Threat Exposure & Attack Surface Analyst (R-00191)

3 days, 16 hours ago
Full-time
Mid Level
Cybersecurity
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Analyze enterprise vulnerability data to identify the highest-priority cyber exposures across the NIH environment.
  • Track CISA Known Exploited Vulnerabilities, emerging threats, and active adversary campaigns affecting NIH systems.
  • Correlate vulnerability findings with threat intelligence, exploitability, attack techniques, and operational risk to improve prioritization.
  • Evaluate the enterprise attack surface and assess risk changes from infrastructure, cloud, identity, and external exposure changes.
  • Validate penetration testing findings and determine realistic attack paths, privilege escalation, and lateral movement opportunities.
  • Assess compensating controls and remediation effectiveness to confirm risk reduction.
  • Support vulnerability management teams by recommending remediation priorities based on exploitability, mission impact, and threat activity.
  • Collaborate with incident responders, penetration testers, ISSOs, and security engineers to refine risk prioritization.
  • Develop technical analyses, exposure assessments, executive summaries, and operational reports for technical and executive audiences.
  • Support RMF activities by providing justification for POA&M prioritization, risk acceptance decisions, and continuous monitoring.
  • Recommend improvements to attack surface management and threat-informed exposure management processes.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • 3+ years of experience in vulnerability management, attack surface management, cyber threat intelligence, penetration testing, security operations, or enterprise risk analysis.
  • Experience analyzing vulnerability data and translating technical findings into operational risk.
  • Working knowledge of CVSS, CVEs, CISA KEV, MITRE ATT&CK, and modern threat intelligence methodologies.
  • Understanding of attack paths, identity-based attacks, lateral movement, privilege escalation, and common adversary TTPs.
  • Familiarity with NIST RMF, FISMA, and Federal cybersecurity practices.
  • Strong analytical, investigative, and technical writing skills.
  • Experience supporting NIH, HHS, or other Federal civilian agencies (preferred).
  • Experience with Tenable, Qualys, Rapid7, Armis, CrowdStrike Exposure Management, Microsoft Defender, ServiceNow, or similar security platforms (preferred).
  • Experience with EASM, CAASM, or exposure management platforms; cloud security, Zero Trust, enterprise architecture, continuous monitoring, RMF, or POA&M management (preferred).
  • One or more preferred certifications: GCVA, GPEN, GDAT, CySA+, CEH, or Security+.

Benefits

  • Competitive salary, paid twice per month.
  • Best-in-class medical coverage with 100% of medical premiums covered by True Zero.
  • 3 weeks of PTO plus 11 paid holidays annually.
  • 401(k) program with 100% company match on the first 4%.
  • Monthly reimbursement for cell phone and home internet costs.
  • Paternity/maternity leave.
  • Investment in training and certifications.
  • Company-wide new business incentive programs and contribution incentives.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Sr. Cyber Analyst, Digital Forensics Incident Response

At-Bay 251-1K Insurance

At-Bay is hiring a Digital Forensics and Incident Response (DFIR) team member to support incident investigation, response, and recovery for insured small businesses.

AWS Azure GCP Linux Unix
1 day, 15 hours ago

Cyber Analyst, Digital Forensics Incident Response

At-Bay 251-1K Insurance

At-Bay is hiring a Cybersecurity Analyst focused on digital forensics and incident response to investigate and help recover from security incidents for its insured small-business customers.

AWS Azure Cybersecurity GCP
1 day, 15 hours ago

Manager, Governance, Risk & Compliance

Ultimate Medical Academy is hiring a remote Manager, Governance, Risk & Compliance to lead its institution-wide GRC and information security programs in support of a national higher-education environment.

Cybersecurity HIPAA Network Security Penetration Testing
2 days, 16 hours ago

Sr. Insider & Data Risk Analyst

Alpaca 51-250 Capital Markets

Alpaca is hiring a Senior Insider & Data Risk Analyst to lead insider risk investigations and strengthen data loss prevention and risk management across its global brokerage infrastructure.

AWS Azure Cybersecurity Elasticsearch GCP Python SIEM Splunk SQL
3 days, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers