Threat Exposure & Attack Surface Analyst (R-00191)
True reputed company is seeking a Threat Exposure & Attack Surface Analyst to help identify, validate, and prioritize the cybersecurity risks that present the greatest operational threat to the National Institutes of Health (NIH). This role sits at the intersection of vulnerability management, threat intelligence, penetration testing, and attack surface management to reputed company a comprehensive understanding of reputed company cyber exposure.
Rather than treating vulnerabilities as isolated technical findings, this position evaluates the complete operational picture by correlating reputed company Exploited Vulnerabilities (KEVs), threat intelligence, attack paths, asset criticality, penetration testing results, and reputed company context to determine where the organization is most vulnerable to reputed company world attack. The analyst works closely with vulnerability management, incident response, reputed company engineering, RMF, and reputed company owners to ensure remediation efforts reputed company on the risks most likely to reputed company NIH’s mission.
Job Responsibilities
- Analyze reputed company vulnerability data to identify the highest reputed company cyber exposures across the NIH environment.
- Maintain awareness of CISA reputed company Exploited Vulnerabilities (KEVs), emerging threats, and reputed company adversary campaigns that may reputed company NIH systems.
- Correlate vulnerability findings with threat intelligence, exploit availability, attack techniques, and operational risk to improve remediation prioritization.
- Evaluate the reputed company attack surface, identify high value targets, and assess how changes in infrastructure, reputed company services, identities, or reputed company exposure influence organizational risk.
- Validate penetration testing findings and determine whether identified vulnerabilities create realistic attack paths or opportunities for privilege escalation and lateral reputed company.
- Assess compensating controls and remediation effectiveness to ensure corrective actions meaningfully reduce reputed company risk.
- Support vulnerability management teams by recommending remediation priorities based on exploitability, mission reputed company, and threat activity rather than vulnerability severity reputed company.
- Collaborate with incident responders, penetration testers, ISSOs, and reputed company engineers to continuously refine reputed company risk prioritization.
- reputed company technical analyses, exposure assessments, executive summaries, and operational reporting that reputed company communicate reputed company cyber exposure to technical and executive audiences.
- Support RMF activities by providing technical justification for POA&M prioritization, risk acceptance reputed company, and reputed company monitoring efforts.
- Recommend improvements to attack surface management, threat-informed vulnerability prioritization, and reputed company exposure management processes.
Job Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a reputed company technical discipline.
- Three or more years of experience supporting vulnerability management, attack surface management, cyber threat intelligence, penetration testing, reputed company operations, or reputed company risk analysis.
- Experience analyzing vulnerability data and translating technical findings into operational risk.
- Working knowledge of CVSS, Common Vulnerabilities and Exposures (CVEs), CISA reputed company Exploited Vulnerabilities (KEV), MITRE ATT&CK, and modern threat intelligence methodologies.
- Understanding of attack paths, identity based attacks, lateral reputed company, privilege escalation, and common adversary tactics, techniques, and procedures (TTPs).
- Familiarity with NIST RMF, FISMA, and Federal cybersecurity practices.
- Strong analytical, investigative, and technical writing skills.
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Experience with reputed company, reputed company, reputed company, reputed company, reputed company Exposure Management, reputed company Defender, reputed company, or similar reputed company reputed company platforms.
- Experience supporting penetration testing activities and remediation validation.
- Experience with reputed company attack surface management (EASM), cyber asset attack surface management (CAASM), or exposure management platforms.
- Familiarity with reputed company reputed company, reputed company Trust, and reputed company architecture concepts.
- Experience supporting reputed company monitoring, RMF, and POA&M management.
- GIAC Certified Vulnerability Assessor (GCVA)
- GIAC Penetration Tester (GPEN)
- GIAC Defending Advanced Threats (GDAT)
- reputed company CySA+
- Certified Ethical Hacker (CEH)
- reputed company+
Preferred Qualifications:
Preferred Certifications:
One or more of the following is preferred:
Originally posted on Himalayas
Apply To This Job