Senior Attack Surface Testing SME

CACI

United States

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CACI is seeking a Senior Attack Surface Testing SME to lead continuous assessment of federal cyber assets. You will design safe enumeration approaches, guide junior engineers, and deliver rapid remediation guidance.

Focus is on .gov domains, subdomains, and internet-facing assets to uncover exposures and provide actionable remediation to agencies. The role supports CDM program objectives, requiring strong automation, cloud pattern knowledge, and experience with large-scale production

Qualifications

  • Five+ years in attack-surface management, vulnerability assessment, external reconnaissance, or related fields.
  • Ability to lead continuous or large-scale assessment work and coach junior engineers.
  • Strong automation skills using Python, Go, Bash, APIs and CI/CD pipelines.

Responsibilities

  • Lead continuous attack-surface enumeration, vulnerability discovery, validation, change monitoring, triage, reporting, and remediation-support activities.
  • Design scan architecture, asset attribution logic, rate limits, credential handling, validation procedures, and deconfliction safeguards for large-scale production assessment.
  • Direct and mentor junior engineers; review findings, evidence, and remediation recommendations.
  • Prioritize risk using exposure, exploitability, KEV/EPSS, asset criticality, and mission impact.
  • Lead rapid analysis of newly exposed or high-risk assets and coordinate urgent notifications and closure validation.
  • Define automation requirements, data normalization, dashboards, AI-assisted triage, and integrations with customer tools.
  • Produce and approve recurring reports, trend analyses, high-risk findings, playbooks, SOPs, and customer briefings.

Skills

Attack surface mgmt
Vulnerability assessment
Leadership
Automation
Python
Cloud patterns

Tools

APIs

Job description

Job Title:

Senior Attack Surface Testing SME

Job Category:

Information Technology

Time Type:

Full time

Minimum Clearance Required to Start:

Public Trust

Employee Type:

Regular

Percentage of Travel Required:

Up to 10%

Type of Travel:

Continental US

The Opportunity:

CACI is seeking a Senior Attack Surface Testing subject‑matter expert to lead assigned continuous‑assessment operations for federal cyber assets. This SME designs safe enumeration and validation approaches, directs junior engineers, adjudicates high‑risk findings, and ensures rapid reporting and remediation guidance. This position works with the VM‑ASE Technical Lead, customer process owners, Cloud/DevOps specialists, and AI‑assisted analysis staff to deliver a repeatable, high‑confidence assessment service. This position will provide continuous technical assessment support for full‑time, proactive testing of externally and internally visible federal cyber assets. This expands federal visibility by conducting continual assessments of .gov domains, subdomains, and internet‑facing assets to uncover unknown exposures, validate vulnerabilities, and provide agencies with actionable remediation guidance. This role supports the Continuous Diagnostics and Mitigation (CDM) Program's mission to safeguard and secure cyberspace in an environment where the threat of cyber‑attack is continuously growing and evolving and is responsible for enhancing the security, resilience, and reliability of the Nation's cyber and communications infrastructure. The CDM Program defends the United States (U.S.) Federal Information Technology (IT) networks from cybersecurity threats by providing continuous monitoring sensors (tools), diagnosis, mitigation tools, and associated services to strengthen the security posture of Government networks.

Responsibilities:
  • Lead continuous attack‑surface enumeration, vulnerability discovery, controlled validation, change monitoring, triage, reporting, and remediation‑support activities.
  • Design scan architecture, asset‑attribution logic, rate limits, credential and API handling, validation procedures, and deconfliction safeguards for large‑scale production assessment.
  • Direct and mentor junior engineers; review findings, evidence, false‑positive determinations, attack paths, severity, and remediation recommendations.
  • Prioritize risk using exposure, exploitability, CISA KEV, EPSS, asset criticality, compensating controls, and mission impact rather than scanner severity alone.
  • Lead rapid analysis of newly exposed or high‑risk assets and coordinate urgent notifications, customer clarification, and closure validation.
  • Define requirements for automation, data normalization, dashboards, AI‑assisted triage, and integrations with customer tools and authoritative repositories.
  • Produce and technically approve recurring reports, trend analyses, high‑risk findings, playbooks, standard operating procedures, and customer briefings.
Qualifications:
Required:
  • U.S. citizenship is required.
  • The selected candidate must meet eligibility requirements for access to sensitive information and be able to obtain a Public Trust fitness determination (High Risk).
  • Ability to work in customer‑provided remote environments, use customer‑approved tools, and comply with rules of engagement, data‑handling requirements, evidence controls, deconfliction procedures, and stop‑work criteria.
  • Five or more years of attack‑surface management, vulnerability assessment, external reconnaissance, penetration testing, or exposure‑management experience, including leadership of continuous or large‑scale assessment work.
  • Deep knowledge of DNS, TLS/PKI, HTTP/S, TCP/IP , routing, service fingerprinting, cloud‑hosting patterns, asset attribution, scanner behavior, and manual vulnerability validation.
  • Experience designing safe high‑volume scanning and enumeration workflows with rate control, scope enforcement, evidence capture, false‑positive adjudication, and operational deconfliction.
  • Strong automation and integration skills using Python, Go, Bash, APIs, structured data, source control, and repeatable pipelines.
  • Demonstrated ability to lead technical staff, make defensible risk decisions, write high‑quality reports, and brief technical and senior stakeholders.
  • One or more relevant certifications such as OSCP, OSEP/OSCE, GPEN, GXPN, CISSP, GCIH, cloud‑security certifications, or equivalent .
Desired:
  • Eight or more years in attack‑surface, offensive‑security, vulnerability‑management, or internet‑measurement roles.
  • Experience with federal .gov attack‑surface monitoring, coordinated vulnerability disclosure, critical infrastructure, or high‑value assets.
  • Advanced use of certificate‑transparency, passive DNS, BGP/ASN, internet telemetry, cloud inventories, and exposure‑management data sources.
  • Experience integrating findings with SIEM/data‑lake, ticketing, visualization, or threat‑intelligence platforms.
  • AWS, Terraform, Ansible, CI/CD, container, or IaC‑security experience sufficien
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Attack Surface Testing SME
Senior Attack Surface Testing SME

Visa Hunt • United States

On-site
USD 90,000 - 190,000
Attack Surface Testing SME Lead
Attack Surface Testing SME Lead

CACI International Inc. • United States

Remote
USD 90,000 - 190,000
Senior Attack Surface Testing Lead - Automation & Security
Senior Attack Surface Testing Lead - Automation & Security

Visa Hunt • United States

On-site
USD 90,000 - 190,000
Senior Attack Surface Engineer — Federal CDM Lead
Senior Attack Surface Engineer — Federal CDM Lead

CACI • United States

On-site
USD 120,000 - 180,000
Senior Red Team Operator / SME
Senior Red Team Operator / SME

CACI • United States

On-site
USD 190,000 - 270,000
Senior Penetration Tester & Assessments Lead
Senior Penetration Tester & Assessments Lead

Visa Hunt • United States

On-site
USD 90,000 - 190,000
Senior Red Team Operator / SME
Senior Red Team Operator / SME

NEPSE Trading • Northern (KY)

Hybrid
USD 120,000 - 180,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International • Colorado Springs (CO)

On-site
USD 140,000 - 190,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 160,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

accenturefederalservices • United States

On-site
USD 110,000 - 150,000