> Markdown version of [/jobs/ext/2623038-senior-consultant-application-security-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/2623038-senior-consultant-application-security-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Consultant | Application Security | Vulnerability Management - **Company:** Ipolarity LLC - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $90,000.0 - $160,000.0 - **Contract:** Temporary to permanent - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Configuration Management Databases, Program Optimization, Cyber Security, System Configuration, Python (Programming Language), Performance Tuning, Windows PowerShell, Security Information and Event Management, Software Vulnerability Management, Scripting, Google Cloud, Software Security, Nessus, Qualys - **Published:** August 19, 2026 - **Apply:** https://www.careerjet.com/jobad/us67a4c87eebda70f126f68405265ac488 ## About the Role Vulnerability Management Platforms: Deep hands-on experience managing and optimizing enterprise tools (e.g., Qualys, Wiz, Nessus, Rapid7), including platform configuration, performance tuning, and data quality management. Tooling Integration & Engineering: Experience designing and implementing integrations between vulnerability platforms and enterprise systems (e.g., ServiceNow CMDB, SecOps, SIEM) to support automated workflows and governance processes. Automation & Scripting: Strong proficiency in automation and orchestration using scripting languages (e.g., Python, PowerShell) to streamline scanning, reporting, and remediation processes. Configuration Assurance & Secure Baselines: Advanced understanding of operating systems, secure configuration baselines, and continuous compliance validation across enterprise infrastructure. Data Analytics & Reporting: Ability to develop and maintain dashboards and metrics that provide insight into vulnerability trends, remediation performance, and risk posture for both technical and executive audiences. Cloud & Infrastructure Security: Experience securing modern environments, including cloud platforms (AWS, Azure, GCP) and hybrid infrastructures, with a focus on vulnerability and configuration risk management. Troubleshooting & Platform Optimization: Strong ability to identify tool defects, perform root cause analysis, and work with vendors to resolve issues and improve platform effectiveness. Project Code: Mobile Device Vulnerability Management a ## Description Mandatory skills: This role is responsible for driving end-to-end ownership of tooling, integrations, and processes that enable comprehensive visibility into vulnerabilities and configuration risks across on-premises, cloud, and hybrid environments. Minimum years of experience needed in the required skills: 8-10 years Minimum over all work experience required: 8-10 years Domain: Cyber Security Any certification required: NA Detailed Job Description: The engineer ensures that vulnerability and configuration data is accurate, complete, and actionable, enabling risk-based prioritization and effective remediation across the enterprise. This includes oversight of vulnerability management platforms, troubleshooting tool issues, and collaborating with cross-functional teams to enhance detection, reporting, and response capabilities. In addition, the VMCA Engineer develops and maintains scalable dashboards, metrics, and executive reporting to provide transparency into risk posture, remediation progress, and control effectiveness. The role is instrumental in driving automation, process improvement, and governance alignment, ensuring compliance with regulatory frameworks such as NIST, CIS, ISO, and NY DFS. As a senior technical resource, the engineer provides subject matter expertise, mentoring, and strategic guidance, translating complex technical risks into clear, actionable insights for both technical teams and executive leadership. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)