Cybersecurity Engineer Senior (Senior ISSO) / Exposure Management Analyst
Lumen Solutions Group Inc. · Washington, DC · Yesterday
RemoteRemoteOTHRFull-time
Key Responsibilities
- Identify and assess vulnerabilities, security misconfigurations, exposed assets, attack paths, and security-control gaps across infrastructure, applications, networks, cloud services, and operational environments.
- Use threat intelligence, exploitability data, asset criticality, and business impact to prioritize risks and drive practical remediation decisions.
- Work with technology owners, Cloud Services, Network Engineering, Security Architecture, Security Engineering, the Cyber Fusion Center, and other stakeholders to coordinate and track remediation activities.
- Operate and analyze data from vulnerability and exposure-management tools such as Tenable, Qualys, Rapid7, Microsoft Defender, and ServiceNow.
- Support external attack-surface management and attack-path analysis to identify potentially exploitable entry points and high-risk exposure chains.
- Develop cybersecurity metrics, dashboards, executive-ready reporting, and remediation-status tracking.
- Translate technical security findings into clear business, operational, and risk-focused communication for both technical and non-technical stakeholders.
- Support compliance and cybersecurity best practices aligned with NIST CSF, NIST SP 800-53, CIS Controls, and related enterprise security standards.
- Contribute to a proactive, threat-informed exposure-management program that improves enterprise resilience and reduces overall cyber risk.
Required Qualifications
- Strong experience in enterprise vulnerability management, exposure management, and risk-based remediation.
- Experience assessing infrastructure, applications, networks, cloud platforms, and externally exposed assets.
- Hands-on experience with one or more major vulnerability-management platforms, including Tenable, Qualys, Rapid7, Microsoft Defender, and/or ServiceNow.
- Knowledge of cybersecurity frameworks and practices, including NIST CSF, NIST SP 800-53, and CIS Controls.
- Strong analytical, documentation, communication, and stakeholder-management skills.
- Ability to prioritize competing security findings based on real-world exploitability and business impact.
- Experience supporting large, complex enterprise cybersecurity programs.
Preferred Qualifications
- Relevant certifications such as CISSP, CISM, CISA, CRISC, GICSP, GSEC, Security+, CASP+, or equivalent.
- Experience securing Operational Technology (OT), ICS, or SCADA environments, including awareness of operational safety, system availability, maintenance windows, and vendor constraints.