Senior Consultant | Application Security | Vulnerability Management

Expedite Talent Solutions
  • Boston, MA
  • Remote
  • Quick Apply
1 day ago

Job Description

Description: Job title Mobile Vulnerability Management and Configuration Compliance Engineer

Work location Hybrid the resource is required to work from Springfield or Boston or NY office of client three days in a week.

Is it Hybrid, onsite or remote position - Hybrid

Tentative Start date 25-Aug--2026

Contract duration 1 year

Vendor rate *** USD/Hr

Mandatory skills - design, validate, and operationalize an automated mobile device vulnerability scanning and configuration compliance capability across enterprise-issued mobile endpoints (iOS/iPadOS and Android)

Minimum years of experience needed in the required skills- 8-10 years

Minimum over all work experience required 8-10 years

Domain Cyber Security

Any certification required - Preferred Certifications

CompTIA Security+, CySA+
GIAC: GSEC, GMON, or related (if available/appropriate)
Qualys/Rapid7/Tenable (or equivalent vulnerability platform certifications where relevant)
Governance / Risk / Architecture (bonus)
CISSP, CISM, CCSP
ITIL Foundation (for ITSM integration and operations maturity)

Complete job description
Define PoT scope, success criteria, and test plans for automated mobile vulnerability scanning (e.g., agent-based/agentless, MDM-integrated, API-driven).
Evaluate candidate tools for: coverage (OS/app/cert/profile), detection accuracy, scalability, device impact, privacy controls, and reporting fidelity.
Execute pilots across representative device populations validating:
o vulnerability detection capabilities (OS versions, CVEs, patch levels, risky apps)
o configuration compliance checks (encryption, jailbreak/root, screen lock, OS hardening)
o integration readiness (Intune/Workspace ONE/Jamf; SIEM; ITSM; CMDB)

Produce PoT outcomes: findings, risk analysis, cost/benefit, architecture decision record, and go/no-go recommendation.
Coordinate with InfoSec and Compliance teams to ensure SaaS platform posture aligns with regulatory requirements (NYDFS).
Build and run mobile vulnerability lifecycle processes: discovery, assessment, prioritization, remediation, validation, reporting.
Establish severity/risk scoring tuned for mobile (exposure, device role, app risk, compliance impact).
Coordinate remediation with endpoint engineering, mobility admins, app owners, and operations teams.
Validate remediation effectiveness using scanner re-runs, policy compliance, and audit evidence.
Develop, deploy, and continuously improve baseline security configurations for iOS/iPadOS and Android.
Translate requirements into enforceable policies (password/biometrics, encryption, OS update controls, app controls, certificate/profile constraints, VPN/Wi-Fi security, logging settings).
Implement compliance monitoring and drift detection; drive automated or semi-automated corrective actions.
Build automation scripts and APIs to normalize and enrich findings.
Support change management and communications for new controls impacting device behavior and user experience.
Provide technical guidance and training to operations teams for ongoing support.

Interview mode - In person/Virtual - Virtual

How many rounds of interview 1 or 2

Custom Fields:
Name: Intake Call Completed
Value: true

Name: Intake Call Requested
Value: true

Numbers & Facts

LocationBoston, MA (
Remote
)

Skills

  • Androidunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Change Managementunmatched
  • CompTIA Security+unmatched
  • Computer Securityunmatched
  • Consultingunmatched
  • Continuous Improvementunmatched
  • Corrective Actionunmatched
  • Cost Benefit Analysisunmatched
  • Customer/Consumer Behaviorunmatched
  • Establish Prioritiesunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • GSEC - GIAC Security Essentials Certificationunmatched
  • IT Service Management (ITSM)unmatched
  • ITIL (IT Infrastructure Library)unmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Manufacturing Data Managementunmatched
  • Mobile Devicesunmatched
  • Operating Systemsunmatched
  • Privacy Controlsunmatched
  • Regulatory Requirementsunmatched
  • Risk Analysisunmatched
  • Software Patchesunmatched
  • Software as a Service (SaaS)unmatched
  • Technical Leadershipunmatched
  • Technical Trainingunmatched
  • Test Automationunmatched
  • Test Plan/Scheduleunmatched
  • User Interface/Experience (UI/UX)unmatched
  • Vulnerability Scannersunmatched
  • iOSunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder