Who we're looking for:
We are seeking a results oriented Senior Attack Surface Management Engineer for a potential opportunity to identify, analyze and reduce cyber exposure across enterprise infrastructure, applications and connected environments. The ideal candidate will understand how to evaluate external and internal attack surfaces, prioritize exposure reduction and partner with operations and engineering teams to improve defensive posture. The Sr. Attack Surface Management Engineer role collaborates across technical teams to track exposure related findings, analyze threat relevance and support the closure of identified security gaps across Information Technology (IT) and Operational Technology (OT) assets. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract.
What you'll be doing:
- Identify and assess attack surface exposure across systems, services, assets and externally reachable resources.
- Support risk assessments and help prioritize remediation activities based on threat relevance, environment analysis and mission impact.
- Partner with threat hunting, vulnerability management and engineering teams to integrate threat intelligence and identify coverage gaps and exposure trends.
- Recommend and support implementation of technical controls and protections that reduce exploitability and improve resilience.
- Contribute to security assessments, authorized defensive security exercises and gap analyses related to data coverage and detection effectiveness. (
- Track exposure related findings, document relevant risks and help measure the closure of identified security gaps and detection improvements.
What you need to know:
- Experience in attack surface management, exposure analysis, vulnerability prioritization or related security engineering disciplines.
- Familiarity with how adversaries leverage weaknesses across infrastructure, identity, applications and network pathways.
- Strong analytical skills and ability to prioritize remediation based on risk.
- Experience collaborating across cyber operations, engineering and compliance teams.
- Strong documentation and reporting skills.
Must have's:
- Bachelor's degree from an accredited university; a postgraduate degree from an accredited university may substitute for 6 years of experience.
- 10+ years of relevant work experience.
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.
Beneficial to have:
- Active DOE Q or equivalent DoD Top Secret clearance.
Where it's done:
- Onsite (Albuquerque, NM).