Senior Security Analyst

confiz

United States

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Confiz is seeking a Lead Attack Surface Analyst to enhance the organization’s security posture. You will lead the Attack Surface Management program, ensuring efficient risk prioritization and proactive remediation of vulnerabilities.

Responsibilities include collaborating with various teams to implement security best practices and driving the automation of processes. The ideal candidate will possess strong cybersecurity operations experience and a deep understanding of attack surface management methodologies.

Qualifications

  • 6+ years of experience in cybersecurity operations, red teaming, or threat hunting.
  • Deep understanding of the MITRE ATT&CK framework and common attack vectors.
  • Familiarity with offensive security methodologies and ethical hacking.

Responsibilities

  • Lead the evolution of the Attack Surface Management program and implement scalable solutions.
  • Drive continuous improvement of ASM processes with a focus on automation.
  • Collaborate with teams to refine processes and support investigations.

Skills

Cybersecurity operations
Attack surface management
Vulnerability management
Cloud security
Network security
Scripting (Python, PowerShell)
Incident Response

Education

Bachelor’s or Master’s degree in Information Technology, Computer Science, or Cybersecurity

Tools

OSINT methodologies
Cloud platforms (AWS, Azure, GCP)

Job description

Confiz is seeking a Lead Attack Surface Analyst to drive the reduction of the organization’s attack surface through continuous visibility, risk prioritization, and proactive remediation of vulnerabilities and exposures. This role works closely with cybersecurity and technology teams to identify, elevate, and mitigate high-risk issues while advancing automation and secure‑by‑design practices across the technology landscape. The ideal candidate will play a key role in strengthening the Attack Surface Management program and enhancing overall security posture.

Responsibilities
  • Lead the evolution and expansion of the Attack Surface Management (ASM) program, identifying gaps and implementing scalable solutions and new capabilities.
  • Drive continuous improvement of ASM processes, methodologies, and toolsets, with a strong focus on automation and operational efficiency.
  • Develop and maintain cybersecurity standards, ASM procedures, and operational runbooks.
  • Collaborate with Incident Response teams to refine processes and actively support investigations and mitigation efforts.
  • Partner with Application Security, DevOps, and Cloud teams to embed security best practices into system and software design.
  • Maintain a comprehensive and continuously updated map of the organization’s attack surface through OSINT, reconnaissance, and dark web monitoring.
  • Lead enterprise-wide, risk-prioritized initiatives to reduce vulnerabilities and exposures, including recommending architectural improvements.
  • Define, track, and present key metrics to measure attack surface risk and operational performance.
  • Automate workflows and integrate security tools to enhance efficiency and scalability.
  • Contribute to team development through mentorship, knowledge sharing, and training initiatives.
  • Lead compliance activities, including control validation, evidence collection, and support for audits (PCI, SOC 2).
  • Stay current with emerging threats, technologies, and industry practices through continuous learning and professional development.
Requirements
  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
  • 6+ years of experience in cybersecurity operations, red teaming, or threat hunting.
  • Deep understanding of the MITRE ATT&CK framework, threat actor tactics, techniques, and procedures (TTPs), and common attack vectors.
  • Strong expertise in attack surface management, vulnerability management, cloud security, network security, and cyber hygiene.
  • Experience implementing security controls across multi-cloud environments (AWS, Azure, GCP).
  • Advanced knowledge of enterprise IT architecture, networking, system administration, and data flows across systems.
  • Proficiency in scripting and automation (Python, PowerShell) to enhance operational efficiency.
  • Hands‑on experience with OSINT and reconnaissance methodologies.
  • Familiarity with offensive security methodologies and ethical hacking practices.
  • Strong understanding of regulatory and compliance frameworks (PCI, SOC 2) and associated controls.
  • Experience developing and scaling attack surface management capabilities, including mentoring junior analysts.
  • Knowledge of integrating security into CI/CD pipelines and modern DevSecOps practices.
  • Strong leadership, communication, and stakeholder management skills.
  • Preferred certifications: OSCE, GREM, CISSP.
  • Awareness of emerging technologies, including the application of AI within the attack surface management domain.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst Consultant - Attack Surface Management
Security Analyst Consultant - Attack Surface Management

Kallesgroup • Seattle (WA)

On-site
USD 110,000 - 140,000
Medical, Dental, Vision plans
401(k) with matching
PTO for salaried employees
+1
Lead Attack Surface Architect
Lead Attack Surface Architect

confiz • United States

On-site
USD 120,000 - 150,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Attack Surface Analyst 2
Attack Surface Analyst 2

Jobtailor • Seattle (WA)

On-site
USD 120,000 - 160,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Senior Attack Surface Management Engineer
Senior Attack Surface Management Engineer

ShorePoint • Albuquerque (NM)

On-site
USD 140,000 - 170,000
PTO 144 hours
11 holidays
Health insurance
+3
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Cybersecurity Associate
Senior Cybersecurity Associate

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000