Назад
Company hidden
7 дней назад

Vulnerability & Attack Surface Management Analyst II (Cloud Security)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability & Attack Surface Management Analyst II (Cloud Security): Building and operating vulnerability, exposure, asset inventory, web application security, and coordinated disclosure programs for a HIPAA-regulated telehealth platform with an accent on risk-based prioritization, remediation, and attack surface discovery. Focus on correlating cloud, endpoint, SaaS, container, and code findings, driving verified fixes through engineering, and automating CNAPP and scanner workflows with disciplined AI use in a PHI environment.

Location: United States — Remote

Company

hirify.global provides telehealth support solutions that help companies deliver virtual care across all 50 states, with security focused on protecting patient data, clinical operations, and PHI.

What you will do

  • Operate the vulnerability lifecycle across cloud workloads, containers, code repositories, endpoints, and web applications.
  • Prioritize findings using internet reachability, exploitability, asset criticality, data sensitivity, CVSS, EPSS, and CISA KEV.
  • Build an accurate asset inventory with ownership information and run recurring external attack surface discovery.
  • Drive remediation through Engineering, IT, and Platform teams, including ticketing, escalation, and fix verification.
  • Automate scanner and CNAPP integrations, reporting, hardened image and dependency baselines, and application publishing security gates.
  • Manage vulnerability disclosure and bug bounty intake, reporting metrics and audit evidence for clients, partners, and auditors.

Requirements

  • 3–6 years of security experience with hands-on vulnerability management, attack surface management, or cloud security work.
  • Experience operating and tuning a vulnerability scanning or CNAPP platform, preferably Wiz.
  • Working knowledge of CVSS, EPSS, CISA KEV, cloud security fundamentals, containers, image vulnerabilities, and software composition analysis.
  • Experience establishing incomplete inventories, assigning asset ownership, and working directly with engineering teams to ship fixes.
  • Proficiency with Python, PowerShell, or similar scripting for APIs, automation, and reporting.
  • Hands-on use of AI tools in security operations, with sound judgment regarding PHI, credentials, and sensitive telemetry.

Nice to have

  • Experience with AWS or GCP, GKE or EKS, DAST, WAF, external ASM, CAASM, SBOM, and software supply chain security.
  • Familiarity with Wiz, Orca, Prisma Cloud, Defender for Cloud, CrowdStrike, Tenable, Qualys, Rapid7, Axonius, runZero, Invicti, Burp Suite, HackerOne, or Bugcrowd.
  • Healthcare, fintech, HIPAA, HITRUST, SOC 2, or other regulated-environment experience.
  • Relevant security certifications or equivalent demonstrated expertise.

Culture & Benefits

  • Remote work with hybrid-work flexibility.
  • Medical, dental, and vision coverage.
  • Flexible Spending and Health Savings Accounts.
  • Generous paid time off, 401(k) with company match, life insurance, and pet insurance.
  • Flat organizational structure centered on autonomy, competence, and belonging.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →