Security Analyst - Contract
Core
Analyze external attack surface data to build a validated, risk-actionable External Exposure Baseline and bridge technical discovery with risk governance.
Role type
Security Analyst (External Attack Surface Management)
Builds
External Exposure Baseline, asset inventory, risk prioritization plans
Domain
Cybersecurity, External Attack Surface Management (EASM), Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
External Attack Surface Management (EASM), data consolidation and normalization, asset inventory management, threat modeling, cloud infrastructure knowledge (GCP/AWS/Azure), network security (IP routing, DNS, SSL/TLS, VPN)
Preferred skills
Stakeholder influence, executive reporting, remediation planning
Technologies
GCP, AWS, Azure, security scanning platforms
Responsibilities
Analyze large-scale external exposure datasets to establish an authoritative external attack surface baseline; Consolidate, normalize, and de-duplicate asset discovery data from multiple engines; Reconcile discovered external assets against internal registers to identify ownership gaps; Evaluate findings to identify systemic control gaps and prioritize remediation; Define treatment recommendations including remediation actions or asset decommissioning; Maintain audit-ready records of findings and decision rationale; Deliver reporting on exposure trends and remediation progress for senior cybersecurity leadership.
Seniority
Mid-level, hands-on IC

