Vulnerability & Attack Surface Management Analyst II

Posted 2 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Manage the vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, which includes discovery, validation, prioritization, remediation tracking, verification, and reporting.

• Implement and enhance a risk model that takes into account internet exposure, exploitability, asset criticality, and data sensitivity.

• Develop a comprehensive asset inventory that integrates cloud, endpoint, and SaaS assets, along with designated owners.

• Perform regular external attack surface discovery to identify assets exposed on the internet.

• Facilitate remediation efforts in collaboration with Engineering, IT, and Platform teams; generate actionable tickets, establish timelines, escalate issues, and confirm resolutions.

• Deploy hardened base images and dependency baselines to address underlying issues.

• Integrate scanner and CNAPP APIs with ticketing and reporting systems to automate repetitive reporting processes.

• Take ownership of web application security through dynamic scanning, facilitating application team remediation, and temporary edge/WAF mitigation.

• Set up security checks for internally developed, externally published applications prior to their launch.

• Oversee vulnerability disclosure and bug bounty processes, including report validation, communication with researchers, handling duplicates, and ensuring verified remediation.

• Utilize AI tools to triage findings, correlate data, draft remediation guidance, and produce reports while ensuring the protection of PHI.

• Monitor mean time to remediate, backlog burn-down, and SLA coverage.

• Prepare reports for leadership and provide evidence for client, partner, and auditor requests in a HIPAA-regulated environment.

• Report directly to the Director of Information Security and offer insights on changing program priorities.


⛳️ Requirements

• 3 to 6 years of experience in security, with substantial hands-on experience in vulnerability management, attack surface management, or cloud security posture management.

• Practical experience in operating and fine-tuning a vulnerability scanning or CNAPP platform.

• Proven ability to prioritize a large volume of findings using a risk-based approach.

• Familiarity with CVSS, EPSS, and the CISA KEV catalog.

• Understanding of cloud security fundamentals in at least one major provider, preferably GCP or AWS.

• Experience with vulnerabilities in containers and images as well as dependency (SCA) findings in code repositories.

• Comfort with initiating work from an incomplete inventory and identifying existing assets and their owners.

• Proven experience collaborating directly with engineering teams to implement fixes.

• Proficiency in scripting with Python, PowerShell, or similar languages to query APIs and automate reporting tasks.

• Regular hands-on usage of AI tools such as Claude, ChatGPT, or GitHub Copilot in the context of security work.

• Capability to explain the safe handling of PHI, credentials, and sensitive data when using AI tools.

• Strong writing skills for creating engineering tickets and executive risk summaries.

• Preferred familiarity with tools like Wiz, Orca, Prisma Cloud, Defender for Cloud, Lacework, CrowdStrike Falcon Exposure Management or Spotlight, Tenable, Qualys, or Rapid7.

• Preferred experience with external ASM tools, DNS, certificate transparency, subdomain and shadow IT discovery, CAASM, Axonius, runZero, and SaaS discovery tools.

• Preferred experience with DAST, WAF, Invicti, Burp Suite, Cloudflare, Akamai, HackerOne, or Bugcrowd.

• Preferred familiarity with hardened base images, Kubernetes, GKE, EKS, Vercel, Netlify, Cloudflare Pages, SBOMs, and software supply chain security.

• Preferred experience in healthcare, fintech, or another regulated sector, including HIPAA, HITRUST, or SOC 2 compliance work.

• Preferred certifications include GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialty, OSCP, or equivalent experience.


🏝️ Benefits

• Competitive compensation.

• Medical, Dental & Vision coverage.

• Flexible Spending / Health Savings Accounts.

• Generous PTO and hybrid work flexibility.

• 401(k) plan with Company Match.

• Life Insurance, Pet Insurance, and additional benefits.

People also viewed

ICF17 hours ago

Summer Intern, Business Analyst

US flagVirginia OnlyPart-timeBusiness Analyst$23/hour
ApplyView job
David Kennedy Recruitment Ltd.17 hours ago

Junior Business Analyst

US flagUnited States OnlyFreelanceBusiness Analyst
ApplyView job
Intel Corporation1 day ago

Business Analyst

US flagUnited States OnlyFreelanceBusiness Analyst$52k – $200k/year
ApplyView job
Revolution Space1 day ago

Configuration Management Analyst

US flagUnited States OnlyFull-timeBusiness Analyst$85k – $100k/year
ApplyView job
Spread Tecnologia1 day ago

Business Analyst

BR flagBrazil OnlyFull-timeBusiness Analyst
ApplyView job
Slipstream IT1 day ago

Senior Pharma Business Analyst – DATAstream

US flagPennsylvania OnlyFull-timeBusiness Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers