Vulnerability Management Engineer
VaporVM · Dubai, United Arab Emirates
Apply & track with Apply EdgePosition Title: Rapid7 Vulnerability Management EngineerExperience Level: 2–4 YearsLocation: Dubai, UAE (Onsite)Job Type: Full-time / Managed Services TeamRole SummaryWe are seeking a dedicated Cybersecurity Engineer with 2–4 years of experience to take ownership of our vulnerability management operations. In this role, you will be the subject matter expert for our Rapid7 InsightVM environment, ensuring the platform is finely tuned, operationally stable, and delivering actionable security intelligence. You will not just run scans—you will architect the scanning logic, analyze risk, and drive remediation efforts across a complex enterprise infrastructure.Key ResponsibilitiesPlatform Administration & OperationsAdminister, operate, and continuously optimize the Rapid7 InsightVM ecosystem, including the Security Console, distributed Scan Engines, and Insight Agents.Configure and manage all core components: Sites, Scan Templates, Credentials, Asset Groups, and agent policies.Proactively monitor platform health, scanning performance, coverage gaps, failed scans, and authentication errors to ensure 100% asset visibility.Vulnerability Assessment & AnalysisPlan, schedule, and execute authenticated and unauthenticated scans across diverse environments (servers, network devices, cloud, applications).Analyze scan results to prioritize vulnerabilities based on CVSS, exploitability, asset criticality, and business context.Differentiate true positives from false positives and provide remediation teams with clear, actionable guidance.Remediation & ReportingTrack vulnerabilities through the entire remediation lifecycle, conducting revalidation scans to confirm closure.Generate comprehensive weekly/monthly reports, including dashboards, SLA/KPI metrics, and remediation status for both technical and executive audiences.Configure automated ticketing workflows and integrate vulnerability data with ITSM, SIEM, GRC, and Active Directory/LDAP.Collaboration & Continuous ImprovementPartner with infrastructure, application, network, and security teams to drive timely remediation.Participate in platform upgrades, health checks, troubleshooting, and capacity planning.Maintain detailed operational documentation, SOPs, and scan-configuration baselines.Required Skills & ExperienceExperience: 2–4 years in cybersecurity, with a specific focus on vulnerability management.Rapid7 Expertise: Minimum 1–2 years of hands-on, administrative-level experience with Rapid7 InsightVM (not just report consumption).Technical Proficiency:Deep understanding of CVE, CVSS scoring, vulnerability prioritization, and risk frameworks.Strong knowledge of Windows/Linux OS, networking fundamentals, Active Directory, and common enterprise architectures.Proven experience configuring and troubleshooting authenticated scanning and credential-based scans.Integration & Automation: Familiarity with APIs and integrating InsightVM with enterprise platforms (SIEM, ITSM, ticketing tools).Soft Skills: Excellent reporting, documentation, and verbal communication skills. Ability to translate technical risk into business language for stakeholders.Preferred CertificationsRapid7 certification (e.g., InsightVM Administrator) is highly preferred.Additional security certifications (Security+, CEH, eJPT, or equivalent) are advantageous but not mandatory.Critical Screening RequirementPlease note: We require candidates with genuine, hands-on administrative experience with Rapid7 InsightVM. Applicants whose experience is limited to consuming or viewing vulnerability reports generated by others will not be considered. You must be comfortable configuring scan engines, tuning credentials, and troubleshooting the platform itself.