Назад
Company hidden
10 дней назад

Senior 2 Cybersecurity Analyst (Attack Surface Management)

166 000 - 258 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior 2 Cybersecurity Analyst (Attack Surface Management) (Cybersecurity/Cloud Security): Reducing Nordstrom’s enterprise attack surface through continuous exposure identification, risk assessment, remediation, and automation with an accent on multi-cloud security, offensive security, and attack surface visibility. Focus on mapping attack surfaces, prioritizing vulnerabilities, integrating secure-by-design practices, and leading compliance and risk-reduction initiatives.

Location: Hybrid in Seattle, Washington

Salary: $166,000–$258,000 annual

Company

hirify.global is a retail company with an enterprise cybersecurity function focused on protecting its technology landscape.

What you will do

  • Lead the growth of the attack surface management program and develop capabilities that improve exposure visibility.
  • Drive improvements to attack surface management processes, methodologies, security toolsets, and automation.
  • Maintain cybersecurity standards, operating procedures, runbooks, and the organization’s attack surface map.
  • Collaborate with AppSec, DevOps, cloud platform, network, and offensive security teams to secure software and technology deployments.
  • Lead risk-prioritized initiatives to reduce vulnerabilities and exposures, while developing operational and risk metrics.
  • Lead compliance activities, including evidence validation, control evaluations, gap mitigation, and PCI assessments.

Requirements

  • 6+ years of experience in security operations, vulnerability management, or offensive security, including senior or lead-level experience.
  • Deep knowledge of the MITRE ATT&CK framework, threat actor TTPs, common attack vectors, and ethical hacking methodologies.
  • Experience implementing cloud security controls in multi-cloud environments and applying enterprise IT architecture principles.
  • Expertise in networking, system administration, cloud services, asset management, cybersecurity, and system and data-flow analysis.
  • Proficiency in scripting languages such as Python or PowerShell for process automation.
  • Bachelor’s or Master’s degree in information technology, computer science, cybersecurity, or a related field; equivalent experience is accepted.

Nice to have

  • Experience developing attack surface management capabilities and coaching junior analysts.
  • Expertise across vulnerability management, cloud security, network security, and cyber hygiene.
  • Thought leadership on emerging AI technologies in cybersecurity.
  • Advanced certifications such as OSCE, GREM, or CISSP.

Culture & Benefits

  • Hybrid work arrangement in Seattle.
  • Medical, vision, dental, retirement, and paid time-away benefits.
  • Life insurance, disability coverage, merchandise discounts, and employee assistance resources.
  • 401(k), paid time off, holidays, and potential performance-based incentives or bonuses.
  • Opportunities for training, certifications, industry engagement, mentorship, and knowledge sharing.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →