Vulnerability Management and Configuration Assurance Analyst - New York - Massmutual

    Massmutual
    Massmutual New York

    21 hours ago

    Description

    JOB DESCRIPTION

    Vulnerability Management and Configuration Assurance Analyst Vulnerability Management and Configuration Assurance (VMCA), Enterprise Cyber Security

    Full-Time, Hybrid (Springfield, MA, Boston, MA, New York, NY)

    The Opportunity

    We are seeking an experienced Vulnerability Management and Configuration Assurance Engineer to join our Vulnerability Management and Configuration Assurance team. The ideal candidate will have a deep understanding of security principles, vulnerability management and secure baseline configuration monitoring and designing, implementing, and optimizing vulnerability assessment solutions for MassMutual. As an advanced-level engineer, you will collaborate with cross-functional teams to ensure the security posture of our organization meets industry standards and regulatory requirements.

    The Team

    The Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization's infrastructure, applications, and systems. Our team plays a critical role in maintaining the security posture of the company by proactively managing vulnerabilities that could be exploited by attackers.

    VMCA is motivated by a shared sense of responsibility to protect the organization's assets and reputation by knowing our work directly mitigates security threats and prevents potential breaches, strong collaboration with other security and IT teams, continuous learning, innovation, and problem-solving. The culture of VMCA consists of proactive and preventative mindsets, collaboration, cross-disciplinary communication, accountability, ownership, agility, adaptability, inclusivity, knowledge sharing, and transparency.

    The Impact:

    Your key responsibilities will consist of the following to ensure digital assets are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.

    Vulnerability Management

    • Lead the design, implementation, and continuous improvement of the enterprise vulnerability management program.
    • Hands on experience using automated scanning tools (e.g., Qualys, Tenable, Rapid7, Wiz) to identify, assess, report, and track vulnerabilities detected on operating systems, databases, network devices, mobile devices, and cloud services.
    • Perform advanced vulnerability assessments across on-premises, cloud, containerized, and hybrid environments.
    • Analyze vulnerability scan results, prioritize findings based on risk, exploitability, and business impact.
    • Integrate threat intelligence and MITRE ATT&CK mapping to contextualize vulnerabilities and enhance prioritization.
    • Collaborate with infrastructure and business information security officers (BISO) teams to drive timely remediation and mitigation.
    • Identify and recommend compensating controls when immediate remediation is not feasible.
    • Develop and maintain metrics and dashboards to report on vulnerability trends, remediation progress, and risk posture.

    Configuration Assurance

    • Utilize automated compliance tools to assess and validate configuration compliance for operating systems, databases, network devices, and cloud services.
    • Partner with IT and engineering teams to remediate configuration drift and ensure continuous compliance.
    • Map configuration assurance controls to regulatory frameworks (e.g., NIST, CIS, ISO 27001, PCI-DSS, HIPAA).
    • Maintain documentation of configuration standards and exceptions.

    Data Analytics & Visualization

    • Leverage data analytics to identify trends, anomalies, and risk concentrations across vulnerability and configuration data.
    • Build and maintain dashboards and visualizations using tools such as Tableau, etc.
    • Present actionable insights to technical and executive stakeholders to support risk-based decision-making.

    Tooling & Automation

    • Develop scripts and automation workflows to streamline scanning, reporting, and remediation tracking.
    • Integrate vulnerability and configuration data into SIEM, GRC, and ticketing systems.

    Governance & Reporting

    • Provide executive-level reporting and risk analysis to support strategic decision-making.
    • Participate in internal and external audits, ensuring evidence of vulnerability and configuration assurance controls.
    • Stay current with emerging threats, vulnerabilities, and security technologies.

    The Minimum Qualifications

    • 8+ years of experience in vulnerability management, configuration assurance, or related security engineering roles.
    • Relevant security certifications such as CISSP, CISM, OSCP, GIAC (GSEC, GCIH, GCIA, etc.) from an industry recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2, etc.)

    The Ideal Qualifications

    • Hands on experience with vulnerability scanning tools and configuration assessment platforms.
    • Familiar with advanced vulnerability management techniques such as continuous threat and exposure management and external attack surface management.
    • Deep understanding of CVSS, MITRE ATT&CK, threat modeling, and risk-based prioritization.
    • Experience implementing and validating compensating controls in enterprise environments.
    • Knowledge of cybersecurity concepts and methods including secure configuration management, data protection, security monitoring, incident response, patch management, governance, enterprise security strategies, and architecture.
    • Deep understanding of security vulnerabilities, exploits, and mitigation techniques.
    • Strong understanding of risk analysis, vulnerability assessment methodologies, and securing baselines.
    • Clear understanding of various operating systems (Windows, Unix, etc.,), secure configuration and build images.
    • Experience with cloud platforms (AWS, Azure, GCP), container security (Docker, Kubernetes), and security frameworks specific to cloud environment.
    • Familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NIST, ISO, CIS, etc.).
    • Strong scripting skills (Python, PowerShell, Bash) for automation and data manipulation.
    • Strong knowledge of networking protocols, firewalls, VPNs, and security measures.
    • Strong analytical, problem-solving, communication, and technical writing skills.
    • Excellent communication skills and ability to influence cross-functional teams.
    • Experience working in large, complex environments.
    • Ability to manage multiple projects and tasks effectively, with a proactive and detail-oriented approach.
    • Able to translate complex technical issues into simple, easy to understand concepts.

    #LI-SC1

    MassMutual is an equal employment opportunity employer. We welcome all persons to apply.

    Like the look of this opportunity Make sure to apply fast, as a high volume of applications is expected Scroll down to read the complete job description.

    If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. xhmxlyz

    California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.

  • Work in company Remote job

    Transaction Assurance Analyst

    Only for registered members

    + Initio Sphere is a full-service private capital ecosystem where capital meets talent. · + We serve fund managers, · investors, · operators, · and finance professionals across private markets—combining deal flow, · analyst talent, · investor relations, · nweworking training and ...

    New York, NY

    1 month ago

  • Work in company Remote job

    Deal Assurance Analyst

    Only for registered members

    Initio Sphere is seeking qualified finance professionals to join as Certified Deal Assurance Analysts. · This is not a traditional employment role. Analysts operate as independent contractors and are activated through Initio Sphere's certification and verification process. · ...

    New York, NY

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are looking for a motivated and experienced Quality Assurance (QA) Analyst to join our team As a Quality Assurance (QA) Analyst, you will be responsible for planning, implementation and monitoring of the quality assurance test cases. · Plan, write and execute functional testin ...

    New York $75,000 - $85,000 (USD)

    1 month ago

  • Work in company

    Compliance Assurance Analyst

    Only for registered members

    COMPLIANCE ASSURANCE ANALYST · Current is a leading consumer fintech platform transforming financial access for everyday Americans with over five million members. We provide access to financial solutions that seamlessly work together to solve the needs of our members and enable a ...

    New York $85,000 - $110,000 (USD) Full time

    4 days ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    About us: Breaking Ground operates nearly 4000 units of housing across New York City along with housing in upstate New York and Connecticut. · We believe that everyone deserves a home. We provide supportive housing paired with services designed to help people maintain their homes ...

    New York Full time

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are not a staffing firm or agency. Lensa partners with DirectEmployers to promote this job for Breaking Ground. · ...

    New York

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are seeking a skilled Quality Assurance Analyst to join our team and support testing activities for Kore AI's conversational AI platform. · Define functional and non-functional test strategies for the conversational AI platform. · Collaborate with AI developers and product own ...

    New York

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are looking for a motivated and experienced Quality Assurance (QA) Analyst to join our team As a Quality Assurance (QA) Analyst, you will be responsible for planning, implementation and monitoring of the quality assurance test cases. · ...

    New York Full time

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    Title: Quality Assurance Analyst · Location: Hybrid, New York, New York · About Us · is the industry's leading estate planning platform, empowering more than 1,000 wealth management firms to modernize how they talk about estate planning with their clients. As the only tech-led, e ...

    New York, New York $55,000 - $95,000 (USD) per year

    1 week ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are looking for a motivated and experienced Quality Assurance (QA) Analyst to join our team As a Quality Assurance (QA) Analyst, you will be responsible for planning, implementation and monitoring of the quality assurance test cases.Plan, write and execute functional testing, ...

    New York, NY

    3 weeks ago

  • Work in company

    Compliance Assurance Analyst

    Only for registered members

    · COMPLIANCE ASSURANCE ANALYST · Current is a leading consumer fintech platform transforming financial access for everyday Americans with over five million members. We provide access to financial solutions that seamlessly work together to solve the needs of our members and enabl ...

    New York, NY $85,000 - $110,000 (USD) per year

    2 days ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    The QC Analyst supports the Product Integrity and Quality Assurance function. · 5+ years of apparel product experience within a corporate environment. · Proficiency in BlueCherry ERP preferred; experience with Quonda QC software strongly preferred. · ...

    New York

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    Join a Global Leader in Workforce Solutions Net2Source Inc. who we are Net2Source Inc isnt just another staffing company were a powerhouse of innovation connecting top talent with the right opportunities Recognized for 300 growth in the past three years we operate in 34 countries ...

    New York

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    The QC Analyst supports the Product Integrity and Quality Assurance function, · a primary focus on Costco and Walmart programs.About the Role · The position partners closely with QA/QC leadership, · warehouse teams, and cross-functional stakeholders to support accurate reporting, ...

    New York City Metropolitan Area

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    · Company Description · Warm Greetings · My name is Ganesh and I am a Sr. Technical Recruiter with Tricolor Inc. We are a leading consulting company and have been in consulting business for last 20 years. We are primary vendors to several Fortune 1000, Investment Banks and Fina ...

    New York, NY $55,000 - $95,000 (USD) per year

    1 week ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are looking for talented QA analysts to make our user experience on our platform more delightful and reliable for our millions of users. · Test our chrome extension and web application,executing detailed test plans on a variety of browsers and operating systems · Created detai ...

    New York $40,000 - $80,000 (USD)

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are always looking forward. We continue to innovate, evolve, and invest in ourselves to bring out the best in everyone. · Our extensive learning programs and mentorship opportunities help us create a culture of curiosity that pushes us to always find new solutions and better w ...

    New York Full time

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    Quality Assurance Analyst at St Paul MN Duration – 6 months Contract to Hire Interview Process – Phone Hire · ...

    New York

    1 month ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We are seeking a detail-oriented QA Analyst to support a complex enterprise ecosystem spanning eCommerce, Salesforce platforms, ERP, and cross-system integrations. This role is responsible for ensuring data accuracy, system integrity, and reliable customer experiences across inte ...

    Jersey City $80,000 - $95,000 (USD)

    1 day ago

  • Work in company

    Quality Assurance Analyst

    Only for registered members

    We believe that everyone deserves a home. Breaking Ground operates nearly 4,000 units of housing across New York City, along with housing in upstate New York and Connecticut. · ...

    New York, NY

    1 month ago

  • Work in company Remote job

    Capital Deployment Assurance Analyst

    Only for registered members

    Certified Contractor Roles: Senior · Lead · Analyst · Initio Sphere Private Capital Ecosystem – · ...

    New York, NY

    1 month ago

Jobs
>
New York City