← Back to projects

SECURITY ENGINEERING CASE STUDY

Vulnerability and Compliance Engineering

A vulnerability and compliance engineering portfolio section covering two related but distinct toolchains: Rapid7 for modern vulnerability management and dashboard-driven remediation workflows, and ACAS/Nessus for authenticated compliance scanning, vulnerability assessment, and baseline validation.

Status: Active Type: Vulnerability Management Role: Security / Infrastructure Engineer Focus: Remediation Validation Context: Professional Experience - Sanitized
EVIDENCE AT A GLANCE Rapid7 + ACAS/Nessus Authenticated scanning Baseline validation Remediation to rescan

Choose a workflow: Rapid7 or ACAS/Nessus.

This section is split by platform because the workflows serve different operational needs. Rapid7 supports enterprise vulnerability visibility, dashboards, benchmark policy review, remediation tracking, and before and after reporting. ACAS/Nessus supports credentialed scanning, plugin-level findings, compliance validation, baseline checks, and controlled vulnerability assessment workflows.

Rapid7 Vulnerability Management

Dashboard-driven visibility, asset review, benchmark policy work, remediation tracking, and validation reporting.

View Rapid7 workflow →

ACAS / Nessus Compliance Scanning

Credentialed scanning, plugin review, compliance checks, baseline validation, remediation guidance, and rescan verification.

View ACAS / Nessus workflow →

Rapid7 turned vulnerability data into operational visibility.

Rapid7 was used to support vulnerability visibility, asset tracking, dashboard creation, benchmark policy review, and remediation reporting. The work focused on turning scan data into information that infrastructure owners could actually act on.

flowchart TD
  ASSET[Assets] --> DISC[Discovery / Agent / Scan Data]
  DISC --> R7[Rapid7 Platform]
  R7 --> DASH[Dashboards and Findings]
  DASH --> PRI[Prioritization]
  PRI --> REM[Remediation Work]
  REM --> RESCAN[Validation / Rescan]
  RESCAN --> REPORT[Before and After Reporting]
        

Asset visibility

Reviewed visible assets, scan coverage, and whether expected systems were properly represented in the vulnerability management platform.

Dashboards and findings

Built and reviewed dashboards so vulnerability data could be understood by infrastructure owners instead of sitting as static scan output.

Benchmark review

Worked through CIS-style benchmark and policy evaluation to understand how baseline controls applied to real assets.

Remediation validation

Focused on before and after reporting so remediation could be measured through dashboard changes, rescans, or other validation evidence.

The Rapid7 workflow improved the path from finding to fix.

The Rapid7 work improved vulnerability visibility and created a better operational path from findings to remediation. Instead of treating scans as static reports, the workflow focused on dashboards, ownership, prioritization, and validation.

ACAS and Nessus supported controlled compliance scanning.

ACAS and Nessus workflows were used for authenticated vulnerability assessment, compliance scanning, baseline validation, and remediation support in controlled environments. This work focused on accurate scan targeting, credentialed assessment, plugin and finding review, and translating technical scan output into actionable remediation steps.

flowchart TD
  SCOPE[Defined Scan Scope] --> CREDS[Credentialed Access]
  CREDS --> SCAN[Nessus / ACAS Scan]
  SCAN --> FIND[Plugin Findings]
  FIND --> REVIEW[Review / Validate Findings]
  REVIEW --> REMED[Remediation Guidance]
  REMED --> VERIFY[Rescan / Verify]
  VERIFY --> REPORT[Compliance Report]
        

Credentialed scanning

Supported authenticated scanning workflows to produce deeper and more accurate results than unauthenticated discovery alone.

Plugin review

Reviewed plugin findings and vulnerability output to understand affected systems, finding logic, severity, and remediation paths.

Compliance validation

Worked with compliance-style scan results and security baseline validation workflows, including STIG-style assessment thinking.

Rescan verification

Used rescanning and evidence review to confirm whether remediation was successful and whether findings remained present.

The tools overlap, but they serve different operational patterns.

Rapid7 is strongest for

  • Enterprise vulnerability management.
  • Dashboards and exposure visibility.
  • Asset tracking and remediation ownership.
  • Benchmark reporting and trend review.
  • Before and after remediation validation.

ACAS / Nessus is strongest for

  • Credentialed vulnerability scanning.
  • Plugin-level findings.
  • Compliance and baseline checks.
  • Controlled scan scopes.
  • Technical remediation verification.

Scanner output only becomes valuable when it drives action.

Visibility comes before remediation

You cannot fix what you cannot see. Asset visibility and scan coverage are the foundation of vulnerability management.

Output is not the same as value

A scanner can produce findings, but engineering judgment is needed to prioritize, validate, and communicate what matters.

Credentialed scans matter

Authenticated scanning provides deeper and more accurate results than unauthenticated discovery alone.

Benchmarks need context

CIS, STIG, and benchmark-style policies are baselines. They need to be interpreted against the environment, risk, and operational requirements.

Vulnerability management, compliance scanning, and validation reporting.

Built and supported vulnerability and compliance engineering workflows across Rapid7 and ACAS/Nessus platforms, including asset visibility, dashboard creation, authenticated scanning, benchmark review, compliance validation, remediation tracking, and before and after verification reporting.