Attack Surface Management (ASM) Senior Analyst
About the role
Independently lead programs, projects, and operational initiatives to manage technical risk at scale across Best Buy. Partner with IT and business stakeholders to collect, analyze, and communicate vulnerability and configuration risk data, translating findings into clear reporting and metrics that inform risk posture and decision-making. Ensure services are delivered effectively, manage stakeholder expectations, and contribute to continuous improvement of technical risk management processes. Mentor and support analysts, help maintain dashboards and reporting artifacts, and adapt quickly to evolving tools, technologies, and processes.
This role is hybrid, requiring some days at the corporate office in Richfield, Minnesota, and some days working virtually from home or another non-Best Buy location. Specific work arrangements will be provided during the hiring process.
Responsibilities
- Perform risk-based vulnerability analysis by evaluating severity, exploitability, asset criticality, and business impact to prioritize remediation efforts.
- Partner with engineering, infrastructure, and application teams to drive timely remediation and compensating controls for identified vulnerabilities.
- Develop and maintain vulnerability management reporting (dashboards, metrics, KPIs) that clearly communicate risk posture, trends, and remediation progress.
- Support and improve security, risk, and compliance workflows through process evaluation, documentation, and training.
- Monitor ongoing activities, identify gaps or improvement opportunities, and communicate findings and solutions to leadership.
- Translate technical vulnerability data into clear business risk narratives for non-technical stakeholders.
- Lead vulnerability triage activities, including validation, false-positive reduction, and prioritization aligned to risk tolerance and SLAs.
Requirements
- 2 or more years of experience in vulnerability management, application security, or security operations, including involvement in application security, secure coding practices, or other vulnerability-related identification, triage, and remediation processes.
- 2 or more years of experience managing network and infrastructure, Windows, Linux, and/or mobile platforms patching or security configuration and remediation activities.
- Strong written and verbal communication skills, with emphasis on distilling complex technical vulnerabilities into actionable business insights.
Preferred Qualifications
- 2 or more years of experience supporting application or software security processes, including identification and remediation of security concerns.
- 2 or more years of experience implementing or maintaining secure configuration standards across systems or platforms.
- 1 or more years of experience designing, improving, or optimizing web applications.
- Experience using standardized frameworks like CVSS to triage vulnerabilities.
- Familiarity with OWASP Top 10 lists.
- Hands-on experience with cloud platforms and awareness of common security risks and control mechanisms.
- Experience working with containerized environments and understanding associated security controls and risks.
Benefits
- Competitive pay
- Generous employee discount
- Physical and mental well-being support
- Leaves of absence (LOA) with potential pay sources based on eligibility, including intermittent or reduced-schedule leave for medical or family care
- Paid time off (vacation or PTO) based on work location, employment status, and years of service
- Incentive pay for eligible roles to drive performance and recognition
For more information about benefits, LOA, and paid time off, refer to the Benefits Guide.