Summary
The Senior 2 Attack Surface Analyst reduces enterprise risk by identifying, assessing, and prioritizing high-risk exposures across the technology landscape. This role leads improvements to attack surface management capabilities and collaborates with cybersecurity and technology teams to drive remediation, automation, and secure-by-design practices.
Responsibilities
- Grow the attack surface management program and develop capabilities that improve exposure visibility.
- Improve processes, methodologies, and security tools, automating work where possible.
- Maintain cybersecurity standards, procedures, and runbooks.
- Partner with application security, DevOps, cloud, network, and offensive security teams to assess and reduce exposures.
- Lead risk-prioritized initiatives, identify opportunities for architectural improvements, and present operational and risk metrics.
- Lead compliance activities, validate evidence, and assess and address control gaps.
- Mentor teammates and maintain expertise through training and engagement with cybersecurity communities and threat intelligence.
Requirements
- At least 6 years of experience in security operations, vulnerability management, or offensive security, including senior or lead experience.
- Deep knowledge of MITRE ATT&CK, threat actor tactics, offensive security, ethical hacking, and cybersecurity controls.
- Experience implementing cloud security controls in a multi-cloud environment and expertise in scripting for automation.
- Advanced knowledge of networking, system administration, cloud services, asset management, IT architecture, and regulatory compliance.
- Strong leadership and communication skills.
- Bachelor's or master's degree in IT, computer science, cybersecurity, or a related field, or equivalent experience.
- Preferred: experience developing attack surface management capabilities, coaching analysts, applying emerging AI in cybersecurity, or holding advanced certifications.