MassMutual employees
MassMutual Logo

MassMutual

Vulnerability Management and Configuration Assurance Analyst

Posted Yesterday
Be an Early Applicant
Hybrid
Springfield, MA
134K-176K Annually
Senior level
Hybrid
Springfield, MA
134K-176K Annually
Senior level
The role involves leading the vulnerability management program, conducting assessments, ensuring compliance, collaborating with teams, and reporting on security risks.
The summary above was generated by AI
The Opportunity
We are seeking an experienced Vulnerability Management and Configuration Assurance Engineer to join our Vulnerability Management and Configuration Assurance team. The ideal candidate will have a deep understanding of security principles, vulnerability management and secure baseline configuration monitoring and designing, implementing, and optimizing vulnerability assessment solutions for MassMutual. As an advanced-level engineer, you will collaborate with cross-functional teams to ensure the security posture of our organization meets industry standards and regulatory requirements.
The Team
The Vulnerability Management and Configuration Assurance (VMCA) team is responsible for identifying, assessing, prioritizing, reporting, and continuous monitoring of vulnerabilities and configuration baseline deficiencies within our organization's infrastructure, applications, and systems. Our team plays a critical role in maintaining the security posture of the company by proactively managing vulnerabilities that could be exploited by attackers.
VMCA is motivated by a shared sense of responsibility to protect the organization's assets and reputation by knowing our work directly mitigates security threats and prevents potential breaches, strong collaboration with other security and IT teams, continuous learning, innovation, and problem-solving. The culture of VMCA consists of proactive and preventative mindsets, collaboration, cross-disciplinary communication, accountability, ownership, agility, adaptability, inclusivity, knowledge sharing, and transparency.
The Impact:
Your key responsibilities will consist of the following to ensure digital assets are resilient against emerging threats, reducing potential financial and reputational damage from security incidents.
Vulnerability Management
  • Lead the design, implementation, and continuous improvement of the enterprise vulnerability management program.
  • Hands on experience using automated scanning tools (e.g., Qualys, Tenable, Rapid7, Wiz) to identify, assess, report, and track vulnerabilities detected on operating systems, databases, network devices, mobile devices, and cloud services.
  • Perform advanced vulnerability assessments across on-premises, cloud, containerized, and hybrid environments.
  • Analyze vulnerability scan results, prioritize findings based on risk, exploitability, and business impact.
  • Integrate threat intelligence and MITRE ATT&CK mapping to contextualize vulnerabilities and enhance prioritization.
  • Collaborate with infrastructure and business information security officers (BISO) teams to drive timely remediation and mitigation.
  • Identify and recommend compensating controls when immediate remediation is not feasible.
  • Develop and maintain metrics and dashboards to report on vulnerability trends, remediation progress, and risk posture.

Configuration Assurance
  • Utilize automated compliance tools to assess and validate configuration compliance for operating systems, databases, network devices, and cloud services.
  • Partner with IT and engineering teams to remediate configuration drift and ensure continuous compliance.
  • Map configuration assurance controls to regulatory frameworks (e.g., NIST, CIS, ISO 27001, PCI-DSS, HIPAA).
  • Maintain documentation of configuration standards and exceptions.

Data Analytics & Visualization
  • Leverage data analytics to identify trends, anomalies, and risk concentrations across vulnerability and configuration data.
  • Build and maintain dashboards and visualizations using tools such as Tableau, etc.
  • Present actionable insights to technical and executive stakeholders to support risk-based decision-making.

Tooling & Automation
  • Develop scripts and automation workflows to streamline scanning, reporting, and remediation tracking.
  • Integrate vulnerability and configuration data into SIEM, GRC, and ticketing systems.

Governance & Reporting
  • Provide executive-level reporting and risk analysis to support strategic decision-making.
  • Participate in internal and external audits, ensuring evidence of vulnerability and configuration assurance controls.
  • Stay current with emerging threats, vulnerabilities, and security technologies.

The Minimum Qualifications
  • Bachelor's or master's degree in computer science, Cybersecurity, or related field.
  • 8+ years of experience in vulnerability management, configuration assurance, or related security engineering roles.
  • Relevant security certifications such as CISSP, CISM, OSCP, GIAC (GSEC, GCIH, GCIA, etc.) from an industry recognized certifier (e.g., SANS/GIAC, CompTIA, ISACA, ISC2, etc.)

The Ideal Qualifications
  • Hands on experience with vulnerability scanning tools and configuration assessment platforms.
  • Familiar with advanced vulnerability management techniques such as continuous threat and exposure management and external attack surface management.
  • Deep understanding of CVSS, MITRE ATT&CK, threat modeling, and risk-based prioritization.
  • Experience implementing and validating compensating controls in enterprise environments.
  • Knowledge of cybersecurity concepts and methods including secure configuration management, data protection, security monitoring, incident response, patch management, governance, enterprise security strategies, and architecture.
  • Deep understanding of security vulnerabilities, exploits, and mitigation techniques.
  • Strong understanding of risk analysis, vulnerability assessment methodologies, and securing baselines.
  • Clear understanding of various operating systems (Windows, Unix, etc.,), secure configuration and build images.
  • Experience with cloud platforms (AWS, Azure, GCP), container security (Docker, Kubernetes), and security frameworks specific to cloud environment.
  • Familiarity with security best practices, regulatory requirements, and industry frameworks (e.g., NIST, ISO, CIS, etc.).
  • Strong scripting skills (Python, PowerShell, Bash) for automation and data manipulation.
  • Strong knowledge of networking protocols, firewalls, VPNs, and security measures.
  • Strong analytical, problem-solving, communication, and technical writing skills.
  • Excellent communication skills and ability to influence cross-functional teams.
  • Experience working in large, complex environments.
  • Ability to manage multiple projects and tasks effectively, with a proactive and detail-oriented approach.
  • Able to translate complex technical issues into simple, easy to understand concepts.

What to Expect as Part of MassMutual and the Team
  • Regular meetings with the Vulnerability Management and Configuration Assurance team.
  • Focused one-on-one meetings with your manager.
  • Access to mentorship opportunities.
  • Networking opportunities including access to Asian, Hispanic/Latinx, African American, women, LGBTQIA+, veteran and disability-focused Business Resource Groups.
  • Access to learning content on Degreed and other informational platforms.
  • Your ethics and integrity will be valued by a company with a strong and stable ethical business with industry leading pay and benefits.

MassMutual is an equal employment opportunity employer. We welcome all persons to apply.
If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.
Salary Range: $134,400.00-$176,400.00

Top Skills

AWS
Azure
Bash
Cis
GCP
Hipaa
Iso 27001
Nist
Pci-Dss
Powershell
Python
Qualys
Rapid7
Tableau
Tenable
Wiz

MassMutual Boston, Massachusetts, USA Office

Our new Boston campus opened in November in the Seaport neighborhood.

Boston Campus

Just like MassMutual, Boston's Seaport district is surrounded by decades of history, yet is now being recognized as a hub for digital innovation and professional growth. With us you can develop the skills you need to build a successful future and connect with talented and collaborative colleagues working together to help people secure their future and protect the ones they love.

Similar Jobs at MassMutual

Yesterday
Hybrid
Boston, MA, USA
71K-93K Annually
Junior
71K-93K Annually
Junior
Big Data • Fintech • Information Technology • Insurance • Financial Services
As a Regulatory Product Filing Consultant, you will manage the production of regulatory documents for variable products, coordinate with vendors, and incorporate legal updates while collaborating with a specialized team.
Top Skills: ExcelMicrosoft Office Suite
Yesterday
Hybrid
Springfield, MA, USA
176K-232K Annually
Senior level
176K-232K Annually
Senior level
Big Data • Fintech • Information Technology • Insurance • Financial Services
The Head of Voice of Customer & Experience Analytics leads experience insights strategy, oversees VOC programs, and drives measurable improvements through data analysis and team leadership.
Top Skills: ConfluenceForstaGitMedalliaPythonQualtricsRstudioSalesforceServicenow
Yesterday
Hybrid
Boston, MA, USA
105K-138K Annually
Senior level
105K-138K Annually
Senior level
Big Data • Fintech • Information Technology • Insurance • Financial Services
The ETX Governance & Administration Consultant coordinates audits, manages information repositories, produces reports, and implements governance frameworks to improve operational efficiency.
Top Skills: Enterprise-Level Grc PlatformExcelSharepoint

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account