1

Contract Vulnerability Analyst Jobs in Springfield, MA

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Varsity Tutors does not contract in: Alaska, California, Colorado, Delaware, Hawaii, Maine, New ...

Contract Vulnerability Analyst information

See Springfield, MA salary details

$30.9K

$73K

$129.5K

How much do contract vulnerability analyst jobs pay per year?

As of May 28, 2026, the average yearly pay for contract vulnerability analyst in Springfield, MA is $73,005.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,300.00 and $86,700.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Contract Vulnerability Analyst, and why are they important?

To thrive as a Contract Vulnerability Analyst, you need a strong background in cybersecurity principles, vulnerability assessment methodologies, and relevant certifications such as CEH or CompTIA Security+. Familiarity with vulnerability scanning tools like Nessus, Qualys, or OpenVAS, as well as experience with common operating systems and network protocols, is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts effectively identify, prioritize, and report vulnerabilities to stakeholders. These skills are crucial for ensuring organizational security and compliance while minimizing risk in dynamic contract-based environments.

What are some common challenges faced by Contract Vulnerability Analysts, and how can they overcome them?

Contract Vulnerability Analysts often face challenges such as rapidly changing threat landscapes and the need to quickly adapt to new security vulnerabilities in client environments. They must balance multiple client projects and prioritize tasks based on risk and impact. Success in this role requires strong communication skills to clearly explain technical findings to non-technical stakeholders and collaborate with both internal security teams and client IT departments. Building efficient workflows, staying updated with the latest security tools, and participating in regular training can help analysts stay ahead of threats and deliver impactful results.

What is a Contract Vulnerability Analyst?

A Contract Vulnerability Analyst is a cybersecurity professional who is hired on a contractual basis to identify, assess, and report security vulnerabilities within an organization's systems, networks, or applications. Their main role is to help companies find and address security weaknesses before attackers can exploit them. They often use various tools and methodologies to conduct vulnerability assessments, penetration testing, and security audits. Contract Vulnerability Analysts typically work for a set period or on a specific project, providing expert guidance to enhance the organization's security posture.

What is the difference between Contract Vulnerability Analyst vs Security Analyst?

AspectContract Vulnerability AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA
Work EnvironmentContract-based, project-specific roles, often remote or on-siteFull-time, in-house or remote security teams within organizations
Industry UsageIT security firms, consulting companies, tech organizationsCorporate, government, financial institutions
Search & Comparison IntentFocus on vulnerability assessment, penetration testing, security gapsBroader security management, incident response, policy enforcement

The Contract Vulnerability Analyst primarily focuses on identifying and mitigating security vulnerabilities through assessments and testing, often working on a contractual basis. In contrast, a Security Analyst typically handles ongoing security monitoring, incident response, and policy implementation within an organization. While both roles require similar certifications and work in the cybersecurity field, their scope and employment structure differ significantly.

What are the most commonly searched types of Vulnerability Analyst jobs in Springfield, MA? The most popular types of Vulnerability Analyst jobs in Springfield, MA are:
What are popular job titles related to Contract Vulnerability Analyst jobs in Springfield, MA? For Contract Vulnerability Analyst jobs in Springfield, MA, the most frequently searched job titles are:
What job categories do people searching Contract Vulnerability Analyst jobs in Springfield, MA look for? The top searched job categories for Contract Vulnerability Analyst jobs in Springfield, MA are:
What cities near Springfield, MA are hiring for Contract Vulnerability Analyst jobs? Cities near Springfield, MA with the most Contract Vulnerability Analyst job openings:
IT - Technology Architect | Identity Management | IDAM-Design , work flow , Implementation

IT - Technology Architect | Identity Management | IDAM-Design , work flow , Implementation

Spruce Infotech

Springfield, MA • On-site

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Job title - Mobile Device Vulnerability Management & Configuration Compliance Engineer
Work location - Springfield, Boston or New York/ NJ
Is it Hybrid, onsite or remote position - Onsite
Tentative Start date - Start Date will be decided based on candidate selection by client
Contract duration - 12 months
Vendor rate - 87.66
Does this position require Visa independent candidates only? Yes
Minimum years of experience needed in the required skills- 5 years of experience
Minimum over all work experience required - 5 years
Domain - Cyber Security : Application Security
JD:
The Mobile Device Vulnerability Management & Configuration Compliance Engineer will partner
with internal stakeholders to design, validate, and operationalize an automated mobile device
vulnerability scanning and configuration compliance capability across enterprise-issued mobile
endpoints (iOS/iPadOS and Android). This role leads proof-of-technology (PoT) activities including
tool evaluation, architecture validation, security controls mapping, and pilot execution, and drives
full-scale implementation through integration with other security tools such as MDM, SIEM/SOAR,
ITSM, and asset inventory/CMDB systems.
The engineer will establish and maintain mobile vulnerability management processes aligned to
corporate and regulatory requirements, develop continuous compliance and policy enforcement
strategies, implement risk-based remediation workflows, and deliver measurable improvements in
mobile endpoint security posture.
Key Responsibilities
• Define PoT scope, success criteria, and test plans for automated mobile vulnerability
scanning (e.g., agent-based/agentless, MDM-integrated, API-driven).
• Evaluate candidate tools for: coverage (OS/app/cert/profile), detection accuracy,
scalability, device impact, privacy controls, and reporting fidelity.
• Execute pilots across representative device populations validating:
o vulnerability detection capabilities (OS versions, CVEs, patch levels, risky apps)
o configuration compliance checks (encryption, jailbreak/root, screen lock, OS
hardening)
o integration readiness (Intune/Workspace ONE/Jamf; SIEM; ITSM; CMDB)
• Produce PoT outcomes: findings, risk analysis, cost/benefit, architecture decision record,
and go/no-go recommendation.
• Coordinate with InfoSec and Compliance teams to ensure SaaS platform posture aligns with
regulatory requirements (NYDFS).
• Build and run mobile vulnerability lifecycle processes: discovery, assessment, prioritization,
remediation, validation, reporting.
• Establish severity/risk scoring tuned for mobile (exposure, device role, app risk, compliance
impact).
• Coordinate remediation with endpoint engineering, mobility admins, app owners, and
operations teams.
• Validate remediation effectiveness using scanner re-runs, policy compliance, and audit
evidence.
• Develop, deploy, and continuously improve baseline security configurations for iOS/iPadOS
and Android.
• Translate requirements into enforceable policies (password/biometrics, encryption, OS
update controls, app controls, certificate/profile constraints, VPN/Wi-Fi security, logging
settings).
• Implement compliance monitoring and drift detection; drive automated or semi-automated
corrective actions.
• Build automation scripts and APIs to normalize and enrich findings
• Support change management and communications for new controls impacting device
behavior and user experience.
• Provide technical guidance and training to operations teams for ongoing support.
Required Skills
• Mobile OS security fundamentals: iOS/iPadOS and Android security models, patching,
permissions, app ecosystems, jailbreak/root detection concepts.
• Vulnerability management expertise: CVE/patch lifecycle, risk-based prioritization, SLAs,
validation, metrics.
• Configuration compliance: baseline hardening, policy enforcement, continuous compliance
monitoring, and drift remediation.
• Mobility Scanning Tool Experience (hands-on): Qualys Mobile VMDR, Lookout, Workspace
One + Microsoft Threat Defense, or equivalent.
• MDM experience (hands-on): Microsoft Intune, Omnissa Workspace ONE, Jamf Pro, or
equivalent.
• Enterprise integration skills: API integration, data normalization, and automation with
SIEM/SOAR/ITSM (e.g., Splunk, Sentinel, QRadar; XSOAR, Sentinel SOAR; ServiceNow).
• Identity & access: conditional access concepts, device compliance states, SSO,
certificates, MFA, posture-based access controls.
• Scripting/automation: PowerShell and/or Python; familiarity with REST APIs, JSON, OAuth,
and secrets management.
• Security documentation: ability to author PoT plans, architecture diagrams, operational
runbooks, and audit evidence.
• Excellent documentation and stakeholder management skills.
• Strong analytical and problem-solving skills.
• Excellent communication and stakeholder management skills; experience presenting PoT
results and recommendations.
• Ability to work independently and across multifunctional teams.
• Detail-oriented with a focus on process improvement and operational excellence.
• Ability to manage multiple workstreams (pilot + integration + operations) with minimal
supervision.
• Familiarity with NIST, CIS Benchmarks, DISA STIG (mobile), ISO 27001 control mapping, or
similar frameworks.
Educational Requirements
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering,
or equivalent practical experience.
Relevant Certifications
• CompTIA Security+, CySA+
• GIAC: GSEC, GMON, or related (if available/appropriate)
• Qualys/Rapid7/Tenable (or equivalent vulnerability platform certifications where relevant)
• Governance / Risk / Architecture (bonus)
• CISSP, CISM, CCSP
• ITIL Foundation (for ITSM integration and operations maturity)
Experience Level
• 5 - 8+ years in cybersecurity/endpoint security, with 2 - 4+ years specifically in mobile/UEM
security, vulnerability management, or compliance engineering.
Interview mode - In person/Virtual : Virtual
How many rounds of interview - minimum 2 rounds.