Senior Attack Surface Management Engineer
About the Role
We are seeking a results-oriented Senior Attack Surface Management Engineer for a potential opportunity to identify, analyze, and reduce cyber exposure across enterprise infrastructure, applications, and connected environments. The ideal candidate will understand how to evaluate external and internal attack surfaces, prioritize exposure reduction, and partner with operations and engineering teams to improve defensive posture. This role collaborates across technical teams to track exposure-related findings, analyze threat relevance, and support the closure of identified security gaps across Information Technology (IT) and Operational Technology (OT) assets. This is a unique opportunity to shape the growth, development, and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract.
Responsibilities
- Identify and assess attack surface exposure across systems, services, assets, and externally reachable resources.
- Support risk assessments and help prioritize remediation activities based on threat relevance, environment analysis, and mission impact.
- Partner with threat hunting, vulnerability management, and engineering teams to integrate threat intelligence and identify coverage gaps and exposure trends.
- Recommend and support implementation of technical controls and protections that reduce exploitability and improve resilience.
- Contribute to security assessments, authorized defensive security exercises, and gap analyses related to data coverage and detection effectiveness.
- Track exposure-related findings, document relevant risks, and help measure the closure of identified security gaps and detection improvements.
Requirements
- Bachelor’s degree from an accredited university; a postgraduate degree from an accredited university may substitute for 6 years of experience.
- 10+ years of relevant work experience in attack surface management, exposure analysis, vulnerability prioritization, or related security engineering disciplines.
- Familiarity with how adversaries leverage weaknesses across infrastructure, identity, applications, and network pathways.
- Strong analytical skills and ability to prioritize remediation based on risk.
- Experience collaborating across cyber operations, engineering, and compliance teams.
- Strong documentation and reporting skills.
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.
Preferred Qualifications
- Active DOE Q or equivalent DoD Top Secret clearance.
Benefits
We offer a comprehensive benefits package, including:
- 144 hours of PTO and 11 holidays.
- 85% of insurance premium covered (major carriers for health care providers).
- 401k retirement plan.
- Continued education, certifications maintenance, and reimbursement.
Schedule
Onsite (Albuquerque, NM).