Mobile Vulnerability Management and Configuration Compliance Engineer

Hybrid in Boston, MA, US • Posted 2 days ago • Updated 2 days ago
Contract Independent
Contract Corp To Corp
Contract W2
Hybrid
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • design
  • validate
  • configuration compliance
  • mobile device vulnerability
  • iOS
  • iPadOS
  • Android

Summary

Unable to sponsor - ONLY Candidates that don't require any sponsorship are accepted

Job title Mobile Vulnerability Management and Configuration Compliance Engineer
Work location Hybrid the resource must work from the Springfield, IL / Boston, MA / NY, NY office three days a week.
Contract duration 1 year

Mandatory skills - design, validate, and operationalize an automated mobile device vulnerability scanning and configuration compliance capability across enterprise-issued mobile endpoints (iOS/iPadOS and Android)

Minimum overall work experience required 8-10 years

Domain Cyber Security

Any certification required - Preferred Certifications

CompTIA Security+, CySA+
GIAC: GSEC, GMON, or related (if available/appropriate)
Qualys/Rapid7/Tenable (or equivalent vulnerability platform certifications where relevant)
Governance / Risk / Architecture (bonus)
CISSP, CISM, CCSP
ITIL Foundation (for ITSM integration and operations maturity)

Complete job description


Define PoT scope, success criteria, and test plans for automated mobile vulnerability scanning (e.g., agent-based/agentless, MDM-integrated, API-driven).
Evaluate candidate tools for: coverage (OS/app/cert/profile), detection accuracy, scalability, device impact, privacy controls, and reporting fidelity.
Execute pilots across representative device populations validating:
o vulnerability detection capabilities (OS versions, CVEs, patch levels, risky apps)
o configuration compliance checks (encryption, jailbreak/root, screen lock, OS hardening)
o integration readiness (Intune/Workspace ONE/Jamf; SIEM; ITSM; CMDB)

Produce PoT outcomes: findings, risk analysis, cost/benefit, architecture decision record, and go/no-go recommendation.
Coordinate with InfoSec and Compliance teams to ensure SaaS platform posture aligns with regulatory requirements (NYDFS).
Build and run mobile vulnerability lifecycle processes: discovery, assessment, prioritization, remediation, validation, reporting.
Establish severity/risk scoring tuned for mobile (exposure, device role, app risk, compliance impact).
Coordinate remediation with endpoint engineering, mobility admins, app owners, and operations teams.
Validate remediation effectiveness using scanner re-runs, policy compliance, and audit evidence.
Develop, deploy, and continuously improve baseline security configurations for iOS/iPadOS and Android.
Translate requirements into enforceable policies (password/biometrics, encryption, OS update controls, app controls, certificate/profile constraints, VPN/Wi-Fi security, logging settings).
Implement compliance monitoring and drift detection; drive automated or semi-automated corrective actions.
Build automation scripts and APIs to normalize and enrich findings.
Support change management and communications for new controls impacting device behavior and user experience.
Provide technical guidance and training to operations teams for ongoing support.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90901966
  • Position Id: 122624
  • Posted 2 days ago

Company Info

About Epic Systems, Inc,

Epic Systems, Inc (a.k.a. EPIC) has been incorporated in the state of Virginia. EPIC provides highest degree of satisfaction in providing the services for clients IT organizations since 2005. EPIC provides IT Consulting services throughout in the United States with various federal agencies and as well as commercial clients.

EPIC has been awarded as Small, Women-owned, and Minority-owned Business (SWaM) certified company in 2013 and has been received 8(a) small business certification from U.S Small Business Administration (SBA.gov)

Our IT professionals are committed to providing high-end reliable IT consulting services .Our consultants are highly skilled in the latest technology, and whether we work onsite at your office or we handle your needs remotely, you can be assured of reduced costs, increased productivity, and a greater return on your IT investment.

We work closely with customers to understand their goals and requirements. With a clear understanding of customer objectives and management goals, we develop the proper solutions for our customer organization.

We specializes in providing advanced technology solutions focused on information systems, enterprise solutions, custom web development and systems integration. We are here to solve client's IT challenges in various areas such as Enterprise Application Development, Application Integration and also Developing custom applications based on JAVA/J2EE/.NET. EPIC provide services to our clients using COTS (Commercial Off-The-Shelf) based products such as TIBCO SOA, Oracle OSB, and SAP areas. We also specialized in developing web development for clients that are needed to custom their web sites.

We provide lifecycle services that align your IT systems with your business processes so your organization can perform at its best from planning, development, and integration to security, management, and support.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs