Senior Information Security Analyst - Attack Surface Management Lead
Core
Lead the Attack Surface Management function to identify meaningful exposure, prioritize remediation based on exploitability and business impact, and connect findings to detection engineering and threat hunting.
Role type
Senior IC security analyst (attack surface management lead)
Builds
Risk-driven validation capability for vulnerability discovery, penetration testing, and attack simulation
Domain
Healthcare cybersecurity / Offensive security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability management, Attack surface analysis, Penetration testing, Adversary emulation, Remediation prioritization, Detection engineering handoffs, Process maturity development, Incident response support, Technical reporting, Executive communication
Preferred skills
GCIH, GPEN, CISSP, OSCP
Technologies
MITRE ATT&CK, Vulnerability scanners, Penetration testing frameworks, Attack simulation platforms
Responsibilities
Support vulnerability discovery across infrastructure, applications, cloud, and endpoints; Analyze exposed assets and identities to identify meaningful exposure; Coordinate penetration testing activities including scoping and validation; Execute attack simulation and adversary emulation to validate security controls; Prioritize remediation based on exploitability and asset criticality; Partner with detection and threat hunting teams to inform security priorities; Develop repeatable processes and playbooks for ASM workflows; Support incident response by providing insight into attack paths and exposed assets.
Seniority
Senior, hands-on IC with leadership responsibilities