Attack Surface Management Lead

3M

Austin (TX)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Relocation Assistance
Opportunity to transition from varied experience

Job summary

A leading technology company is seeking an Attack Surface Management Lead to oversee the enterprise-wide ASM strategy. The ideal candidate will have a background in cybersecurity and leadership experience in managing teams. Key responsibilities include defining ASM strategy, guiding a cross-functional team, and managing related vendor relationships. This role is based in Austin, TX and offers relocation assistance.

Qualifications

  • Seven years of experience in cybersecurity, with at least two years focused on ASM.
  • Proven leadership experience in security functions.

Responsibilities

  • Define and execute the enterprise Attack Surface Management strategy.
  • Lead and mentor a cross-functional ASM team.
  • Manage vendor relationships and toolsets supporting ASM.

Skills

Leadership
Cybersecurity
Communication Skills

Education

Bachelor's degree in cybersecurity or computer science

Tools

Randori
Censys
Shodan
Palo Alto Xpanse
Wiz
Qualys
Microsoft Defender TVM

Job description

Overview

Join to apply for the Attack Surface Management Lead role at 3M.

This position provides an opportunity to transition from other private, public, government or military experience to a 3M career.

The Impact You Will Make in this Role

The Attack Surface Management (ASM) Lead will drive the identification, analysis, and reduction of the organization's digital and physical exposure across cloud, on-prem, OT, and third-party environments. This role will lead the enterprise-wide ASM strategy, combining external threat visibility with internal exposure reduction, and will oversee related functions such as vulnerability management, asset discovery, and exposure monitoring.

Key Responsibilities
  • Define and execute the enterprise Attack Surface Management strategy across cloud, on-premises, and external environments.
  • Lead and mentor a cross-functional ASM team, including direct oversight of the Vulnerability Management (VM) and Threat Intel & Testing Manager.
  • Establish clear goals, success metrics, and maturity roadmaps for ASM including VM and Threat Intel & Testing functions.
  • Collaborate with IT, cloud, OT, and third-party risk teams to align ASM initiatives with organizational risk priorities.
  • Manage vendor relationships and toolsets supporting ASM, external scanning, and attack surface discovery platforms.
Technical
  • Lead efforts to map, monitor, and validate known and unknown assets, services, and digital exposures.
  • Implement continuous discovery and monitoring of exposed assets and services, including shadow IT, abandoned infrastructure, expired domains, and misconfigured cloud resources.
  • Develop and maintain asset classification and tagging strategies to support risk-based prioritization and contextual analysis.
  • Correlate ASM findings with threat intelligence feeds and vulnerability data to identify high-risk exposures and inform remediation efforts.
  • Define and implement processes for validation, triage, and escalation of ASM findings in coordination with vulnerability management and SOC teams.
  • Oversee integration of ASM platforms with SIEM/SOAR solutions (e.g., Sentinel, Splunk, ServiceNow) to automate alerting, ticketing, and response workflows.
  • Collaborate with security engineering and architecture teams to implement preventive controls, such as automated remediation, segmentation, or blocking of exposed services.
  • Analyze trends and patterns in exposure data to identify systemic issues, control gaps, and architectural weaknesses.
Organizational
  • Translate ASM insights into business risk terms and influence remediation priorities with stakeholders.
  • Report attack surface trends, exposure metrics, and risk posture to senior leadership and governance forums.
  • Collaborate with Security Architecture and GRC to integrate ASM outputs into risk registers and architectural reviews.
  • Ensure ASM-related processes and reporting support regulatory, compliance, and audit requirements.
Your Skills and Expertise

To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications:

  • Bachelor's degree in cybersecurity or computer science (completed and verified prior to start) from an accredited university.
  • Seven (7) years of experience in cybersecurity, with at least 2 years focused on ASM, external threat management, or exposure reduction in a private, public, government or military environment.

Additional qualifications that could help you succeed even further in this role include:

  • Proven leadership experience managing security functions and personnel, ideally including vulnerability management.
  • Strong understanding of enterprise architectures, networking, cloud environments (Azure, AWS, GCP), and OT/IoT systems.
  • Experience with ASM tools (e.g., Randori, Censys, Shodan, Palo Alto Xpanse) and vulnerability platforms (e.g., Wiz, Qualys, Microsoft Defender TVM).
  • Familiarity with threat modeling frameworks, MITRE ATT&CK, and risk-based prioritization methodologies.
  • Strong verbal and written communication skills, including experience presenting to executives and technical stakeholders.
  • Strong leadership and people management skills with cross-functional influence.
  • Deep understanding of ASM concepts, tools, and exposure management lifecycle.
  • Experience managing or integrating vulnerability management functions.
  • Expertise in asset discovery, external reconnaissance, and attack path mapping.
  • Ability to translate technical risks into business impacts.
  • Familiarity with hybrid infrastructure (cloud, on-prem, OT, third-party).
  • Knowledge of security architecture principles and IT/OT convergence challenges.
  • Skilled in vendor evaluation, tool selection, and capability building.
  • Competence in data analysis and reporting using dashboards or BI tools.
  • Excellent documentation and communication skills, with a focus on executive reporting and technical clarity.

Work location: On site in Austin TX

Travel: May include up to 10% domestic and international

Relocation Assistance: Is Authorized

Must be legally authorized to work in country of employment without sponsorship for employment visa status (e.g., H1B status).

3M does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remediation Oversight Analyst
Remediation Oversight Analyst

National Black MBA Association • Maplewood (MN)

On-site
USD 165,000 - 201,000
Security Analyst Consultant - Attack Surface Management
Security Analyst Consultant - Attack Surface Management

Kallesgroup • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical, Dental, Vision plans
401(k) with matching
PTO for salaried employees
+1
Cybersecurity Service and Change Management Lead
Cybersecurity Service and Change Management Lead

3M • Minnesota

On-site
USD 164,000 - 202,000
Senior Security Analyst
Senior Security Analyst

confiz • United States

On-site
USD 120,000 - 150,000
Advanced OT System Specialist
Advanced OT System Specialist

National Black MBA Association • Irvine (CA), Northern (KY)

Hybrid
USD 165,000 - 201,000
Security Analyst Consultant - Attack Surface Management
Security Analyst Consultant - Attack Surface Management

Kalles Group • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical plan
Dental plan
Vision plan
+2
Senior Authentication Services Engineer
Senior Authentication Services Engineer

3M • Maplewood (MN)

On-site
USD 146,000 - 178,000
Senior Authentication Services Engineer
Senior Authentication Services Engineer

3M • Minnesota

On-site
USD 145,000 - 179,000
Medical
Dental & Vision
Health Savings Accounts
+3
Senior Software Engineer, AWS Cloud
Senior Software Engineer, AWS Cloud

3M • Minnesota

On-site
USD 146,000 - 178,000
Attack Surface Analyst 2
Attack Surface Analyst 2

Jobtailor • Seattle (WA)

On-site
USD 120,000 - 160,000