← Back to jobs

Remote job

Vulnerability & Attack Surface Management Analyst II

Other Full-time Freelance United States

Job details

Not specified Salary
United States Eligibility
Lead Experience
Full-time Employment

About this role

Role overview

This is a newly created, full-time position on a security operations team that protects patient data and clinical systems for a healthcare organization subject to HIPAA. You will be the first person dedicated to vulnerability and attack surface management, owning the day-to-day program while reporting to a Director who sets strategy. Success looks like shrinking a large, fast-growing finding backlog into the handful of issues that actually matter and verifying that fixes have landed.

Responsibilities

- Run the full vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, from discovery through verification. - Prioritize findings using a risk model that weighs internet exposure, exploitability signals like CISA KEV and EPSS, asset criticality, and data sensitivity, and document when items are deliberately deferred. - Build and maintain a unified asset inventory spanning cloud, endpoint, and SaaS, ensuring every meaningful asset has a named owner. - Drive remediation through engineering, IT, and platform teams by writing actionable tickets, agreeing on timelines, escalating blockers, and confirming fixes. - Address root causes through hardened base images, dependency baselines, and automation that connects scanner and CNAPP APIs to ticketing and reporting. - Lead web application security, including dynamic scans, edge and WAF mitigations, and tracking for vulnerability disclosure or bug bounty reports. - Stand up security checks for an internal application publishing platform so internally built, externally published apps are inventoried and scanned.

Requirements

- 3 to 6 years in security, with hands-on time in vulnerability management, attack surface management, or cloud security posture. - Direct experience operating and tuning a vulnerability scanning or CNAPP platform, not only reading its output. - Practical risk-based prioritization skills, with working fluency in CVSS, EPSS, and the CISA KEV catalog and an opinion on how they combine. - Cloud security fundamentals in at least one major provider, ideally GCP or AWS, including container and dependency or SCA findings in code. - Comfort working from an incomplete inventory and figuring out what exists and who owns each asset. - A track record of working directly with engineering teams to ship fixes, plus scripting skills in Python, PowerShell, or similar to query APIs and automate reporting. - Hands-on use of AI assistants in security work, with concrete examples and discipline around what data is safe to share.

Nice to have

- Specific experience with Wiz, or comparable CNAPP and VM platforms such as Orca, Prisma Cloud, Defender for Cloud, Lacework, CrowdStrike Falcon Exposure Management, Tenable, Qualys, or Rapid7. - Attack surface and CAASM tooling such as Axonius or runZero, plus external discovery techniques including DNS, certificate transparency, and subdomain enumeration. - DAST and edge or WAF platforms like Invicti, Burp Suite, Cloudflare, or Akamai, and experience running a vulnerability disclosure or bug bounty program. - Hardened base image programs, Kubernetes and container security at scale (GKE or EKS), PaaS or edge hosting, SBOMs, and supply chain security work. - Regulated industry experience with HIPAA, HITRUST, or SOC 2, especially supplying vulnerability evidence to auditors and customers. - Relevant certifications such as GCLD, GCPN, GWEB, GSEC, cloud security specialty, or OSCP.

Benefits and work setup

- Competitive compensation - Medical, dental, and vision coverage - Flexible spending and health savings accounts - Generous PTO with hybrid work flexibility - 401(k) with company match - Life insurance, pet insurance, and additional benefits

Skills detected in the listing

PythonGoInformation SecurityAWSGCPKubernetes
Detected Sep 24, 2026
Last verified Sep 24, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight