Threat Exposure Management Analyst
Core
Advancing cybersecurity from traditional vulnerability management to mature exposure management by identifying high-risk exposures, validating exploitability, and driving remediation of real risk to critical business services.
Role type
Senior IC threat exposure management analyst
Builds
Threat-informed prioritization models and attack-path analysis for critical assets
Domain
Fintech / Cybersecurity / Attack Surface Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Attack path analysis, exploitability validation, breach-and-attack simulation, cross-functional influence, risk prioritization beyond CVSS, threat intelligence integration (EPSS, CISA KEV), remediation campaign management, executive reporting
Preferred skills
Enterprise Attack Surface Management function experience, exception and risk-acceptance governance, exposure reporting for board audiences, systemic exposure coordination
Technologies
MITRE ATT&CK, Gartner CTEM model, EPSS, CISA KEV, CVSS, breach-and-attack simulation platforms
Responsibilities
Analyze exposure chaining into viable attack paths toward critical assets; Build and operate threat-informed prioritization models incorporating exploit availability; Map exposures to crown-jewel assets and define risk reduction metrics; Validate prioritized exposures using attack-path analysis and offensive security findings; Assess compensating controls before remediation; Maintain visibility across external, cloud, SaaS, and identity attack surfaces; Drive remediation across infrastructure and security partner teams; Produce technical and executive reporting on exposure trends
Seniority
Senior, hands-on IC with program leadership