Vulnerability Management Engineer
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 2–4 yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are looking for a motivated Cybersecurity Engineer with 2 to 4 years of relevant experience to fully take charge of vulnerability management using the Rapid7 InsightVM platform. This position, based in Dubai, requires onsite work and involves acting as the subject matter expert to maintain and enhance the vulnerability scanning environment, ensuring it is finely tuned and delivers precise security intelligence.
Primary Duties
- Manage, operate, and optimize the Rapid7 InsightVM environment, including its Security Console, distributed Scan Engines, and Insight Agents.
- Set up and maintain core components such as Sites, Scan Templates, Credentials, Asset Groups, and agent policies.
- Continuously monitor platform health parameters like scanning effectiveness, asset coverage, and authentication success to assure complete asset visibility.
- Schedule and execute both authenticated and unauthenticated vulnerability scans across various infrastructure layers including servers, network devices, cloud, and applications.
- Analyze scan outputs to prioritize and classify vulnerabilities according to established risk metrics such as CVSS, exploitability, asset importance, and business impact.
- Identify true positives, filter out false alarms, and provide remediation teams with precise, actionable instructions.
- Oversee vulnerability remediation progress through its full lifecycle, confirming fixes with re-scans.
- Produce detailed reports on a weekly and monthly basis, consisting of dashboards, SLA/KPI performance, and remediation updates targeted to both technical teams and executive management.
- Implement and maintain automated ticketing systems and integrate vulnerability data with enterprise ITSM, SIEM, GRC solutions, and directory services like Active Directory or LDAP.
- Collaborate closely with infrastructure, application, network, and security teams to ensure prompt remediation measures.
- Engage in platform upgrading, health assessments, troubleshooting, and capacity planning to maintain optimal performance.
- Document operational procedures, standard operating protocols, and baseline configurations meticulously.
Required Qualifications and Experience
- Between 2 and 4 years experience in cybersecurity with an emphasis on vulnerability management.
- At least 1 to 2 years of hands-on administrative experience specifically with Rapid7 InsightVM; experience limited to report review is insufficient.
- Strong familiarity with CVE, CVSS scoring, vulnerability assessment methodologies, and risk management frameworks.
- Solid understanding of Windows and Linux operating systems, networking principles, Active Directory, and typical enterprise network architectures.
- Proven ability to configure and troubleshoot credential-based authenticated vulnerability scans.
- Experience with automation and API integrations involving InsightVM and enterprise platforms such as SIEM, ITSM, and ticketing solutions.
- Excellent communication skills, both verbal and written, with the capability to translate complex technical risks into accessible business terminology for stakeholders.
Preferred Credentials
- Rapid7 InsightVM Administrator certification is highly desirable.
- Additional cybersecurity certifications such as Security+, CEH, or eJPT add value but are not mandatory.
Important Screening Information
Applicants must demonstrate genuine hands-on experience administering Rapid7 InsightVM, including configuring scan engines, credentials, and troubleshooting. Candidates without this depth of experience, limited to viewing vulnerability reports only, will be disqualified.
Industry
Cybersecurity