Threat Exposure, Attack Surface Analyst

Job not on LinkedIn

🔥 2 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of True Zero Technologies, LLC

True Zero Technologies, LLC

11 - 50 employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

True Zero Technologies, LLC is a veteran-owned company specializing in cybersecurity solutions. The company offers a range of services including security engineering and architecture, emerging technology adoption, cyber operations, cyber threat intelligence, penetration testing, and information assurance. True Zero is also recognized for its managed services and cloud security capabilities. The company partners with technology leaders such as Tanium, Splunk, Cribl, and Zscaler to deliver high-impact, high-value solutions that help organizations innovate while enhancing their security and operational programs. True Zero is committed to empowering organizations with actionable insights to secure their IT environments effectively.

📋 Description

• Analyze enterprise vulnerability data to identify the highest priority cyber exposures across the NIH environment • Maintain awareness of CISA Known Exploited Vulnerabilities (KEVs), emerging threats, and active adversary campaigns affecting NIH systems • Correlate vulnerability findings with threat intelligence, exploit availability, attack techniques, and operational risk to improve remediation prioritization • Evaluate the enterprise attack surface, identify high value targets, and assess how infrastructure, cloud services, identities, or external exposure changes influence organizational risk • Validate penetration testing findings and determine whether vulnerabilities create realistic attack paths or opportunities for privilege escalation and lateral movement • Assess compensating controls and remediation effectiveness • Recommend remediation priorities based on exploitability, mission impact, and threat activity • Collaborate with incident responders, penetration testers, ISSOs, and security engineers to refine enterprise risk prioritization • Develop technical analyses, exposure assessments, executive summaries, and operational reporting • Support RMF activities with technical justification for POA&M prioritization, risk acceptance decisions, and continuous monitoring • Recommend improvements to attack surface management, threat-informed vulnerability prioritization, and enterprise exposure management processes • Coordinate day-to-day RMF activities, maintain security documentation, support continuous monitoring, track remediation efforts, and align cybersecurity activities with Federal requirements

🎯 Requirements

• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline • Three or more years of experience supporting vulnerability management, attack surface management, cyber threat intelligence, penetration testing, security operations, or enterprise risk analysis • Experience analyzing vulnerability data and translating technical findings into operational risk • Working knowledge of CVSS, CVEs, CISA Known Exploited Vulnerabilities (KEV), MITRE ATT&CK, and modern threat intelligence methodologies • Understanding of attack paths, identity-based attacks, lateral movement, privilege escalation, and common adversary TTPs • Familiarity with NIST RMF, FISMA, and Federal cybersecurity practices • Strong analytical, investigative, and technical writing skills • Preferred: Experience supporting NIH, HHS, or other Federal civilian agencies • Preferred: Experience with Tenable, Qualys, Rapid7, Armis, CrowdStrike Exposure Management, Microsoft Defender, ServiceNow, or similar enterprise security platforms • Preferred: Experience supporting penetration testing activities and remediation validation • Preferred: Experience with EASM, CAASM, or exposure management platforms • Preferred: Familiarity with cloud security, Zero Trust, and enterprise architecture concepts • Preferred: Experience supporting continuous monitoring, RMF, and POA&M management • Preferred certifications include GCVA, GPEN, GDAT, CompTIA CySA+, CEH, or Security+

🏖️ Benefits

• Competitive salary, paid twice per month • Best in class medical coverage • 100% of medical premiums covered by True Zero • Company wide new business incentive programs • Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.) • 3 weeks of PTO starting + 11 Paid Holidays Annually • 401k Program with 100% company match on the first 4% • Monthly reimbursement of Cell Phone and Home Internet costs • Paternity/Maternity Leave • Investment in training and certifications to broaden and deepen your technical skills

Apply Now

Similar Jobs

🔥 47 minutes ago

The Cigna Group

10,000+ employees

🏥 Healthcare

🛡️ Insurance

Risk Adjustment Quality Analyst reviewing medical records, HCC coding, and CMS compliance for Cigna Healthcare. Auditing data and supporting compliant health-plan risk-adjustment programs.

🇺🇸 United States – Remote

💵 $25 - $38 / hour

⏰ Full Time

🟢 Junior

🟡 Mid-level

🧐 Analyst

🚫👨‍🎓 No degree required

🔥 3 hours ago

Liberty Dental Plan

1001 - 5000

🏥 Healthcare

💼 Consulting

📦 Logistics

IT Operational Analyst improving Liberty Dental Plan’s business systems and technology operations. Translating stakeholder needs into technical solutions and supporting continuous process improvement remotely across the United States.

🔥 5 hours ago

Cadence

10,000+ employees

🔧 Hardware

☁️ SaaS

🤖 Artificial Intelligence

Epic Willow Analyst optimizing ambulatory pharmacy applications for Health Choice Network. Supporting outpatient, retail, specialty pharmacy, and 340B operations through configuration, integrations, testing, and user support.

🔥 9 hours ago

Evri

5001 - 10000

📦 Logistics

🚗 Transport

🛍️ eCommerce

IT Request Fulfilment Analyst managing service requests, hardware provisioning, assets, and supplier coordination for Evri. Improving IT service performance through ServiceNow, SLA management, reporting, and accurate CMDB records.

🔥 10 hours ago

Kodiak Cakes

51 - 200

🍽️ Food & Beverage

🛍️ eCommerce

👥 B2C

Trade Analyst managing receivables, deductions, collections, and trade finance workflows for Kodiak’s CPG business. Supporting sales and operations through reporting, dispute resolution, and process automation.

🇺🇸 United States – Remote

💵 $62k - $72k / year

💰 Series unknown on 2022-03

⏰ Full Time

🟡 Mid-level

🟠 Senior

🧐 Analyst