding of security principles, vulnerability management and secure baseline configuration monitoring and designing, implementing, and optimizing vulnerability assessment solutions for MassMutual. As an advanced-level engineer, you will collaborate with cross-functional teams to ensure the security posture of our organization meets industry standards and regulatory requirements.

The Team

The Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization’s infrastructure, applications, and systems. Our team plays a critical role in maintaining the security posture of the company by proactively managing vulnerabilities that could be exploited by attackers.

VMCA is motivated by a shared sense of responsibility to protect the organization’s assets and reputation by knowing our work directly mitigates security threats and prevents potential breaches, strong collaboration with other security and IT teams, continuous learning, innovation, and problem-solving. The culture of VMCA consists of proactive and preventative mindsets, collaboration, cross-disciplinary communication, accountability, ownership, agility, adaptability, inclusivity, knowledge sharing, and transparency.

The Impact :

Your key responsibilities will consist of the following to ensure digital assets are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.

Vulnerability Management

Lead the design, implementation, and continuous improvement of the enterprise vulnerability management program.

Hands on experience using automated scanning tools (e.g., Qualys, Tenable, Rapid7, Wiz) to identify, assess, report, and track vulnerabilities detected on operating systems, databases, network devices, mobile devices, and cloud services.

Perform advanced vulnerability assessments across on-premises, cloud, containerized, and hybrid environments.

Analyze vulnerability scan results, prioritize findings based on risk, exploitability, and business impact.

Integrate threat intelligence and MITRE ATT&CK mapping to contextualize vulnerabilities and enhance prioritization.

Collaborate with infrastructure and business information security officers (BISO) teams to drive timely remediation and mitigation.

Identify and recommend compensating controls when immediate remediation is not feasible.

Develop and maintain metrics and dashboards to report on vulnerability trends, remediation progress, and risk posture.

Configuration Assurance

Utilize automated compliance tools to assess and validate configuration compliance for operating systems, databases, network devices, and cloud services.

Partner with IT and engineering teams to remediate configuration drift and ensure continuous compliance.

Map configuration assurance controls to regulatory frameworks (e.g., NIST, CIS, ISO 27001, PCI-DSS, HIPAA).

Maintain documentation of configuration standards and exceptions.

Data Analytics & Visualization

Leverage data analytics to identify trends, anomalies, and risk concentrations across vulnerability and configuration data.

Build and maintain dashboards and visualizations using tools such as Tableau, etc.

Present actionable insights to technical and executive stakeholders to support risk-based decision-making.

Tooling & Automation

Develop scripts and automation workflows to streamline scanning, reporting, and remediation tracking.

Integrate vulnerability and configuration data into SIEM, GRC, and ticketing systems.

Governance & Reporting

Provide executive-level reporting and risk analysis to support strategic decision-making.

Participate in internal and external audits, ensuring evidence of vulnerability and configuration assurance controls.

Stay current with emerging threats, vulnerabilities, and security technologies.

The Minimum Qualifications

Bachelor's or master's degree in computer science, Cybersecurity, or related field.

8+ years of experience in vulnerability management, configuration assurance, or related security engineering roles.

Relevant security certifications such as CISSP, CISM, OSCP, GIAC (GSEC, GCIH, GCIA, etc.) from an industry recognized certifier (e.g., SANS / GIAC, CompTIA, ISACA, ISC2, etc.)

The Ideal Qualifications

Hands on experience with vulnerability scanning tools and configuration assessment platforms.

Familiar with advanced vulnerability management techniques such as continuous threat and exposure management and external attack surface management.

Deep understanding of CVSS, MITRE ATT&CK, threat modeling, and risk-based prioritization.

Experience implementing and validating compensating controls in enterprise environments.

Knowledge of cybersecurity concepts and methods including secure configuration management, data protection, security monitoring, incident response, patch management, governance, enterprise security strategies, and architecture.

Deep understanding of security vulnerabilities, exploits, and mitigation techniques.

Strong understanding of risk analysis, vulnerability assessment methodologies, and securing baselines.

Clear understanding of various operating systems (Windows, Unix, etc.,), secure configuration and build images.

Experience with cloud platforms (AWS, Azure, GCP), container security (Docker, Kubernetes), and security frameworks specific to cloud environment.

Familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NIST, ISO, CIS, etc.).

Strong scripting skills (Python, PowerShell, Bash) for automation and data manipulation.

Strong knowledge of networking protocols, firewalls, VPNs, and security measures.

Strong analytical, problem-solving, communication, and technical writing skills.

Excellent communication skills and ability to influence cross-functional teams.

Experience working in large, complex environments.

Ability to manage multiple projects and tasks effectively, with a proactive and detail-oriented approach.

Able to translate complex technical issues into simple, easy to understand concepts.

What to Expect as Part of MassMutual and the Team

Regular meetings with the Vulnerability Management and Configuration Assurance team.

Focused one-on-one meetings with your manager.

Access to mentorship opportunities.

Networking opportunities including access to Asian, Hispanic / Latinx, African American, women, LGBTQIA+, veteran and disability-focused Business Resource Groups.

Access to learning content on Degreed and other informational platforms.

Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits.

Salary Range :

$134,400.00-$176,400.00

At MassMutual, we focus on ensuring fair equitable pay, by providing competitive salaries, along with incentive and bonus opportunities for all employees. Your total compensation package includes either a bonus target or in a sales-focused role a Variable Incentive Compensation component.

[job_alerts.create_a_job]

Configuration Analyst • Springfield, Massachusetts, US

[internal_linking.related_jobs]
CAT Risk Analyst

CAT Risk Analyst

Munich RE • Hartford, CT, United States
[job_card.full_time]
Amelia, United States; Atlanta, United States; Austin, United States; Charlotte, United States; Chicago, United States; Dallas, United States. Hartford, United States; Houston, United States; Miami...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Technical Support & Security Analyst

Technical Support & Security Analyst

UMass Amherst • Amherst, MA, United States
[job_card.full_time]
The flagship of the Commonwealth, the University of Massachusetts Amherst is a nationally ranked public land-grant research university that seeks to expand educational access, fuel innovation and c...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Senior Strategic Sourcing Analyst Enterprise Labor Hybrid

Senior Strategic Sourcing Analyst Enterprise Labor Hybrid

Stanley Black & Decker • New Britain, CT, US
[job_card.full_time]
Senior Strategic Sourcing Analyst Enterprise Labor.Onsite Tuesday-Thursday New Britain, CT, United States Come build something that matters. It takes great people to achieve greatness.People with a ...[show_more]
[last_updated.last_updated_30] • [promoted]
Speech Language Pathologist (SLP)

Speech Language Pathologist (SLP)

The Stepping Stones Group • Holyoke, MA, US
[job_card.full_time]
The Stepping Stones Group .YOU to join our dynamic team in.As a full-time, school-based SLP, you'll inspire young minds, build confidence, and help students find their voice-literally!.Wha...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Risk Analyst

Risk Analyst

The Hartford • Hartford, CT, United States
[job_card.full_time]
Risk Analyst - KR08CERisk Manager - KR07AE.We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having ever...[show_more]
[last_updated.last_updated_30] • [promoted]
Exposure Management NACP Lead Analyst

Exposure Management NACP Lead Analyst

Beazley Group • West Hartford, CT, United States
[job_card.full_time]
Exposure Management North America Commercial Property (NACP) Lead Analyst.Exposure Management, General Management.Exposure Management Property Risks Lead. Exposure Management, NACP Underwriters, Pro...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior Analyst, Enterprise Monitoring

Senior Analyst, Enterprise Monitoring

RTX • Hartford, CT, United States
[job_card.full_time]
UT6 : 4 Farm Springs 4 Farm Springs Road, Farmington, CT, 06032 USA.Person, or Immigration Status Requirements : .RTX Corporation is an Aerospace and Defense company that provides advanced systems and...[show_more]
[last_updated.last_updated_30] • [promoted]
Cybersecurity Compliance Analyst

Cybersecurity Compliance Analyst

Dcode Talent LLC • Hartford, Connecticut, USA
[job_card.full_time]
Serve as a Cybersecurity Compliance Analyst supporting a major network redesign project.Assess and enhance the organizations network security posture. Ensure compliance with cybersecurity standards ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Internal Audit, Global Trade Analyst (Remote)

Internal Audit, Global Trade Analyst (Remote)

RTX • Hartford, CT, United States
[filters.remote]
[job_card.full_time]
CT502 : 10 Farm Springs Rd, Farmington 10 Farm Springs Road.Person, or Immigration Status Requirements : .RTX Corporation is an Aerospace and Defense company that provides advanced systems and service...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Remote Investment Analyst – AI Trainer ($50-$60 / hour)

Remote Investment Analyst – AI Trainer ($50-$60 / hour)

Data Annotation • Holyoke, Massachusetts
[filters.remote]
[job_card.full_time] +1
We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of ...[show_more]
[last_updated.last_updated_30] • [promoted]
Tooling Specialist I (UH) - 2nd shift

Tooling Specialist I (UH) - 2nd shift

U.S. Tsubaki Power Transmission, LLC • Holyoke, MA, US
[job_card.full_time]
The TSUBAKI name is synonymous with excellence in quality, dependability, and customer service.Tsubaki is a leading manufacturer and supplier of power transmission and motion control products.As a ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Associate Risk Analyst

Associate Risk Analyst

The Hartford • Hartford, CT, United States
[job_card.full_time]
We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and t...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Nuclear Reliability Integrity Management (RIM) Engineering Consultant

Nuclear Reliability Integrity Management (RIM) Engineering Consultant

SI Solutions • Hartford, Connecticut, USA
[job_card.full_time]
We are seeking a Reliability Integrity Management (RIM) Engineer with a strong focus on inspection and monitoring for advanced and operating nuclear reactor systems. This role will apply technical e...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Compliance Surveillance Analyst

Compliance Surveillance Analyst

AlphaSense • Springfield, MA, US
[job_card.full_time]
Compliance Surveillance Analyst.The world's most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaS...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Quality Assurance Analyst

Quality Assurance Analyst

nLeague • Hartford, Connecticut, USA
[job_card.full_time]
Position : Quality Assurance Analyst.This position will report to the DSS-BITS QM Manager working for the Child Support modernization effort. The role will function as a QM Functional Test Lead unde...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Remote FinTech Product Analyst - AI Trainer ($50-$60 / hour)

Remote FinTech Product Analyst - AI Trainer ($50-$60 / hour)

Data Annotation • Holyoke, Massachusetts
[filters.remote]
[job_card.full_time] +1
We are looking for a finance professional to join our team to train AI models.You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of ...[show_more]
[last_updated.last_updated_30] • [promoted]
Travel Behavioral Health Tech in Holyoke, MA

Travel Behavioral Health Tech in Holyoke, MA

AlliedTravelCareers • Holyoke, MA, US
[job_card.full_time]
AlliedTravelCareers is working with Kiwi Healthcare to find a qualified Behavioral Health Tech in Holyoke, Massachusetts, 01040!. Our client is seeking an experienced Behavioral Health for a Days sh...[show_more]
[last_updated.last_updated_30] • [promoted]
Lead Project Controls, Risk Management (Hybrid)

Lead Project Controls, Risk Management (Hybrid)

Eversource • Hartford, CT, US
[job_card.full_time]
Transmission Project Controls / Risk Team Leadership Role.We have an exciting leadership role in our Transmission Project Controls / Risk Team. Lead and supervise a group of Project Controls Analysts to...[show_more]
[last_updated.last_updated_30] • [promoted]