Global Lead, Attack Surface Management
Core
Owns the Attack Surface Management (ASM/EASM/CAASM) capability, driving discovery, attribution, asset ownership, risk prioritization, and cross-functional remediation for internet-facing, internal, cloud, SaaS, and third-party surfaces.
Role type
Senior IC cybersecurity engineer (attack surface management)
Builds
ASM operating model, automated discovery correlation/enrichment pipelines, and integration blueprints connecting asset visibility to vulnerability and threat intel platforms.
Domain
Cybersecurity, Cloud Security, Internet Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Attack surface management (ASM/EASM/CAASM), offensive/recon security, enterprise risk governance, API integration, scripting (Python), TCP/IP, DNS, TLS/certificates, domain management, stakeholder reporting
Preferred skills
Digital risk protection, M&A security integration, CISSP/CISM/OSCP/CRTO/GCIH/GIAC certifications, vendor ASM/CAASM certification
Technologies
Cortex Xpanse, Defender EASM, CyCognito, Censys, Shodan, CMDB
Responsibilities
Architect ASM operating models and workflows; Engineer/automate discovery correlation and enrichment; Design integration blueprints for asset visibility; Design sustainability and governance models for remediation SLAs.
Seniority
Senior, hands-on IC
