NEW JOB OPENING
VULNERABILITY MANAGEMENT AND CONFIGURATION ASSURANCE ENGINEER
IN Springfield, MA, USA!

 

Date Posted: 06/04/2026
Hiring Organization: Rose International
Position Number: 502343
Industry: Insurance
Job Title: Vulnerability Management and Configuration Assurance Engineer
Job Location: Springfield, MA, USA, 01111
Work Model: Hybrid
Work Model Details: Hybrid, onsite 3 days a week
Shift: M to F, 9 to 5
Employment Type: Temporary
FT/PT: Full-Time
Estimated Duration (In months): 9
Min Hourly Rate($): 60.00
Max Hourly Rate($): 62.00
Must Have Skills/Attributes: AWS, Azure, Cloud, Engineer, GCP, PowerShell, Python, Security, ServiceNow, SME, Vulnerability
Experience Desired: Enterprise Vulnerability Management platform administration and optimization (Qualys, Rapid, Nessus) (5+ yrs); Security Tool Integration experience with ServiceNow, CMDB, SIEM, SecOps, and enterprise security (4+ yrs); Automation and Scripting experience using Python, PowerShell, or similar technologies (3+ yrs); Cloud Security and Configuration Assurance experience across AWS, Azure, and/or GCP environments (4+ yrs); Vulnerability Remediation, Compliance Management, Dashboard Development, and Executive Reporting (4+ yrs)
Required Minimum Education: Bachelor’s Degree

**C2C is not available**

 

Job Description
Required Education:
• Bachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field

Required Qualifications/Skills/Experience:
• Deep hands-on experience with vulnerability management platforms such as Qualys, Wiz, Nessus, Rapid7, or similar tools
• Experience managing and optimizing enterprise vulnerability management programs
• Experience integrating security platforms with ServiceNow, CMDB, SIEM, SecOps, or related enterprise systems
• Strong automation and scripting experience using Python, PowerShell, or similar technologies
• Experience with configuration assurance and secure baseline validation
• Knowledge of cloud security principles across AWS, Azure, and GCP environments
• Experience developing dashboards, metrics, and security reporting
• Strong troubleshooting, root cause analysis, and problem-solving skills
• Strong communication and stakeholder engagement skills
• Experience supporting governance, compliance, and remediation initiatives

Preferred Qualifications/Skills/Experience:
• Experience supporting hybrid infrastructure environments
• Experience implementing automated vulnerability remediation workflows
• Experience with executive-level reporting and risk communication
• Experience mentoring technical teams and providing subject matter expertise
• Experience supporting regulatory compliance initiatives including NIST, CIS, ISO, and NY DFS frameworks

Vulnerability Management and Configuration Assurance Engineer Overview:
• The Vulnerability Management and Configuration Assurance (VMCA) Engineer is responsible for strengthening enterprise security by designing, implementing, and optimizing vulnerability management and configuration assurance capabilities across complex technology environments
• This role provides end-to-end ownership of the tools, integrations, automation processes, and reporting mechanisms that support enterprise-wide visibility into vulnerabilities and configuration risks
• The VMCA Engineer ensures vulnerability and configuration data remains accurate, actionable, and aligned with organizational security objectives
• The role focuses on improving vulnerability detection, remediation workflows, compliance monitoring, and risk reporting across on-premises, cloud, and hybrid environments
• Working closely with infrastructure, cloud, engineering, architecture, and security teams, the engineer supports the development of scalable security processes that enhance operational efficiency and reduce risk exposure
• This position also drives automation initiatives through scripting and platform integrations, enabling streamlined workflows and improved governance
• The engineer develops and maintains dashboards, metrics, and executive reporting to provide visibility into risk posture, remediation progress, and control effectiveness
• As a senior technical resource, the VMCA Engineer serves as a subject matter expert in vulnerability management and configuration assurance, providing technical guidance, mentoring, and strategic recommendations
• Success in this role requires strong analytical skills, technical expertise, problem-solving abilities, and the capability to translate complex security risks into actionable insights for both technical and executive stakeholders

Job Duties:
• Manage and optimize enterprise vulnerability management platforms
• Configure and maintain vulnerability scanning and reporting capabilities
• Develop integrations between security tools and enterprise platforms
• Automate vulnerability management and remediation processes using scripting technologies
• Monitor and validate secure configuration baselines
• Assess vulnerability and configuration risks across cloud and hybrid environments
• Develop and maintain security dashboards, metrics, and executive reporting
• Analyze vulnerability trends and remediation effectiveness
• Perform troubleshooting, root cause analysis, and platform optimization
• Collaborate with infrastructure, cloud, application, and security teams
• Support governance, compliance, and audit initiatives
• Provide technical guidance and mentorship to stakeholders and team members
• Drive process improvement and operational efficiency initiatives
• Support risk prioritization and remediation decision-making




  • **Only those lawfully authorized to work in the designated country associated with the position will be considered.**

  • **Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.**

 

Benefits:
For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.

California Pay Equity:
For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.

Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.

If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.

Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).

 

Apply Now

 

About Rose

  • Founded in 1993
  • Office Locations Across the U.S.
  • 150+ Clients: Corporations and Government Agencies
  • Employee Oriented Company
  • Challenging Assignments Across the U.S.
  • Continuous Professional Development

The interactions that I have had with your representatives have always been prompt and very professional. I am very pleased and impressed with your company and services.

Sioe, Consultant

You are customer service oriented. No matter whether it was the Recruiter or someone in Human Resources/Payroll, you were responsive. That to me is key!

Tonya, Consultant

Thanks for the opportunity. If in the future I ever need a job, I would like to work for Rose International.

David, Consultant

It is a great pleasure being a part of the Rose International Team.

Toni, Consultant

Rose International maintained good communication during assignments and are very informative through email and phone calls.

Sade, Consultant

EMPLOYEE COMMENTS

  • We want you to work with us, but don't take our word for it. Take a look at this sampling of employee comments. They speak for themselves.