Senior Attack Surface Management / Vulnerability Management Analyst
Job Summary:
The Senior Attack Surface Management / Vulnerability Management Analyst plays
a critical role in safeguarding the organization's digital landscape by
identifying, assessing, and mitigating vulnerabilities. With a focus on
advanced security tools and strategies, this position directly impacts the
overall security posture and resilience of the company.
Key Responsibilities:
-
Conduct comprehensive vulnerability assessments and prioritize risks to
support organizational security efforts.
-
Implement and manage Attack Surface Management (ASM) strategies to
proactively identify and reduce security exposure.
-
Utilize cloud security tools, specifically WIZ, to monitor and enhance the
organization's cloud security posture.
-
Leverage CrowdStrike to analyze endpoint vulnerabilities and develop
mitigation strategies.
-
Collaborate with cross-functional teams to develop and disseminate security
best practices across the organization.
-
Prepare detailed reports and present findings on vulnerability management
and attack surface assessments to stakeholders.
-
Stay current with security trends, threat landscapes, and emerging
technologies to ensure robust security measures.
Requirements:
-
6+ years of experience in vulnerability management or attack surface
management within an enterprise environment.
-
Proficient in using WIZ and CrowdStrike for cloud security and endpoint
management.
-
Strong understanding of security frameworks and best practices (e.g., NIST,
ISO 27001).
- Experience with penetration testing and security assessment tools.
-
Excellent problem-solving skills and the ability to analyze complex security
issues.
-
Outstanding communication skills, capable of conveying technical information
to non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, or CEH are preferred.
Preferred Qualifications:
- Experience with DevSecOps practices and tools.
- Familiarity with SIEM tools and incident response techniques.
-
Hands-on experience in cloud service provider security (AWS, Azure, GCP).
-
Previous experience in a security operations center (SOC) or similar
environment.
Benefits:
- Competitive salary with performance-based incentives.
- Flexible hybrid work model, promoting work-life balance.
-
Comprehensive health insurance coverage for employees and their families.
-
Continuous learning and development opportunities, including certifications.
- Access to wellness programs and mental health resources.
- Employee referral bonuses and rewards for exceptional performance.
- Engaging company culture with regular team-building activities.