Senior Consultant | Application Security | Vulnerability Management
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Mobile Vulnerability Management And Configuration Compliance Engineer
Work location – Hybrid – the resource is required to work from Springfield or Boston or NY office of client three days in a week. Tentative start date – 25-Aug-2026. Contract duration – 1 year.
Mandatory skills:
Design, validate, and operationalize an automated mobile device vulnerability scanning and configuration compliance capability across enterprise-issued mobile endpoints (iOS/iPadOS and Android).
Minimum years of experience needed in the required skills: 8-10 years. Minimum overall work experience required: 8-10 years. Domain – Cyber Security.
Preferred certifications:
CompTIA Security+, CySA+ GIAC: GSEC, GMON, or related (if available/appropriate) Qualys/Rapid7/Tenable (or equivalent vulnerability platform certifications where relevant) Governance / Risk / Architecture (bonus) CISSP, CISM, CCSP ITIL Foundation (for ITSM integration and operations maturity).
Complete job description:
Define PoT scope, success criteria, and test plans for automated mobile vulnerability scanning (e.g., agent-based/agentless, MDM-integrated, API-driven). Evaluate candidate tools for: coverage (OS/app/cert/profile), detection accuracy, scalability, device impact, privacy controls, and reporting fidelity. Execute pilots across representative device populations validating: vulnerability detection capabilities (OS versions, CVEs, patch levels, risky apps) configuration compliance checks (encryption, jailbreak/root, screen lock, OS hardening) integration readiness (Intune/Workspace ONE/Jamf;
SIEM; ITSM; CMDB). Produce PoT outcomes: findings, risk analysis, cost/benefit, architecture decision record, and go/no-go recommendation. Coordinate with Info Sec and Compliance teams to ensure SaaS platform posture aligns with regulatory requirements (NYDFS). Build and run mobile vulnerability lifecycle processes: discovery, assessment, prioritization, remediation, validation, reporting. Establish severity/risk scoring tuned for mobile (exposure, device role, app risk, compliance impact). Coordinate remediation with endpoint engineering, mobility admins, app owners, and operations teams.
Validate remediation effectiveness using scanner re-runs, policy compliance, and audit evidence. Develop, deploy, and continuously improve baseline security configurations for iOS/iPadOS and Android. Translate requirements into enforceable policies (password/biometrics, encryption, OS update controls, app controls, certificate/profile constraints, VPN/Wi-Fi security, logging settings). Implement compliance monitoring and drift detection; drive automated or semi-automated corrective actions. Build automation scripts and APIs to normalize and enrich findings.
Support change management and communications for new controls impacting device behavior and user experience. Provide technical guidance and training to operations teams for ongoing support.
Interview mode – In person/Virtual - Virtual. How many rounds of interview – 1 or 2.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).