Sr. Cyber Security Engineer, Exposure Management
Job Summary
As a member of the Exposure Management Team, the Sr. Cyber Security Engineer for Exposure Management owns complex analysis across internet-facing assets—cloud, hybrid, SaaS, domains, applications, APIs, certificates, and shadow IT—to identify, validate, and prioritize vulnerabilities, misconfigurations, leaked data, and other exposures that create a material business risk. The Specialist will operate within the existing exposure management team as a subject matter expert in vulnerability management, ensuring sound practices while designing, growing, and maintaining the external attack surface management program, contributing to vulnerability identification and remediation methodologies, supporting penetration testing practices, report generation, and more. The Specialist will be responsible for seeking out and reporting on vulnerability discoveries and classifications of new vulnerabilities as well as partnering with Threat Intelligence to incorporate current threat activity into risk prioritization. The Specialist will work directly with other security and information technology team members to develop plans for reporting and remediation of vulnerabilities across all operating systems, applications, and other internet-facing assets in the enterprise.
Essential Functions
- Designs, develops, configures, and implements solutions to address intermediate to complex technical and business issues related to cybersecurity.
- Leads efforts to assess cybersecurity risks, identify vulnerabilities, and implement advanced mitigation strategies to protect critical systems and data.
- Reviews and provides consultation on the security of technology solutions addressing intermediate to complex technical and business needs.
- Ensures technology solutions comply with organizational security standards.
- Designs and integrates new security solutions into existing or newly defined architectures and business processes.
- Serves as a subject matter expert for one or more technical solutions and provides guidance to team members.
- Performs other duties as assigned.
- Maintains regular and reliable attendance.
- Complies with all policies and standards.
Qualifications
- Bachelor's Degree in Cyber Security, Computer Science, Information Technology, or a related field; or the equivalent required
- 5-7 years of experience in cybersecurity, information technology operations, or a related field required
Knowledge, Skills and Abilities
- Advanced ability to design and implement solutions for complex, cross-functional technical challenges with minimal oversight.
- Expertise in identifying, troubleshooting, and proactively resolving advanced technical issues.
- Ability to mentor less experienced team members in technical problem-solving.
- In-depth knowledge of security principles across multiple cybersecurity domains.
- Comprehensive understanding of the systems development lifecycle and experience leading complex technical projects.
- Ability to translate complex technical concepts for non-technical audiences, including senior leaders and external stakeholders.
- Advanced written and verbal communication skills.
- Strong collaboration skills, including the ability to work across functions, balance security controls with business requirements, and build consensus.
- Familiarity with NIST 800-53, HITRUST, or similar security and compliance frameworks.
- Hands-on expertise across multiple cybersecurity domains, including endpoint protection, security information and event management, identity and access management, and cloud security.
Licenses and Certifications
- Relevant security certifications (e.g., CISSP, GIAC, or OSCP) preferred
