Security Analyst Consultant - Attack Surface Management

Kallesgroup

Seattle (WA)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision plans
401(k) with matching
PTO for salaried employees
Work/life balance initiatives

Job summary

Kallesgroup is searching for a Senior Security Analyst Consultant specializing in Attack Surface Management in Seattle, WA. This role involves leading efforts to reduce cyber risks through proactive analysis and collaboration across teams.

The ideal candidate will have over 6 years of cybersecurity experience, strong understanding of vulnerability management, and expertise in cloud security and scripting. Kallesgroup offers a competitive salary along with benefits such as medical, dental, and a 401(k) plan.

Qualifications

  • 6+ years of experience in cybersecurity including security operations.
  • Experience building and leading Attack Surface Management programs.
  • Strong understanding of risk prioritization frameworks.
  • Deep knowledge of attacker tactics, techniques, and procedures.

Responsibilities

  • Lead and mature the organization's Attack Surface Management program.
  • Drive remediation efforts in partnership with engineering and security teams.
  • Monitor emerging threats and empower teams to strengthen security posture.
  • Mentor team members and share expertise across security domains.

Skills

Cybersecurity experience
Attack Surface Management
Vulnerability management
Cloud security (AWS, Azure, GCP)
Scripting (Python, PowerShell)

Tools

Threat intelligence tools
Security platforms

Job description

WHAT YOU WILL DO

As a Senior Security Analyst Consultant – Attack Surface Management, you will lead and evolve our client’s enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through proactive discovery, analysis, automation, and collaboration. This is a highly visible role that combines strategic leadership with hands‑on technical execution, requiring expertise across vulnerability management, cloud security, threat intelligence, and offensive security disciplines.

You will be responsible for developing a comprehensive view of the organization’s attack surface, identifying opportunities to reduce exposure, and driving remediation efforts in partnership with engineering, cloud, DevOps, and security teams. Leveraging data, automation, and threat intelligence, you will help prioritize risk‑reduction initiatives while influencing architectural decisions that strengthen the organization’s security posture. This role is ideal for someone who enjoys building programs, solving complex security challenges, and partnering across the enterprise to create meaningful security outcomes.

KEY RESPONSIBILITIES
  • Lead and mature the organization’s Attack Surface Management (ASM) program, identifying opportunities to expand capabilities and improve visibility
  • Develop and maintain a comprehensive understanding of the enterprise attack surface across cloud, network, and application environments
  • Continuously identify, assess, and prioritize vulnerabilities and exposures based on business and security risk
  • Partner with security, engineering, infrastructure, and cloud teams to drive remediation efforts and reduce risk
  • Leverage metrics and analytics to measure program effectiveness and inform risk‑based decision making
  • Conduct external reconnaissance activities, OSINT research, and threat intelligence analysis to identify potential exposure points
  • Monitor emerging threats, attacker techniques, and industry trends to proactively strengthen defensive capabilities
  • Collaborate with Application Security, DevOps, and Cloud Engineering teams to promote secure‑by‑design practices
  • Contribute to incident response investigations and post‑incident analysis as needed
  • Design and implement automation solutions that improve visibility, efficiency, and risk management workflows
  • Develop and maintain operational standards, procedures, documentation, and runbooks
  • Mentor team members and share expertise across security domains
  • Support compliance initiatives including PCI DSS, SOC 2, and related regulatory requirements
  • Validate security controls and identify opportunities for continuous improvement
ABOUT YOU
  • Your values:
    • Integrity: You believe in doing the right thing, even when it’s uncomfortable, seemingly inefficient, or costly.
    • Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
    • Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.
YOUR EXPERIENCE
Required Qualifications
  • 6+ years of experience in cybersecurity, including security operations, threat hunting, offensive security, red teaming, or related disciplines
  • Experience building, scaling, or leading Attack Surface Management (ASM) capabilities and programs
  • Strong understanding of vulnerability management methodologies and risk prioritization frameworks
  • Experience working within multi‑cloud environments, including AWS, Azure, and GCP
  • Deep knowledge of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK
  • Expertise in network security, cloud security, attack path analysis, and external attack surface discovery
  • Experience conducting OSINT, reconnaissance, and threat intelligence activities
  • Proficiency with scripting and automation technologies such as Python and PowerShell
  • Strong understanding of enterprise infrastructure, application architectures, and data flows
  • Ability to evaluate and influence architectural decisions that reduce organizational risk
  • Experience leading cross‑functional security initiatives and driving collaboration across multiple teams
  • Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non‑technical stakeholders
  • Strong analytical and problem‑solving skills with a data‑driven approach to risk management
Preferred Qualifications
  • Industry certifications such as CISSP, OSCE, GREM, or similar cybersecurity credentials
  • Experience applying AI and automation technologies to security operations or attack surface management programs
  • Experience with cloud‑native security platforms and exposure management tooling
  • Familiarity with threat modeling, purple teaming, or advanced adversary simulation exercises
  • Experience working in large‑scale enterprise environments with complex security requirements
WHAT WE OFFER
  • The annual salary range for this role is $110,000-$140,000.
  • We offer Medical, Dental, Vision plans, 401(k) with matching, and PTO for salaried employees.
  • Work/life balance – we know there’s more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload.
LOCATION

This role is on‑site at our client location in Seattle, WA. At this time, we are only considering candidates who currently live in Seattle, WA.

Contact us at talent@kallesgroup.com for any questions.

Kalles Group is an equal‑opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst Consultant - Attack Surface Management
Security Analyst Consultant - Attack Surface Management

Kalles Group • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical plan
Dental plan
Vision plan
+2
Senior Security Analyst
Senior Security Analyst

confiz • United States

On-site
USD 120,000 - 150,000
Senior ASM Program Lead & Security Architect
Senior ASM Program Lead & Security Architect

Kallesgroup • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical, Dental, Vision plans
401(k) with matching
PTO for salaried employees
+1
Senior Application Security Consultant
Senior Application Security Consultant

Kallesgroup • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical plans
Dental plans
Vision plans
+2
Senior Application Security Consultant
Senior Application Security Consultant

Kalles Group • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical coverage
Dental coverage
Vision coverage
+2
Senior Staff Information Security Engineer – AI & Attack Surface Management
Senior Staff Information Security Engineer – AI & Attack Surface Management

Palo Alto Networks, Inc. • Santa Clara (CA)

Hybrid
USD 151,000 - 246,000
Flexible work location
Work from home options
Senior Security Architect Consultant - Identity
Senior Security Architect Consultant - Identity

Kallesgroup • Seattle (WA)

On-site
USD 210,000 - 260,000
Work/life balance
Equal opportunity employer
Attack Surface Analyst 2
Attack Surface Analyst 2

Jobtailor • Seattle (WA)

On-site
USD 120,000 - 160,000
Attack Surface Management Lead
Attack Surface Management Lead

3M • Austin (TX)

On-site
USD 120,000 - 150,000
Relocation Assistance
Opportunity to transition from varied experience
Senior Security Analyst, Detection & Response
Senior Security Analyst, Detection & Response

Jobgether • United States

On-site
USD 100,000 - 130,000
Competitive salary
Senior cybersecurity role
Diverse environments and platforms
+3