Vulnerability & Attack Surface Management Analyst II

Hidden Jobs

United States

Hybrid

USD 110,000 - 160,000

Full time

44 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible spending account
Health savings account
Hybrid work flexibility
Generous PTO

Job summary

Hidden Jobs is seeking a security operations professional to own vulnerability and attack surface management for a HIPAA-regulated healthcare org. This full-time role focuses on reducing a large backlog of findings, coordinating with engineering to ship fixes, and maturing base images and CI/CD security controls.

You will lead cloud, container, and web application security, using CVSS/EPSS, and drive remediation with cross-functional teams across cloud, endpoints, and SaaS.

Qualifications

  • Minimum 3–6 years in security with hands-on vulnerability management experience.
  • Direct experience operating and tuning a vulnerability scanner or CNAPP platform.
  • null],
  • job_responsibilities_description
  • CoT_job_summary_short
  • job_summary_short
  • contract_type
  • location_type
  • remote_scope
  • perks
  • stated_min
  • stated_max
  • stated_absolute
  • salary_estimation_cot
  • estimated_low
  • estimated_medium
  • estimated_high
  • currency
  • frequency
  • bonus
  • tax
  • application_email
  • job_end_date
  • contact_person
  • hiring_department_name

Responsibilities

  • Run the full vulnerability lifecycle across cloud workloads, containers, code repos, and endpoints.
  • Prioritize findings using a risk model with CVSS/EPSS and data sensitivity.
  • Build and maintain a unified asset inventory across cloud, endpoint, and SaaS.
  • Drive remediation by coordinating with engineering and IT teams.
  • Address root causes via hardened images and automated tooling.
  • Lead web app security, including dynamic scans and WAF mitigations.
  • Stand up checks for an internal app publishing platform.

Skills

Vulnerability management
Attack surface management
Cloud security basics
Scripting (Python/PowerShell)
Risk-based prioritization
Engineering collaboration
AI in security workflows

Education

Bachelor's degree in CS or related field

Tools

Wiz
Orca
Prisma Cloud
Defender for Cloud
Lacework
CrowdStrike Falcon Exposure Management
Tenable
Qualys
Rapid7
Axonius
runZero

Job description

Role overview

This is a newly created, full-time position on a security operations team that protects patient data and clinical systems for a healthcare organization subject to HIPAA. You will be the first person dedicated to vulnerability and attack surface management, owning the day-to-day program while reporting to a Director who sets strategy. Success looks like shrinking a large, fast-growing finding backlog into the handful of issues that actually matter and verifying that fixes have landed.

Responsibilities
  • Run the full vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, from discovery through verification.
  • Prioritize findings using a risk model that weighs internet exposure, exploitability signals like CISA KEV and EPSS, asset criticality, and data sensitivity, and document when items are deliberately deferred.
  • Build and maintain a unified asset inventory spanning cloud, endpoint, and SaaS, ensuring every meaningful asset has a named owner.
  • Drive remediation through engineering, IT, and platform teams by writing actionable tickets, agreeing on timelines, escalating blockers, and confirming fixes.
  • Address root causes through hardened base images, dependency baselines, and automation that connects scanner and CNAPP APIs to ticketing and reporting.
  • Lead web application security, including dynamic scans, edge and WAF mitigations, and tracking for vulnerability disclosure or bug bounty reports.
  • Stand up security checks for an internal application publishing platform so internally built, externally published apps are inventoried and scanned.
Requirements
  • 3 to 6 years in security, with hands-on time in vulnerability management, attack surface management, or cloud security posture.
  • Direct experience operating and tuning a vulnerability scanning or CNAPP platform, not only reading its output.
  • Practical risk-based prioritization skills, with working fluency in CVSS, EPSS, and the CISA KEV catalog and an opinion on how they combine.
  • Cloud security fundamentals in at least one major provider, ideally GCP or AWS, including container and dependency or SCA findings in code.
  • Comfort working from an incomplete inventory and figuring out what exists and who owns each asset.
  • A track record of working directly with engineering teams to ship fixes, plus scripting skills in Python, PowerShell, or similar to query APIs and automate reporting.
  • Hands-on use of AI assistants in security work, with concrete examples and discipline around what data is safe to share.
Nice to have
  • Specific experience with Wiz, or comparable CNAPP and VM platforms such as Orca, Prisma Cloud, Defender for Cloud, Lacework, CrowdStrike Falcon Exposure Management, Tenable, Qualys, or Rapid7.
  • Attack surface and CAASM tooling such as Axonius or runZero, plus external discovery techniques including DNS, certificate transparency, and subdomain enumeration.
  • DAST and edge or WAF platforms like Invicti, Burp Suite, Cloudflare, or Akamai, and experience running a vulnerability disclosure or bug bounty program.
  • Hardened base image programs, Kubernetes and container security at scale (GKE or EKS), PaaS or edge hosting, SBOMs, and supply chain security work.
  • Regulated industry experience with HIPAA, HITRUST, or SOC 2, especially supplying vulnerability evidence to auditors and customers.
  • Relevant certifications such as GCLD, GCPN, GWEB, GSEC, cloud security specialty, or OSCP.
Benefits and work setup
  • Competitive compensation
  • Medical, dental, and vision coverage
  • Flexible spending and health savings accounts
  • Generous PTO with hybrid work flexibility
  • 401(k) with company match
  • Life insurance, pet insurance, and additional benefits
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop Health • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Group 1001 • United States

On-site
USD 190,000 - 230,000
Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 80,000 - 100,000
Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
+1
Vulnerability management Consultant
Vulnerability management Consultant

Tata Consultancy Services • Charlotte (NC)

On-site
USD 110,000 - 150,000
Discretionary Annual Incentive
Medical Coverage
Parental Leaves
+2
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000
Vulnerability Management Lead
Vulnerability Management Lead

K2United • Washington

On-site
USD 120,000 - 180,000
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation

New York Life • New York (NY)

On-site
USD 147,500 - 211,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

United States Digital Space LLC • Seattle (WA), San Francisco (CA)

On-site
USD 110,000 - 150,000
Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Holdings, Inc. • Cincinnati (OH)

Hybrid
USD 85,000 - 125,000
Medical insurance
Dental insurance
Life insurance
+7