We are looking for a Cybersecurity Engineer with 2–4 years of hands-on experience in Vulnerability Management, with strong practical experience in Rapid7 InsightVM. The engineer will support the day-to-day operation, administration, monitoring, tuning, and optimization of the Rapid7 vulnerability management environment.
Key Responsibilities:
- Administer, operate, monitor, and maintain Rapid7 InsightVM and associated components.
- Configure and manage Security Console, Scan Engines, Sites, Scan Templates, Credentials, Asset Groups and Insight Agents. The proposed architecture specifically includes Security Console, distributed Scan Engines, and optional Insight Agents.
- Plan, configure, schedule, and monitor authenticated and unauthenticated vulnerability scans.
- Perform regular vulnerability assessments across servers, network devices, applications, cloud and other IT environments.
- Analyze vulnerabilities, prioritize risks, identify false positives, and support remediation teams.
- Track vulnerabilities through remediation and perform revalidation/rescanning to confirm closure.
- Monitor platform health, scanning performance, coverage, failed scans, authentication failures, and overall operational performance.
- Support integration of Rapid7 with ITSM/incident management, SIEM, GRC, Active Directory/LDAP and credential-management solutions.
- Configure automated ticketing/remediation workflows and vulnerability reporting.
- Prepare weekly/monthly vulnerability reports, dashboards, SLA/KPI reports and remediation status reports.
- Participate in platform health checks, troubleshooting, upgrades, tuning and continuous service improvement.
- Coordinate with infrastructure, application, network and security teams to drive vulnerability remediation.
- Maintain operational documentation, SOPs, scan configurations and remediation tracking.
Required Skills & Experience:
- 2–4 years of total cybersecurity / vulnerability management experience.
- Minimum 1–2 years of hands-on Rapid7 InsightVM experience strongly preferred.
- Practical experience managing vulnerability scanning in medium/large enterprise environments.
- Good understanding of CVEs, CVSS, vulnerability prioritization, remediation and risk management.
- Knowledge of Windows/Linux, networking, Active Directory and common enterprise infrastructure.
- Experience with authenticated vulnerability scanning and troubleshooting scan/credential issues.
- Understanding of APIs and integration with SIEM/ITSM platforms is an advantage.
- Good reporting, documentation and customer-facing communication skills.
- Ability to work onsite in Dubai and operate as part of a managed-services team.
Mandatory Certifications:
Rapid7 certification is mandatory.