Source Job

US 3w PTO

  • Analyze enterprise vulnerability data to identify the highest priority cyber exposures across the NIH environment.
  • Correlate vulnerability findings with threat intelligence, exploit availability, and operational risk to improve remediation prioritization.
  • Collaborate with incident responders, penetration testers, and security engineers to refine enterprise risk prioritization.

Vulnerability Management Threat Intelligence Penetration Testing Risk Analysis NIST RMF

20 jobs similar to Threat Exposure & Attack Surface Analyst

Jobs ranked by similarity.

United States

  • Lead complex Global Vulnerability Management workstreams to advance Threat Exposure Management capabilities and transition to a Continuous Threat Exposure Management model.
  • Conduct hands-on vulnerability research, technical analysis, and security validation to eliminate false positives, characterize exploitability, and provide actionable remediation guidance.
  • Partner across Information Security and engineering teams to evolve platforms, integrations, and automation for improved discovery, prioritization, and remediation outcomes.

Sony Interactive Entertainment (SIE) is the company behind the PlayStation brand, delivering innovative gaming hardware and network services to over 100 million people worldwide. As a subsidiary of Sony Group Corporation, SIE is a dynamic and entertainment-focused organization that values innovation, excellence, and employee empowerment.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

$86,000–$96,000/yr
US

  • Conduct vulnerability assessments using tools like Tenable, Qualys, and Burp to identify security weaknesses.
  • Analyze scan results and produce detailed reports with remediation recommendations.
  • Collaborate with technical teams to ensure timely delivery of assessment results and effective risk reduction.

The company provides cybersecurity services including vulnerability assessment and risk management. It fosters a collaborative remote environment focused on continuous learning and professional growth.

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.

$105,000–$155,000/yr
US

  • Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
  • Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
  • Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.

The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.

US

  • Manage the vulnerability management program end-to-end, including scanning and remediation.
  • Collaborate with developers on secure architecture, threat modeling, and code dependency reviews.
  • Oversee bug bounty programs, security tools, incident response, and compliance frameworks.

RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.

US

  • Responsible for daily incident management of customer incidents, including incident response and forensic analysis of compromised systems.
  • Formulate and direct incident response efforts, prioritize response actions, and create legible incident reports describing compromise vectors and attacker methodologies.
  • Build and maintain incident response plans, playbooks, and sandbox/test lab environments to evaluate malicious code.

We protect over 100,000 organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation with a prevention-first approach. We are recognized by TIME, Newsweek, and Forbes for our excellence and workplace culture, and we value ownership, curiosity, and solving complex problems.

US

  • Perform incident response and forensic analysis of compromised systems, identifying and recommending remediation.
  • Formulate and direct incident response efforts, prioritizing actions and creating detailed reports on compromise vectors and attacker methodologies.
  • Build incident response plans, playbooks, and attack scenarios for customer tabletop exercises, maintaining sandbox environments to evaluate malicious code.

Check Point Software Technologies is the world's leading vendor of cyber security, facing sophisticated threats and attacks. Honored by Time Magazine as one of the World's Best Companies and on Forbes' list of the World's Best Places to Work, we have a global team of driven and innovative people.

$120,000–$140,000/yr
US Unlimited PTO

  • Define and enforce security requirements for software products, features, and components.
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
  • Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.

symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.

US Unlimited PTO

  • Develop differentiated product messaging and positioning for VulnCheck's exploit intelligence products.
  • Lead go-to-market launches and create sales enablement content like solution briefs and battlecards.
  • Conduct market intelligence and competitive analysis to inform strategy and support the sales team.

VulnCheck is The Exploit Intelligence Company, delivering structured exploit intelligence for cybersecurity infrastructure. Founded in 2021, the company has a transparent, collaborative culture and values growth, curiosity, and innovation.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

$105,000–$130,000/yr
US

  • Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
  • Perform gap analyses of current environments and recommend remediation steps.
  • Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.

CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.

US

  • Provide advanced cybersecurity expertise to support secure system operations and compliance initiatives.
  • Analyze system designs and architectures to ensure appropriate security controls and protection mechanisms.
  • Collaborate with technical teams and security organizations to align priorities and security objectives.

The partner company is a mission-driven organization that strengthens cybersecurity capabilities for critical information systems. It offers a collaborative culture with opportunities for professional growth and impactful work.

Ireland UK

  • Maintain the ability to identify, investigate, and manage threats of violence toward global offices, executives, and employees.
  • Utilize evidence-based risk assessment tools and conduct research using open-source intelligence and other resources.
  • Collaborate with internal teams and external partners to develop and manage case life cycles and provide actionable threat assessments.

Concentric is a risk consultancy specializing in delivering strategic security and intelligence services to private clients and corporations globally. The company is comprised of elite professionals from military, government, and intelligence backgrounds and operates with core values of integrity, collaboration, and excellence.

Canada

  • Support cybersecurity operations by monitoring threats, improving security controls, and protecting systems and data.
  • Respond to security incidents, analyze threats, and assist with vulnerability management and remediation.
  • Collaborate with technical and business teams to assess risks and implement effective security solutions.

The company is a large, technology-driven organization focused on cybersecurity. It offers a collaborative environment with experienced security professionals and an inclusive workplace culture.

$121,000–$181,600/yr
United States Canada

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
  • Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.

Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments, grow revenue, and accelerate new business opportunities. As a large, mission-driven company, Stripe fosters a culture of passion, grit, and integrity with diverse perspectives.

US

  • Lead enterprise-wide response to high-risk cybersecurity incidents as Cyber Incident Commander, directing cross-functional efforts and driving containment to resolution.
  • Provide executive incident leadership by delivering updates to senior leaders and supporting decision-making during incidents.
  • Strengthen the incident response program through post-incident reviews, root cause analysis, and continuous improvements to response plans and playbooks.

Experian is a global data and technology company that powers opportunities for people and businesses across financial services, healthcare, automotive, and more. The company has a team of 25,200 employees in 32 countries and is known for its award-winning, people-first culture.

$78,300–$104,220/yr
Netherlands

  • Implement and enable Tenable's Exposure Management solutions to help organizations manage cyber risks.
  • Onboard Tenable technologies, following industry standards, to deliver customized solutions addressing vulnerabilities.
  • Provide consultative advice and build positive client relationships to ensure ongoing satisfaction and partnership.

Tenable is an exposure management company that helps organizations understand and reduce cyber risk. With over 40,000 clients globally, including 65% of the Fortune 500, the company fosters a culture of belonging, respect, and excellence.

$170,000–$170,000/yr
US

  • Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis.
  • Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to close gaps in the Dragos Platform's vulnerability detection.
  • Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits and integrating findings into broader threat intelligence.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.

US

  • Lead bug bounty program strategy and vulnerability management initiatives.
  • Collaborate with engineering and security teams to drive remediation efforts.
  • Conduct code reviews and develop security tooling to improve efficiency.

This company operates a global technology platform. It values security, collaboration, and continuous learning, with a team dedicated to protecting user privacy and safety.