Back to all jobs

Attack Surface Management Analyst

Booz Allen

Nov 05

Attack Surface Management Analyst

Key Role:

Work as an Attack Surface Management Analyst, including leading and supporting the development and delivery of a diverse range of attack surface management consulting and operations service programs to a portfolio of our commercial clients. Collaborate with a team that delivers world-class Cybersecurity attack surface management, vulnerability management, security testing, and application security capability development programs and solutions to large enterprise customers. Deliver vulnerability management and attack surface management security services to our large enterprise clients in support of their overall Cyber Defense programs. Consult and document attack surface management and threat and vulnerability management improvements based on assessment, operations, and analysis work. Perform vulnerability attack surface assessments and threat modeling to identify control weaknesses and assess the effectiveness of existing controls. Perform root cause analysis on identified vulnerabilities and attack surface weaknesses to determine feasible technical solutions, help triage risks, and prioritize remediation activities. This position is open to remote delivery anywhere within the U.S., to include the District of Columbia.

Basic Qualifications:

  • 1+ years of experience with vulnerability management and Cybersecurity operations

  • 1+ years of experience with vulnerability management platforms, including Qualys, Rapid7, or Tenable Nessus

  • 1+ years of experience with databases and CSV files to query, analyze, and identify ways to improve various vulnerability management related functions and processes

  • Knowledge of general Cybersecurity concepts and methods, including vulnerability management, application security, incident response, governance, risk or compliance, or security architecture

  • Bachelor’s degree

Additional Qualifications:

  • 2+ years of experience with attack surface reduction or attack surface management

  • 1+ years of experience with penetration testing or ethical hacking 

  • Experience with secure coding and software development

  • Experience with server application and network security hardening 

  • Experience with ASM or VM platforms, including Kenna, Microsoft Defender, Metasploit, RiskIQ, or Tripwire

  • Possession of excellent oral and written communication skills


The proposed salary range for this position in Colorado is 65,000 to 90,000. Final salary will be determined based on various factors.

At Booz Allen, we celebrate your contributions, provide you with opportunities and choice, and support your total well-being. Our comprehensive benefit offerings include healthcare, retirement plan, insurance programs, commuter program, employee assistance program, paid and unpaid leave programs, education assistance, and childcare benefits.

We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic—to fearlessly drive change.