Remote job
Vulnerability & Attack Surface Management Analyst II
Job details
About this role
Role overview
This is a newly created, full-time position on a security operations team that protects patient data and clinical systems for a healthcare organization subject to HIPAA. You will be the first person dedicated to vulnerability and attack surface management, owning the day-to-day program while reporting to a Director who sets strategy. Success looks like shrinking a large, fast-growing finding backlog into the handful of issues that actually matter and verifying that fixes have landed.
Responsibilities
- Run the full vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, from discovery through verification. - Prioritize findings using a risk model that weighs internet exposure, exploitability signals like CISA KEV and EPSS, asset criticality, and data sensitivity, and document when items are deliberately deferred. - Build and maintain a unified asset inventory spanning cloud, endpoint, and SaaS, ensuring every meaningful asset has a named owner. - Drive remediation through engineering, IT, and platform teams by writing actionable tickets, agreeing on timelines, escalating blockers, and confirming fixes. - Address root causes through hardened base images, dependency baselines, and automation that connects scanner and CNAPP APIs to ticketing and reporting. - Lead web application security, including dynamic scans, edge and WAF mitigations, and tracking for vulnerability disclosure or bug bounty reports. - Stand up security checks for an internal application publishing platform so internally built, externally published apps are inventoried and scanned.
Requirements
- 3 to 6 years in security, with hands-on time in vulnerability management, attack surface management, or cloud security posture. - Direct experience operating and tuning a vulnerability scanning or CNAPP platform, not only reading its output. - Practical risk-based prioritization skills, with working fluency in CVSS, EPSS, and the CISA KEV catalog and an opinion on how they combine. - Cloud security fundamentals in at least one major provider, ideally GCP or AWS, including container and dependency or SCA findings in code. - Comfort working from an incomplete inventory and figuring out what exists and who owns each asset. - A track record of working directly with engineering teams to ship fixes, plus scripting skills in Python, PowerShell, or similar to query APIs and automate reporting. - Hands-on use of AI assistants in security work, with concrete examples and discipline around what data is safe to share.
Nice to have
- Specific experience with Wiz, or comparable CNAPP and VM platforms such as Orca, Prisma Cloud, Defender for Cloud, Lacework, CrowdStrike Falcon Exposure Management, Tenable, Qualys, or Rapid7. - Attack surface and CAASM tooling such as Axonius or runZero, plus external discovery techniques including DNS, certificate transparency, and subdomain enumeration. - DAST and edge or WAF platforms like Invicti, Burp Suite, Cloudflare, or Akamai, and experience running a vulnerability disclosure or bug bounty program. - Hardened base image programs, Kubernetes and container security at scale (GKE or EKS), PaaS or edge hosting, SBOMs, and supply chain security work. - Regulated industry experience with HIPAA, HITRUST, or SOC 2, especially supplying vulnerability evidence to auditors and customers. - Relevant certifications such as GCLD, GCPN, GWEB, GSEC, cloud security specialty, or OSCP.
Benefits and work setup
- Competitive compensation - Medical, dental, and vision coverage - Flexible spending and health savings accounts - Generous PTO with hybrid work flexibility - 401(k) with company match - Life insurance, pet insurance, and additional benefits