Назад
Company hidden
6 дней назад

Senior Attack Surface Management Analyst (Cybersecurity)

92 200 - 155 406$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Attack Surface Management Analyst (Cybersecurity): Building and scaling continuous asset discovery, exposure analysis, and remediation workflows across external and internal digital assets with an accent on multi-cloud security, threat intelligence, and automation. Focus on validating vulnerabilities through breach and attack simulation, correlating attack paths and business risk, and integrating ASM findings into engineering, ticketing, and purple team workflows.

Location: Remote in the United States

Salary: $92,200–$155,406 USD base salary annually for US-based employees; compensation may also include a corporate bonus or role-specific commission and equity participation.

Company

hirify.global provides identity security software and operates a centralized global attack surface management program.

What you will do

  • Scale continuous discovery and maintain inventories of domains, IPs, APIs, cloud resources, SaaS applications, Shadow IT, and other digital assets.
  • Build asset attribution models and integrate CMDB, cloud account, and security-tool data into a reliable source of truth.
  • Analyze cloud misconfigurations, exposed administrative portals, outdated systems, vulnerabilities, zero-days, attack paths, and threat intelligence to prioritize remediation.
  • Operate breach and attack simulation, autonomous pentesting, and purple teaming activities to validate controls and exploitability.
  • Partner with Engineering, DevOps, IT, Infrastructure, Cloud, Risk, and Governance teams to define SLAs, automate ticketing, verify fixes, and establish security policies.
  • Develop scripts, API integrations, metrics, runbooks, and technology roadmaps while mentoring junior analysts.

Requirements

  • 5+ years of hands-on experience in attack surface management, vulnerability management, penetration testing, threat intelligence, or security operations, including 1–2 years in a senior or lead capacity.
  • Advanced practical knowledge of securing and querying AWS, Azure, or GCP environments, including cloud security posture, IAM policies, and cloud-native APIs.
  • Strong scripting and REST API experience with Python, Go, or PowerShell, including JSON processing and security-tool integrations.
  • Experience with microservices, Kubernetes or containers, APIs, CI/CD pipelines, EASM and discovery platforms, and vulnerability management suites.
  • Deep familiarity with MITRE ATT&CK, threat intelligence, attack path analysis, and translating technical risks into actionable stakeholder guidance.
  • Must be based in the United States for the stated salary range and role location.

Nice to have

  • Experience with breach and attack simulation or autonomous pentesting platforms.
  • Experience applying AI/ML to asset discovery, risk categorization, or defense against AI-driven attacks.
  • CISSP, OSCP, GPEN, GCIH, CCSK, or similar advanced certifications.
  • AWS Certified Cloud Practitioner or AWS Certified Security – Specialty; one of these certifications must be obtained within the first year if not already held.

Culture & Benefits

  • Fully remote work within the United States.
  • Medical, dental, vision, disability, life, and accidental death and dismemberment insurance.
  • 401(k) savings and investment plan with company matching, HSA employer contributions, and flexible spending accounts.
  • Flexible vacation policy, paid holidays, sick leave, and paid parental leave.
  • Employee assistance services and optional legal, critical illness, accident, hospital indemnity, and pet insurance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →