Attack Surface Management Engineer (JR229558)

ViziRecruiter,LLC.

Village of Elmsford (NY)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Montefiore is hiring a Cybersecurity Engineer to support patient safety and clinical operations. The role involves implementing automated cybersecurity solutions, managing vendor relations, and ensuring compliance with healthcare regulations. Candidates should have a Bachelor's degree, 4-6 years in Cybersecurity, and familiarity with healthcare cybersecurity frameworks. Preferred qualifications include relevant certifications like CompTIA PenTest+ or GIAC Security Essentials. This position is vital for maintaining the integrity of sensitive health information.

Qualifications

  • 4-6 years of Cybersecurity or IT experience with a focus on vulnerability management.
  • Strong proficiency in management technologies across IT and cloud environments.
  • Experience assessing findings from vulnerability management platforms.

Responsibilities

  • Implement automated solutions to improve efficiency.
  • Collaborate with IT and clinical teams to integrate cybersecurity measures.
  • Manage vendor relationships concerning security solutions.

Skills

Cybersecurity experience
Vulnerability analysis
Asset discovery
Communication skills
Analytical skills

Education

Bachelor's degree or equivalent work experience

Tools

ASM technologies
Vulnerability management platforms

Job description

Introduction

To heal, to teach, to discover and to advance the health of the communities we serve.

Overview

Montefiore is ranked among the top hospitals nationally and regionally by U.S. News & World Report. For more than 100 years we have been innovating new treatments, procedures, and approaches to patient care, producing stellar outcomes and raising the bar for academic medical centers in the region and around the world. Our work to improve health outcomes in underserved communities is unparalleled in the United States. Our workforce is among the most diverse in the US: Montefiore associates speak 60+ languages.

As a Cybersecurity Engineer in Montefiore Technology, you directly support patient safety, clinical operations, and the protection of sensitive health information. This role provides the opportunity to work deeply with modern security technologies while contributing to our mission-driven organization where cybersecurity is essential to care delivery.

Responsibilities
  • Work with architecture and engineering personnel to implement automation and orchestration solutions where appropriate to improve efficiency and reduce manual effort.
  • Collaborate with IT, clinical teams, and other departments to ensure cybersecurity measures are integrated into everyday operations without disrupting patient care.
  • Manage vendor relationships related to security solutions, testing services, and consulting engagements.
  • Maintain security tools and services ensuring continued uptime and efficient execution of scanning activities.
  • Work with DevOps, cloud, and IT infrastructure teams to incorporate secure development practices and vulnerability remediation into their workflows.
  • Perform continuous device and asset discovery across IT, cloud, medical, and IoT/OT environments using approved ASM tooling.
  • Review and validate asset discovery and vulnerability findings to identify unmanaged, unknown, or misclassified assets.
  • Correlate exposure and vulnerability data with CMDBs, internal inventories, and cloud asset repositories to improve accuracy.
  • Support the enterprise vulnerability management lifecycle by tracking findings from identification through remediation.
  • Apply risk-based vulnerability prioritization using exploitability, asset criticality, and business impact.
  • Coordinate with system, application, and device owners to validate their proposed remediation actions and timelines.
  • Review third‑party penetration testing results and assist with remediation tracking and validation.
  • Collaborate with SOC and incident response teams to contextualize vulnerabilities during investigations.
  • Develop and maintain technical documentation, SOPs, and workflows related to ASM processes.
  • Contribute to dashboards, KPIs, and reporting that measure attack surface coverage, vulnerability aging, and risk reduction.
  • Monitor vulnerability and threat trends relevant to healthcare and emerging technologies.
  • Assist with automation and orchestration initiatives to improve ASM efficiency under manager guidance.
Requirements
  • Bachelor's degree or equivalent work experience.
  • 4‑6 years’ Cybersecurity or IT experience with progression from vulnerability analysis, exposure management, or ASM analyst functions.
  • 4‑6 years’ prior experience in highly regulated environments.
  • Strong proficiency with asset discovery and attack surface management technologies across on‑prem IT, cloud, and IoMT environments.
  • Strong ability to interpret, validate, and assess findings from attack surface management (ASM) and vulnerability management platforms.
  • Strong understanding of the vulnerability management lifecycle, including remediation processes and governance requirements.
  • Foundational experience correlating data across CMDBs, cloud inventories, and security tools.
  • Ability to communicate technical findings to non‑technical stakeholders with guidance.
  • Working knowledge of healthcare cybersecurity frameworks including HIPAA, HITECH, NIST CSF, HITRUST, HICP, and NYSDOH 405.46.
  • Strong analytical skills with attention to detail and data accuracy.
  • Ability to operate effectively within defined processes and escalate appropriately.

Preferred:

  • Prior experience in healthcare.
  • One of the following certifications required or obtained within 18 months of hire:
    • CompTIA PenTest+
    • GIAC Security Essentials (GSEC)
    • Tenable Certified Nessus Auditor (TCNA)
    • CREST Registered Vulnerability Specialist (RVS)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer (JR229560)
Cybersecurity Engineer (JR229560)

ViziRecruiter,LLC. • Village of Elmsford (NY)

On-site
USD 80,000 - 100,000
Attack Surface Engineer - Cloud & Vulnerability Automation
Attack Surface Engineer - Cloud & Vulnerability Automation

ViziRecruiter,LLC. • Village of Elmsford (NY)

On-site
USD 90,000 - 130,000
Cybersecurity Engineering Manager
Cybersecurity Engineering Manager

Montefiore Health System • New York (NY)

On-site
USD 136,000 - 170,000
Cybersecurity Engineering Manager
Cybersecurity Engineering Manager

2000 Montefiore Health System, Inc. • Town of Greenburgh (NY)

On-site
USD 136,000 - 170,000
Clinical Engineering Cybersecurity Specialist
Clinical Engineering Cybersecurity Specialist

Confidential Recruiting Partners • New York (NY)

On-site
USD 120,000 - 180,000
Paid time off
Paid holidays
401(k) with match
+4
Senior Infrastructure Security Engineer
Senior Infrastructure Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 87,000 - 161,000
Health insurance
401K & stock purchase
Tuition reimbursement
+2
Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

CHS Corporate • United States

On-site
USD 140,000 - 190,000
Network Engineer MIT (JR230570)
Network Engineer MIT (JR230570)

ViziRecruiter,LLC. • City of Yonkers (NY)

On-site
USD 90,000 - 120,000
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth Corporate Support Center • Louisville (KY)

On-site
USD 180,000 - 240,000
Information Technology Security Manager
Information Technology Security Manager

Wheeler Staffing Partners • Dallas (TX)

Hybrid
USD 120,000 - 140,000