Назад
Company hidden
5 дней назад

Senior Cybersecurity Analyst - Attack Surface Management (Hybrid - Seattle)

166 000 - 258 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cybersecurity Analyst - Attack Surface Management (Cybersecurity): Leading enterprise-wide attack surface management to identify, assess, prioritize, and remediate high-risk exposures with an accent on cloud security, vulnerability management, and secure-by-design practices. Focus on mapping the technology attack surface, automating security processes with Python and PowerShell, integrating threat intelligence, and driving PCI compliance activities.

Location: Hybrid in Seattle, Washington, United States

Salary: $166,000–$258,000 annual

Company

hirify.global is a retail company offering products and services through a large enterprise technology environment.

What you will do

  • Lead the growth of the attack surface management program and develop capabilities that improve exposure visibility.
  • Drive improvements to attack surface management processes, methodologies, security tools, and automation.
  • Maintain cybersecurity standards, operating procedures, runbooks, and the organization’s attack surface map.
  • Collaborate with AppSec, DevOps, cloud platform, network, and offensive security teams to secure deployments and integrate secure-by-design practices.
  • Lead risk-prioritized initiatives to reduce vulnerabilities and exposures, present operational and risk metrics, and recommend architectural improvements.
  • Lead compliance activities, including evidence validation, control assessments, gap mitigation, and PCI-related evaluations.

Requirements

  • 6+ years of experience in security operations, vulnerability management, or offensive security, including senior or lead-level experience.
  • Deep knowledge of MITRE ATT&CK, threat actor TTPs, common attack vectors, offensive security, and ethical hacking.
  • Experience implementing cloud security controls in multi-cloud environments and understanding enterprise IT architecture.
  • Expertise in Python or PowerShell scripting for process automation, networking, system administration, cloud services, asset management, and cybersecurity.
  • Understanding of vulnerability and attack surface management controls required for regulatory compliance, including PCI.
  • Bachelor’s or Master’s degree in IT, Computer Science, Cybersecurity, or a related field; equivalent experience may substitute.

Nice to have

  • Experience developing attack surface management capabilities and mentoring junior analysts.
  • Broad expertise across vulnerability management, cloud security, network security, attack surface management, and cyber hygiene.
  • Thought leadership in applying emerging AI technologies to cybersecurity.
  • Advanced certifications such as OSCE, GREM, or CISSP.

Culture & Benefits

  • Medical, vision, dental, retirement, and paid time away benefits.
  • Life insurance, disability coverage, holidays, and PTO accrual.
  • Merchandise discount and employee assistance resources.
  • Performance-based incentives or bonuses may be available.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →