Attack Surface Analyst II — Vulnerability & Cloud

Relha LLC

Seattle, Northern (WA, KY)

Hybrid

USD 122,000 - 189,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical/Vision, Dental, Retirement and
Paid Time Away
Life Insurance and Disability
Merchandise Discount and EAP Resources

Job summary

Nordstrom is seeking an Attack Surface Analyst II to identify and reduce exposure across cloud, on-prem, and third-party environments. The role requires collaboration with cyber security peers and partner teams to triage vulnerabilities and drive timely remediation.

Hybrid work in Seattle, with in-office presence four days a week at corporate headquarters. You will configure and tune vulnerability scanners, develop alerts, and contribute to metrics on attack surface risk.

Qualifications

  • 2+ years in security operations, vulnerability management, cybersecurity, IT, or related fields.
  • Understanding of networking, system administration, cloud services, asset management and cyber security principles.
  • Working knowledge of cybersecurity tools including vulnerability identification, CSPM, attack surface / exposure management platforms, network security tools.
  • Understanding of processes and controls needed to satisfy regulatory and compliance requirements (e.g. PCI) for vulnerability and attack surface management.
  • Understanding of cloud security concepts for multi-cloud environments (AWS, Azure, GCP), Cloud Asset Exposure: AWS S3 buckets, Azure Blob storage.
  • Proficiency in scripting languages (Python, PowerShell) for process automation.
  • Familiarity with MITRE ATT&CK, attack vectors, defense-in-depth, and cyber hygiene best practices.

Responsibilities

  • Maintain and grow attack surface management tools and reporting platforms by configuring and troubleshooting vulnerability scans, developing alerts, reviewing and tuning false positives, and building reporting templates to meet customer requirements.
  • Lead the triage of critical vulnerability findings alongside partner teams and stakeholders to analyze the risk of emergent vulnerabilities and patch releases, coordinating expedited remediation as needed.
  • Research solutions and mitigations for highest risk vulnerabilities and provide technical guidance to remediation teams.
  • Engage with cybersecurity community and threat intel sources to stay current on latest vulnerability publications, zero-day exploits, and threat actor activity trends.
  • Assist in mapping Nordstrom's attack surface by supporting reconnaissance activities with network and offensive security teams and monitoring dark web resources for emerging exposures.
  • Identify and track the status of attack surface reduction efforts, by analyzing vulnerabilities and exposure, potential impact, and likelihood of exploitation, and contribute to metrics that measure attack surface risk and remediation progress.
  • Identify and recommend opportunities to reduce attack surface through improved processes, tooling, or architectural changes.
  • Collaborate with cybersecurity peers, technology partner teams and other stakeholder groups to conduct asset identification and classification, vulnerability scanning, analysis, and prioritization activities.
  • Support regulatory and compliance requirements including capturing evidence and artifacts related to vulnerability scanning and reporting for [e.g. PCI].
  • Contribute to Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks.
  • Monitor, review, and escalate errors in automation of operational processes.
  • Increase cybersecurity domain depth and breadth by completing trainings, attending industry presentations, and cross-training with peers across Cybersecurity & Privacy and Technology teams.

Skills

Vulnerability management
Cybersecurity
Networking
Cloud services
CSPM
Python
PowerShell

Education

Bachelor's/Master's in IT/CS/Cybersecurity

Tools

Vulnerability scanners
ASM platforms
Cloud security tools

Job description

Nordstrom is seeking an Attack Surface Analyst II to identify and reduce exposure across cloud, on-prem, and third-party environments. The role requires collaboration with cyber security peers and partner teams to triage vulnerabilities and drive timely remediation.

Hybrid work in Seattle, with in-office presence four days a week at corporate headquarters. You will configure and tune vulnerability scanners, develop alerts, and contribute to metrics on attack surface risk.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Attack Surface Analyst: Cloud & Vulnerability Management
Attack Surface Analyst: Cloud & Vulnerability Management

Jobtailor • Seattle (WA)

On-site
USD 120,000 - 160,000
Attack Surface Analyst 2
Attack Surface Analyst 2

Jobtailor • Seattle (WA)

On-site
USD 120,000 - 160,000
Senior Attack Surface Management Analyst (Hybrid)
Senior Attack Surface Management Analyst (Hybrid)

Best Buy • Minneapolis (MN)

Hybrid
USD 100,000 - 140,000
Competitive pay
Generous employee discount
Well-being support
Security Analyst Consultant - Attack Surface Management
Security Analyst Consultant - Attack Surface Management

Kallesgroup • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical, Dental, Vision plans
401(k) with matching
PTO for salaried employees
+1
Offensive Security Analyst — Attack Surface & Vuls
Offensive Security Analyst — Attack Surface & Vuls

EY • Minneapolis (MN)

Hybrid
USD 76,000 - 139,000
Offensive Security Analyst: Hybrid Attack Surface
Offensive Security Analyst: Hybrid Attack Surface

EY • Fort Worth (TX)

Hybrid
USD 76,000 - 139,000
Offensive Security Analyst — Attack Surface & Vuls
Offensive Security Analyst — Attack Surface & Vuls

EY • Alpharetta (GA)

Hybrid
USD 76,000 - 139,000
EASM Analyst: Attack Surface & Risk Insights
EASM Analyst: Attack Surface & Risk Insights

Relha LLC • Hopkins (MN), Northern (KY)

Hybrid
USD 93,000 - 109,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Offensive Security Analyst — Attack Surface & Vuls
Offensive Security Analyst — Attack Surface & Vuls

EY • City of Rochester (NY)

Hybrid
USD 76,000 - 139,000