The Attack Surface Management (ASM) Engineer is a security engineering role responsible for conducting and supporting attack surface discovery, vulnerability management, and exposure reduction ...
The Attack Surface Management (ASM) Engineer is a security engineering role responsible for conducting and supporting attack surface discovery, vulnerability management, and exposure reduction ...
The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking ...
The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking ...
The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking ...
The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking ...
Senior 2 Attack Surface Analyst (Hybrid - Seattle)
$166K - $258K/yr
As a senior leader on the Attack Surface Management team, this role collaborates closely with cybersecurity and technology partner teams to prioritize risk, execute remediation activities, and ...
Senior 2 Attack Surface Analyst (Hybrid - Seattle)
$166K - $258K/yr
As a senior leader on the Attack Surface Management team, this role collaborates closely with cybersecurity and technology partner teams to prioritize risk, execute remediation activities, and ...
They are seeking a Senior Security Analyst Consultant to lead and evolve their client's Attack Surface Management program, focusing on reducing cyber risk through proactive strategies and ...
They are seeking a Senior Security Analyst Consultant to lead and evolve their client's Attack Surface Management program, focusing on reducing cyber risk through proactive strategies and ...
Senior 2 Attack Surface Analyst (Hybrid - Seattle)
Seattle, WA · On-site
$166K - $258K/yr
As a senior leader on the Attack Surface Management team, this role collaborates closely with cybersecurity and technology partner teams to prioritize risk, execute remediation activities, and ...
Senior 2 Attack Surface Analyst (Hybrid - Seattle)
Seattle, WA · On-site
$166K - $258K/yr
As a senior leader on the Attack Surface Management team, this role collaborates closely with cybersecurity and technology partner teams to prioritize risk, execute remediation activities, and ...
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
Quick apply
As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through ...
CyberLinx Solutions, LLC is looking for an External Attack Surface Management (EASM) Analyst that will be responsible for continuously identifying, monitoring, and reducing the company's internet ...
CyberLinx Solutions, LLC is looking for an External Attack Surface Management (EASM) Analyst that will be responsible for continuously identifying, monitoring, and reducing the company's internet ...
CMDB and Attack Surface Management Support - ServiceNow Developer
Mclean, VA · On-site
$54.50 - $75/hr
CMDB and Attack Surface Management Support - ServiceNow Developer The Opportunity: In this role, you'll design and develop ServiceNow solutions that accelerate Booz Allen's CMDB practice and the ...
CMDB and Attack Surface Management Support - ServiceNow Developer
Mclean, VA · On-site
$54.50 - $75/hr
CMDB and Attack Surface Management Support - ServiceNow Developer The Opportunity: In this role, you'll design and develop ServiceNow solutions that accelerate Booz Allen's CMDB practice and the ...
Cyber Attack Surface Management Manager
Norfolk, VA · On-site +1
$107K - $145K/yr
Experience leading or supporting Cyber Attack Surface Management (ASM), vulnerability management, threat intelligence, or cyber exposure management programs. * Strong hands-on experience coordinating ...
Cyber Attack Surface Management Manager
Norfolk, VA · On-site +1
$107K - $145K/yr
Experience leading or supporting Cyber Attack Surface Management (ASM), vulnerability management, threat intelligence, or cyber exposure management programs. * Strong hands-on experience coordinating ...
CyberLinx Solutions, LLC is looking for an External Attack Surface Management (EASM) Analyst that will be responsible for continuously identifying, monitoring, and reducing the company's internet ...
CyberLinx Solutions, LLC is looking for an External Attack Surface Management (EASM) Analyst that will be responsible for continuously identifying, monitoring, and reducing the company's internet ...
CMDB and Attack Surface Management Support - ServiceNow Developer
Mclean, VA · On-site
$54.50 - $75/hr
CMDB and Attack Surface Management Support - ServiceNow Developer The Opportunity: In this role, you'll design and develop ServiceNow solutions that accelerate Booz Allen's CMDB practice and the ...
CMDB and Attack Surface Management Support - ServiceNow Developer
Mclean, VA · On-site
$54.50 - $75/hr
CMDB and Attack Surface Management Support - ServiceNow Developer The Opportunity: In this role, you'll design and develop ServiceNow solutions that accelerate Booz Allen's CMDB practice and the ...
CMDB and Attack Surface Management Support - ServiceNow Developer
Mclean, VA · On-site +1
$54.50 - $75/hr
Share CMDB and Attack Surface Management Support - ServiceNow Developer The Opportunity: In this role, you'll design and develop ServiceNow solutions that accelerate Booz Allen's CMDB practice and ...
CMDB and Attack Surface Management Support - ServiceNow Developer
Mclean, VA · On-site +1
$54.50 - $75/hr
Share CMDB and Attack Surface Management Support - ServiceNow Developer The Opportunity: In this role, you'll design and develop ServiceNow solutions that accelerate Booz Allen's CMDB practice and ...
Associate Web Application Security Specialist, Attack Surface Management
Greensboro, NC · On-site
$72K - $90K/yr
Oversee the Attack Surface Management program from the technical perspective * Regularly identify and catalog all assets, including new and existing ones, to maintain an up-to-date inventory of VF ...
Associate Web Application Security Specialist, Attack Surface Management
Greensboro, NC · On-site
$72K - $90K/yr
Oversee the Attack Surface Management program from the technical perspective * Regularly identify and catalog all assets, including new and existing ones, to maintain an up-to-date inventory of VF ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Plano, TX · On-site
$136K/yr
... Attack Surface Management (VASM) team ... This hands-on role supports vulnerability management across the Boeing estate and subsidiaries ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Plano, TX · On-site
$136K/yr
... Attack Surface Management (VASM) team ... This hands-on role supports vulnerability management across the Boeing estate and subsidiaries ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Mesa, AZ · On-site
$141K/yr
... Attack Surface Management (VASM) team ... This hands-on role supports vulnerability management across the Boeing estate and subsidiaries ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
Mesa, AZ · On-site
$141K/yr
... Attack Surface Management (VASM) team ... This hands-on role supports vulnerability management across the Boeing estate and subsidiaries ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
North Charleston, SC · On-site
$136K/yr
... Attack Surface Management (VASM) team ... This hands-on role supports vulnerability management across the Boeing estate and subsidiaries ...
Mid-level Vulnerability Assessments & Infrastructure Specialist - Vulnerability & Attack Surface ...
North Charleston, SC · On-site
$136K/yr
... Attack Surface Management (VASM) team ... This hands-on role supports vulnerability management across the Boeing estate and subsidiaries ...
Attack Surface Management information
Can I make $200,000 a year in cyber security?
What are the key skills and qualifications needed to thrive as an Attack Surface Management professional, and why are they important?
What is the highest paid cyber security job?
Is cybersecurity still worth it in 2026?
What is the difference between Attack Surface Management vs Vulnerability Analyst?
| Aspect | Attack Surface Management | Vulnerability Analyst |
|---|---|---|
| Primary Focus | Identifying and reducing the organization's attack surface | Detecting and analyzing security vulnerabilities in systems |
| Skills & Certifications | Cybersecurity knowledge, risk assessment, security tools | Security certifications (e.g., CISSP, CEH), vulnerability scanning |
| Work Environment | Security teams, IT departments, proactive security planning | Security operations centers, incident response teams |
| Industry Usage | Cybersecurity, IT security management | Cybersecurity, penetration testing, security analysis |
While both roles focus on cybersecurity, Attack Surface Management emphasizes proactively identifying and reducing potential attack points, whereas Vulnerability Analysts focus on detecting and analyzing existing vulnerabilities. Understanding these differences helps organizations allocate resources effectively for comprehensive security.
What are some common challenges faced by professionals in Attack Surface Management, and how can they effectively address them?
What is Attack Surface Management?
What does attack surface management do?
Other
Posted 9 days ago
Job description
Elmsford, New York
Grant Funded:
No
Department:
Work Shift:
Day
Work Days:
MON-FRI
Scheduled Hours:
8:30 AM-5 PM
Scheduled Daily Hours:
7.5 HOURS
Pay Range:
$112,000.00-$140,000.00
Montefiore is ranked among the top hospitals nationally and regionally by U.S. News & World Report. For more than 100 years we have been innovating new treatments, procedures, and approaches to patient care, producing stellar outcomes and raising the bar for academic medical centers in the region and around the world. Our work to improve health outcomes in underserved communities is unparalleled in the United States. Our workforce is among the most diverse in the US: Montefiore associates speak 60+ languages.
As a Cybersecurity Engineer in Montefiore Technology , you directly support patient safety, clinical operations, and the protection of sensitive health information. This role pro vides the opportunity to work deeply with modern security technologies while contributing to our mission-driven organization where cybersecurity is essentia l to care delivery.
The Attack Surface Management (ASM) Engineer is a security engineering role responsible for conducting and supporting attack surface discovery, vulnerability management, and exposure reduction activities across a complex healthcare environment. Building upon foundational ASM analyst experience, this role emphasizes hands-on technical execution, operational discipline, and collaboration with IT, Clinical Engineering, Cloud, and Security Operations teams to reduce cyber risk while supporting patient care.
Responsibilities:
- Work with architecture and engineering personnel to implement automation and orchestration solutions where appropriate to improve efficiency and reduce manual effort.
- Collaborate with IT, clinical teams, and other departments to ensure cybersecurity measures are integrated into everyday operations without disrupting patient care.
- Manage vendor relationships related to security solutions, testing services, and consulting engagements.
- Maintain security tools and services ensuring continued uptime and efficient execution of scanning activities.
- Work with DevOps, cloud, and IT infrastructure teams to incorporate secure development practices and vulnerability remediation into their workflows.
- Perform continuous device and asset discovery across IT, cloud, medical, and IoT/OT environments using approved ASM tooling.
- Review and validate asset discovery and vulnerability findings to identify unmanaged, unknown, or misclassified assets.
- Correlate exposure and vulnerability data with CMDBs, internal inventories, and cloud asset repositories to improve accuracy.
- Support the enterprise vulnerability management lifecycle by tracking findings from identification through remediation.
- Apply risk-based vulnerability prioritization using exploitability, asset criticality, and business impact.
- Coordinate with system, application, and device owners to validate their proposed remediation actions and timelines.
- Review third-party penetration testing results and assist with remediation tracking and validation.
- Collaborate with SOC and incident response teams to contextualize vulnerabilities during investigations.
- Develop and maintain technical documentation, SOPs, and workflows related to ASM processes.
- Contribute to dashboards, KPIs, and reporting that measure attack surface coverage, vulnerability aging, and risk reduction.
- Monitor vulnerability and threat trends relevant to healthcare and emerging technologies.
- Assist with automation and orchestration initiatives to improve ASM efficiency under manager guidance.
Requirements:
- Bachelor's degree or equivalent work experience.
- 4 - 6 years Cybersecurity or IT experience with progression from vulnerability analysis, exposure management, or ASM analyst functions.
- 4 - 6 years p rior experience in highly regulated environments .
- Strong proficiency with asset discovery and attack surface management technologies across on - prem IT, cloud, and IoMT environments.
- Strong ability to interpret, validate , and assess findings from attack surface management (ASM) and vulnerability management platforms.
- Strong understanding of the vulnerability management lifecycle, including remediation processes and governance requirements.
- Foundational experience correlating data across CMDBs, cloud inventories, and security tools.
- Ability to communicate technical findings to non-technical stakeholders with guidance.
- Working knowledge of healthcare cybersecurity frameworks including HIPAA, HITECH, NIST CSF, HITRUST, HICP, and NYSDOH 405.46.
- Strong analytical skills with attention to detail and data accuracy.
- Ability to operate effectively within defined processes and escalate appropriately.
Preferred:
- Prior experience in healthcare
- One of the following certifications required or obtained within 18 months of hire:
- CompTIA PenTest+
- GIAC Security Essentials (GSEC)
- Tenable Certified Nessus Auditor (TCNA)
- CREST Registered Vulnerability Specialist (RVS)
#SF-DICE-MIT
#LI-MF1
Montefiore Health System, Inc. is an equal employment opportunity employer. Montefiore Health System, Inc. will recruit, hire, train, transfer, promote, layoff and discharge associates in all job classifications without regard to their race, color, religion, creed, national origin, alienage or citizenship status, age, gender, actual or presumed disability, history of disability, sexual orientation, gender identity, gender expression, genetic predisposition or carrier status, pregnancy, military status, marital status, or partnership status, or any other characteristic protected by law.