
Vulnerability & Attack Surface Management Analyst II
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Manage the vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, which includes discovery, validation, prioritization, remediation tracking, verification, and reporting.
• Implement and enhance a risk model that takes into account internet exposure, exploitability, asset criticality, and data sensitivity.
• Develop a comprehensive asset inventory that integrates cloud, endpoint, and SaaS assets, along with designated owners.
• Perform regular external attack surface discovery to identify assets exposed on the internet.
• Facilitate remediation efforts in collaboration with Engineering, IT, and Platform teams; generate actionable tickets, establish timelines, escalate issues, and confirm resolutions.
• Deploy hardened base images and dependency baselines to address underlying issues.
• Integrate scanner and CNAPP APIs with ticketing and reporting systems to automate repetitive reporting processes.
• Take ownership of web application security through dynamic scanning, facilitating application team remediation, and temporary edge/WAF mitigation.
• Set up security checks for internally developed, externally published applications prior to their launch.
• Oversee vulnerability disclosure and bug bounty processes, including report validation, communication with researchers, handling duplicates, and ensuring verified remediation.
• Utilize AI tools to triage findings, correlate data, draft remediation guidance, and produce reports while ensuring the protection of PHI.
• Monitor mean time to remediate, backlog burn-down, and SLA coverage.
• Prepare reports for leadership and provide evidence for client, partner, and auditor requests in a HIPAA-regulated environment.
• Report directly to the Director of Information Security and offer insights on changing program priorities.
• 3 to 6 years of experience in security, with substantial hands-on experience in vulnerability management, attack surface management, or cloud security posture management.
• Practical experience in operating and fine-tuning a vulnerability scanning or CNAPP platform.
• Proven ability to prioritize a large volume of findings using a risk-based approach.
• Familiarity with CVSS, EPSS, and the CISA KEV catalog.
• Understanding of cloud security fundamentals in at least one major provider, preferably GCP or AWS.
• Experience with vulnerabilities in containers and images as well as dependency (SCA) findings in code repositories.
• Comfort with initiating work from an incomplete inventory and identifying existing assets and their owners.
• Proven experience collaborating directly with engineering teams to implement fixes.
• Proficiency in scripting with Python, PowerShell, or similar languages to query APIs and automate reporting tasks.
• Regular hands-on usage of AI tools such as Claude, ChatGPT, or GitHub Copilot in the context of security work.
• Capability to explain the safe handling of PHI, credentials, and sensitive data when using AI tools.
• Strong writing skills for creating engineering tickets and executive risk summaries.
• Preferred familiarity with tools like Wiz, Orca, Prisma Cloud, Defender for Cloud, Lacework, CrowdStrike Falcon Exposure Management or Spotlight, Tenable, Qualys, or Rapid7.
• Preferred experience with external ASM tools, DNS, certificate transparency, subdomain and shadow IT discovery, CAASM, Axonius, runZero, and SaaS discovery tools.
• Preferred experience with DAST, WAF, Invicti, Burp Suite, Cloudflare, Akamai, HackerOne, or Bugcrowd.
• Preferred familiarity with hardened base images, Kubernetes, GKE, EKS, Vercel, Netlify, Cloudflare Pages, SBOMs, and software supply chain security.
• Preferred experience in healthcare, fintech, or another regulated sector, including HIPAA, HITRUST, or SOC 2 compliance work.
• Preferred certifications include GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialty, OSCP, or equivalent experience.
• Competitive compensation.
• Medical, Dental & Vision coverage.
• Flexible Spending / Health Savings Accounts.
• Generous PTO and hybrid work flexibility.
• 401(k) plan with Company Match.
• Life Insurance, Pet Insurance, and additional benefits.
ICF
David Kennedy Recruitment Ltd.
Intel Corporation
Revolution Space
Get handpicked remote jobs straight to your inbox weekly.