Mobile Device Vulnerability Management & Configuration Compliance Engineer


Exl Neo Technologies
Dice Job Match Score™
🫥 Flibbertigibetting...
Job Details
Skills
- Mobile Devices
- Evaluation
- Security Controls
- Inventory
- Workflow
- Test Plans
- Vulnerability Scanning
- Scalability
- Privacy
- Configuration Management Database
- Risk Analysis
- Information Security
- SaaS
- Reporting
- Biometrics
- Encryption
- Virtual Private Network
- Wireless Communication
- Build Automation
- Change Management
- User Experience
- Training
- IOS Development
- Android
- ROOT
- Hardening
- Master Data Management
- Mobile Device Management
- Microsoft
- Enterprise Integration
- API
- Normalization
- SIEM
- Splunk
- IBM QRadar
- ServiceNow
- SSO
- Multi-factor Authentication
- Access Control
- Scripting
- Windows PowerShell
- Python
- JSON
- OAuth
- Auditing
- Documentation
- Analytical Skill
- Conflict Resolution
- Problem Solving
- Communication
- Stakeholder Management
- Presentations
- Attention To Detail
- FOCUS
- Process Improvement
- Operational Excellence
- Management
- Supervision
- STIG
- ISO/IEC 27001:2005
- Mapping
- Information Systems
- Computer Science
- Security+
- GSEC
- Qualys
- CISSP
- CISM
- Cisco Certifications
- ITIL
- IT Service Management
- SANS
- Cyber Security
- Endpoint Protection
- Vulnerability Management
- Regulatory Compliance
Summary
Role: Mobile Device Vulnerability Management & Configuration Compliance Engineer
Location: Springfield or Boston or NY - (Hybrid 3Days Onsite)
Duration: Long Term Contract
The Mobile Device Vulnerability Management & Configuration Compliance Engineer will partner with internal stakeholders to design, validate, and operationalize an automated mobile device vulnerability scanning and configuration compliance capability across enterprise-issued mobile endpoints (iOS/iPadOS and Android). This role leads proof-of-technology (PoT) activities including tool evaluation, architecture validation, security controls mapping, and pilot execution, and drives full-scale implementation through integration with other security tools such as MDM, SIEM/SOAR, ITSM, and asset inventory/CMDB systems.
The engineer will establish and maintain mobile vulnerability management processes aligned to corporate and regulatory requirements, develop continuous compliance and policy enforcement strategies, implement risk-based remediation workflows, and deliver measurable improvements in mobile endpoint security posture.
Key Responsibilities
- Define PoT scope, success criteria, and test plans for automated mobile vulnerability scanning (e.g., agent-based/agentless, MDM-integrated, API-driven).
- Evaluate candidate tools for: coverage (OS/app/cert/profile), detection accuracy, scalability, device impact, privacy controls, and reporting fidelity.
- Execute pilots across representative device populations validating:
- vulnerability detection capabilities (OS versions, CVEs, patch levels, risky apps)
- configuration compliance checks (encryption, jailbreak/root, screen lock, OS hardening)
- integration readiness (Intune/Workspace ONE/Jamf; SIEM; ITSM; CMDB)
- Produce PoT outcomes: findings, risk analysis, cost/benefit, architecture decision record, and go/no-go recommendation.
- Coordinate with InfoSec and Compliance teams to ensure SaaS platform posture aligns with regulatory requirements (NYDFS).
- Build and run mobile vulnerability lifecycle processes: discovery, assessment, prioritization, remediation, validation, reporting.
- Establish severity/risk scoring tuned for mobile (exposure, device role, app risk, compliance impact).
- Coordinate remediation with endpoint engineering, mobility admins, app owners, and operations teams.
- Validate remediation effectiveness using scanner re-runs, policy compliance, and audit evidence.
- Develop, deploy, and continuously improve baseline security configurations for iOS/iPadOS and Android.
- Translate requirements into enforceable policies (password/biometrics, encryption, OS update controls, app controls, certificate/profile constraints, VPN/Wi-Fi security, logging settings).
- Implement compliance monitoring and drift detection; drive automated or semi-automated corrective actions.
- Build automation scripts and APIs to normalize and enrich findings.
- Support change management and communications for new controls impacting device behavior and user experience.
- Provide technical guidance and training to operations teams for ongoing support.
Required Skills
- Mobile OS security fundamentals: iOS/iPadOS and Android security models, patching, permissions, app ecosystems, jailbreak/root detection concepts.
- Vulnerability management expertise: CVE/patch lifecycle, risk-based prioritization, SLAs, validation, metrics.
- Configuration compliance: baseline hardening, policy enforcement, continuous compliance monitoring, and drift remediation.
- Mobility Scanning Tool Experience (hands-on): Qualys Mobile VMDR, Lookout, Workspace One + Microsoft Threat Defense, or equivalent.
- MDM experience (hands-on): Microsoft Intune, Omnissa Workspace ONE, Jamf Pro, or equivalent.
- Enterprise integration skills: API integration, data normalization, and automation with SIEM/SOAR/ITSM (e.g., Splunk, Sentinel, QRadar; XSOAR, Sentinel SOAR; ServiceNow).
- Identity & access: conditional access concepts, device compliance states, SSO, certificates, MFA, posture-based access controls.
- Scripting/automation: PowerShell and/or Python; familiarity with REST APIs, JSON, OAuth, and secrets management.
- Security documentation: ability to author PoT plans, architecture diagrams, operational runbooks, and audit evidence.
- Excellent documentation and stakeholder management skills.
- Strong analytical and problem-solving skills.
- Excellent communication and stakeholder management skills; experience presenting PoT results and recommendations.
- Ability to work independently and across multifunctional teams.
- Detail-oriented with a focus on process improvement and operational excellence.
- Ability to manage multiple workstreams (pilot + integration + operations) with minimal supervision.
- Familiarity with NIST, CIS Benchmarks, DISA STIG (mobile), ISO 27001 control mapping, or similar frameworks.
Educational Requirements
- Bachelor s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or equivalent practical experience.
Relevant Certifications
- CompTIA Security+, CySA+
- GIAC: GSEC, GMON, or related (if available/appropriate)
- Qualys/Rapid7/Tenable (or equivalent vulnerability platform certifications where relevant)
- Governance / Risk / Architecture (bonus)
- CISSP, CISM, CCSP
- ITIL Foundation (for ITSM integration and operations maturity)
Experience Level
- 5 - 8+ years in cybersecurity/endpoint security, with 2 - 4+ years specifically in mobile/UEM security, vulnerability management, or compliance engineering.
- Dice Id: 91172235
- Position Id: OOJ - 1521-522-1786031246
- Posted 1 day ago
Company Info
About Exl Neo Technologies
EXL Neo is a leading IT consulting and staffing firm dedicated to delivering innovative technology solutions and connecting businesses with top-tier IT talent for enterprises in India, USA and Canada. Our mission is to empower organizations to thrive in a rapidly evolving digital landscape by providing expert guidance, strategic consulting, and highly skilled professionals tailored to meet the unique needs of each client.
Our Services IT Consulting:
*Strategic IT Planning: We work closely with clients to develop IT strategies that align with their business goals, ensuring technology serves as a catalyst for growth and efficiency. * Technology Implementation: From software development to cloud migration, our experts guide organizations through seamless technology implementations that enhance operational capabilities. * Cybersecurity: Protecting your business from cyber threats is our priority. We offer comprehensive cybersecurity assessments and solutions to safeguard your data and systems. * Digital Transformation: We assist businesses in embracing digital transformation by modernizing their IT infrastructure and adopting emerging technologies such as AI, IoT, and blockchain.
IT Staffing:
* Temporary Staffing: Whether you need to scale up for a project or require specialized skills, we provide highly qualified IT professionals on a temporary basis to meet your needs. * Permanent Placement: We help you find the right talent for your team, ensuring a perfect match in terms of skills, experience, and cultural fit. * Contract-to-Hire: This flexible staffing option allows you to evaluate a candidate's performance and fit within your organization before making a permanent hiring decision. * Executive Search: Our executive search services focus on identifying and recruiting top-level IT leaders who can drive your business forward.


Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs