Work as a Vulnerability Attack Surface Reduction Analyst, including leading and supporting the development and delivery of a diverse range of attack surface reduction consulting and operations service programs to a portfolio of our commercial clients. Collaborate with a team that delivers world-class Cybersecurity attack surface reduction and vulnerability management, security testing, and application security capability development programs and solutions to large enterprise customers. Deliver vulnerability management and attack surface reduction security services to our large enterprise clients in support of their overall Cyber Defense programs. Recommend and document Attack Surface Reduction (ASR) and Threat and Vulnerability Management improvements based on assessment, operations, and analysis work. Perform vulnerability attack surface assessments and threat modeling to identify control weaknesses and assess the effectiveness of existing controls. Perform root cause analysis on identified vulnerabilities and attack surface weaknesses to determine feasible technical solutions, help triage risks, and prioritize remediation activities. This position is open to remote delivery anywhere within the U.S., to include the District of Columbia.
1+ years of experience with vulnerability management and Cybersecurity operations
1+ years of experience with vulnerability management platforms, including Qualys, Rapid7, or Tenable Nessus
1+ years of experience with databases, CSV files, and other large data sources to query, analyze, and identify ways to improve various attack surface vulnerability management related functions and processes
Knowledge of general Cybersecurity concepts and methods, including vulnerability management, application security, incident response, governance, risk or compliance, or security architecture
HS diploma or GED
2+ years of experience with attack surface reduction
1+ years of experience with penetration testing or ethical hacking
Experience with security or secure coding and software development
Experience with server application and network security hardening
Experience with attack surface reduction or VM platforms, including Kenna, Microsoft Defender, Metasploit, RiskIQ, or Tripwire
CISSP, CISM, or CEH Certification
We’re an EOE that empowers our people—no matter their race, color, religion, sex, gender identity, sexual orientation, national origin, disability, veteran status, or other protected characteristic—to fearlessly drive change.