Назад
Company hidden
4 дня назад

Global Lead, Attack Surface Management (f/m/d)

Формат работы
remote (только Poland)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Global Lead, Attack Surface Management (f/m/d) (Cybersecurity): Architecting and operationalizing enterprise ASM, EASM, and CAASM capabilities across internet-facing, internal, cloud, SaaS, subsidiary, and third-party surfaces with an accent on asset discovery, attribution, risk prioritization, and remediation governance. Focus on automating discovery correlation through APIs and scripting, integrating visibility with vulnerability and threat intelligence platforms, and driving ownership and remediation across distributed infrastructure teams.

Location: Remote in Poland; hosted by the Cytiva operating company in Kraków.

Company

A global science and technology company operating across life sciences, diagnostics, biotechnology, and cybersecurity.

What you will do

  • Architect the ASM operating model, including outside-in discovery, attribution, asset ownership workflows, and risk prioritization for CTEM.
  • Engineer and automate discovery correlation and enrichment across EASM, CAASM, DNS, certificate transparency, and CMDB sources.
  • Design integration blueprints connecting asset visibility with vulnerability, threat intelligence, and remediation platforms.
  • Establish sustainability and governance models covering ownership assignment, remediation SLAs, and external-hygiene controls.
  • Drive remediation across infrastructure, cloud, and third-party teams while reporting external risk to stakeholders.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • 7–9 years of cybersecurity experience focused on attack surface management, exposure management, or offensive and reconnaissance security.
  • Experience leading or operating enterprise ASM, EASM, or CAASM discovery, attribution, and remediation governance across internet-facing, cloud, and third-party surfaces.
  • Hands-on experience with ASM platforms and reconnaissance tools such as Cortex Xpanse, Defender EASM, CyCognito, Censys, or Shodan.
  • Strong knowledge of TCP/IP, DNS, TLS, certificates, and domains, with the ability to work independently across infrastructure, cloud, and third-party teams.

Nice to have

  • Experience with digital risk protection or M&A and subsidiary security integration.
  • Python scripting for API integration and automation.
  • CISSP, CISM, OSCP, CRTO, GCIH, GIAC, or vendor ASM/CAASM certification.

Culture & Benefits

  • Corporate role within hirify.global Information Security.
  • Culture focused on continuous improvement, belonging, and internal career development.
  • Opportunity to work across a global organization and multiple operating companies.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →