Remotery

Threat Exposure, Attack Surface Analyst

Posted Aug 6

This is a fully remote position, open to applicants in United States.

📋 Description

• Analyze enterprise vulnerability data to pinpoint the most critical cyber exposures within the NIH environment.

• Stay informed about CISA Known Exploited Vulnerabilities (KEVs), emerging threats, and active adversary campaigns impacting NIH systems.

• Link vulnerability findings with threat intelligence, exploit availability, attack techniques, and operational risk to enhance remediation prioritization.

• Assess the enterprise attack surface, identify high-value targets, and evaluate how changes in infrastructure, cloud services, identities, or external exposure affect organizational risk.

• Validate penetration testing results and determine if vulnerabilities present feasible attack paths or chances for privilege escalation and lateral movement.

• Evaluate compensating controls and the effectiveness of remediation efforts.

• Suggest remediation priorities based on exploitability, mission impact, and threat activity.

• Collaborate with incident responders, penetration testers, ISSOs, and security engineers to refine the prioritization of enterprise risks.

• Create technical analyses, exposure assessments, executive summaries, and operational reports.

• Assist RMF activities with technical justifications for POA&M prioritization, risk acceptance decisions, and ongoing monitoring.

• Propose enhancements to attack surface management, threat-informed vulnerability prioritization, and enterprise exposure management processes.

• Manage daily RMF activities, maintain security documentation, support continuous monitoring, track remediation efforts, and align cybersecurity activities with Federal requirements.


⛳️ Requirements

• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical field.

• A minimum of three years of experience in vulnerability management, attack surface management, cyber threat intelligence, penetration testing, security operations, or enterprise risk analysis.

• Experience in analyzing vulnerability data and converting technical findings into operational risk assessments.

• Familiarity with CVSS, CVEs, CISA Known Exploited Vulnerabilities (KEV), MITRE ATT&CK, and contemporary threat intelligence methodologies.

• Understanding of attack paths, identity-based attacks, lateral movement, privilege escalation, and common adversary TTPs.

• Knowledge of NIST RMF, FISMA, and Federal cybersecurity practices.

• Strong analytical, investigative, and technical writing abilities.

• Preferred: Experience working with NIH, HHS, or other Federal civilian agencies.

• Preferred: Familiarity with Tenable, Qualys, Rapid7, Armis, CrowdStrike Exposure Management, Microsoft Defender, ServiceNow, or similar enterprise security platforms.

• Preferred: Experience contributing to penetration testing efforts and validating remediation.

• Preferred: Familiarity with EASM, CAASM, or exposure management platforms.

• Preferred: Understanding of cloud security, Zero Trust, and enterprise architecture concepts.

• Preferred: Experience with continuous monitoring, RMF, and POA&M management.

• Preferred certifications include GCVA, GPEN, GDAT, CompTIA CySA+, CEH, or Security+.


🏝️ Benefits

• Competitive salary, paid bi-monthly.

• Top-tier medical coverage.

• Full coverage of medical premiums by True Zero.

• Company-wide new business incentive programs.

• Contribution Incentives (e.g., white papers, blog posts, internal webinars, etc.).

• Three weeks of PTO plus 11 paid holidays each year.

• 401k program with a 100% company match on the first 4%.

• Monthly reimbursement for cell phone and home internet expenses.

• Paternity/Maternity leave.

• Investment in training and certifications to enhance and expand your technical skills.

People also viewed

CVS Health10 hours ago

Senior EDI Testing Analyst

US flagMichigan OnlyFull-timeAnalyst$47k – $112.2k/year
ApplyView job
IVC Evidensia UK10 hours ago

Insight Analyst

GB flagUnited Kingdom OnlyFull-timeAnalyst
ApplyView job
DIGESTIVE HEALTH11 hours ago

Payor Analyst

US flagPennsylvania OnlyFull-timeAnalyst
ApplyView job
Advanced Cooling Technologies, Inc.11 hours ago

Structural Analyst

US flagPennsylvania OnlyFull-timeAnalyst
ApplyView job
NMI11 hours ago

Integration Analyst, Bilingual Spanish/English

US flagUnited States OnlyFull-timeAnalyst$55k – $65k/year
ApplyView job
Abtrex Industries, Inc12 hours ago

Hardware and Software Acquisition Analyst

US flagPennsylvania OnlyFull-timeAnalyst$54k – $58k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers