Attack Surface Management Engineer

hace 3 semanas


Heredia, Costa Rica BMA Group A tiempo completo

**Job Title**:
Attack Surface Management Engineer

**Job Category**:
Professional

**Department/Group**:
Attack Surface Management

**Position Type**:
Full time

**Location**:
Remote, Costa Rica

**Reports to**:
Director Attack Surface Management
- Attack Surface Management EngineerDescription

The Attack Surface Management Engineer is responsible for activities related to Attack Surface Management, with the goal to ensure comprehensive visibility and actionability of the companies external attack surface, exposures, and vulnerabilities, minimizing the companies risk potential.

Functions
- Follows Attack Surface Mgmt processes to continuously monitor and improve visibility of the attack surface in order to detect anomalies faster and reduce incidences or potential of cyber-attacks.
- Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniques.
- Engage with business stakeholders to ensure they fully understand their Attack Surface, and helps them identify prioritization of vulnerabilities.
- Develops vulnerability KPIs/metrics to demonstrate coverage and remediation effectiveness.
- Execute daily operations of the Attack Surface Mgmt program, including the interpretation of scanning results.
- Asist in the identification of internal and external risks based on scanning results.
- Assist in the attribution of findings to appropriate business owner.
- Identify improvements to scan coverage.
- Coordinate with IT and geographically dispersed Business Units on vulnerability remediation and mitigation strategies.
- Assist in the documentation and standardization of process and procedures related to Attack Surface Mgmt
- Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.

Responsibilities/Requirements
- Familiarity with common web vulnerabilities including: XSS, XXE, SQL Injection, Deserialization Attacks, Path Traversal Attacks, Remote Execution Flaws, and Authentication Flaws.
- Experience with one or more scripting languages such as Bash, Python, Perl, PowerShell, etc.
- Working knowledge of networking standards and protocols: IPv4 IPv6, TCP/IP, DNS, HTTPS, TLS, BGP, Firewalls and NAT, SMTP, VPN, ICMP, SSH, IPSec, etc.
- In-depth knowledge of architecture, engineering, and operations of one or more vulnerability management tools, such as Wiz, Qualys, Rapid7 and ServiceNow.
- Ability to provide creative solutions to complex problems.
- Ability to clearly communicate risk of vulnerabilities to all levels within an organization.
- Knowledge of major cloud platforms (AWS, Azure, or GCP).
- Knowledge of systems hardening and other risk mitigation factors on multiple technologies and operating systems (Window, Linux, Mac, routers, switches, Kubernetes).
- Ability to manage, organize, analyze, and present substantial amounts of data.
- Experience selecting and deploying product.

Position Requirements

Formal Education & Certification
- Four-year college diploma or university degree in computer science or computer engineering, and/or 3 years equivalent work experience.

Knowledge & Experience
- Certification that could be helpful but not required: CISSP, Security+, CEH, GIAC certifications.
- 2-4+ years of experience in information security vulnerability management role. 6+ years in security and/or technology engineering roles.
- Experience with large scale and complex environments.
- A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies.
- Applied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management and security and controls.
- Excellent interpersonal skills and strong verbal and written communication.
- An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood and actionable manner.
- Strong organizational skills with proven ability to manage multiple high visibility issues simultaneously.
- Proactive attitude, seeking for improvement opportunities which can positively impact the security posture and the business.

Personal Attributes
- Excellent oral and interpersonal communication skills.
- Outstanding writing and documentation skills.
- Able to communicate ideas in both technical and user-friendly language.
- Highly self-motivated and directed, with keen attention to detail.
- Able to prioritize and execute tasks in a high-pressure environment.
- Experience working in a team-oriented, collaborative environment.
- Willing to travel globally as required.



  • Heredia, Costa Rica Experian A tiempo completo

    Company Description Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control...


  • Heredia, Costa Rica Experian A tiempo completo

    Company Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...


  • Heredia, Costa Rica Experian A tiempo completo

    Company Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...


  • Heredia, Costa Rica BMA Group A tiempo completo

    **Job Title**: **Security Vulnerability Metrics & Data Analyst** **Job Category**: Professional **Department/Group**: **Attack Surface Management** **Position Type**: Full time **Location**: Remote, Costa Rica **Reports to**: Director Attack Surface Management Security Vulnerability Metrics & Data Analyst Description This role will establish and...


  • Heredia, Costa Rica Experian A tiempo completo

    Company Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...

  • Security Vuln Metrics

    hace 3 semanas


    Heredia, Costa Rica Experian A tiempo completo

    Company Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...


  • Heredia, Costa Rica Smarsh A tiempo completo

    **Who are we?** Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or...


  • Heredia, Costa Rica Smarsh A tiempo completo

    **Who are we?** Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or...


  • Heredia, Costa Rica AlignTech A tiempo completo

    **Join a team that is changing millions of lives.** - Transforming smiles, changing lives_ At Align Technology, we believe a great smile can transform a person’s life, so we create technology that gives people the confidence to take on whatever’s next. We revolutionized the orthodontic industry with the introduction of the Invisalign system, and we have...


  • Heredia, Costa Rica ServiceNow A tiempo completo

    **Company Description** At ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can’t wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive...


  • Heredia, Costa Rica 1170 Kyndryl Costa Rica, Sociedad de Responsabilidad Limitada A tiempo completo

    Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The...


  • Heredia, Costa Rica IBM A tiempo completo

    **Introduction** At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's...


  • Heredia, Costa Rica Stryker A tiempo completo

    **Why join Stryker?**: Our total rewards package offering includes bonuses, healthcare, insurance benefits, retirement programs, wellness programs, as well as service and performance awards - not to mention various social and recreational activities, all of which are location specific. **Know someone at Stryker?**: **Who we Want**: - ** Dedicated...


  • Heredia, Costa Rica Kyndryl A tiempo completo

    Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The...

  • IT Solutions Analyst

    hace 4 semanas


    Heredia, Costa Rica Object Technology Solution A tiempo completo

    **OTSI** (**Object Technology Solutions, Inc**) has an immediate opening for an IT Solutions Analyst **IT SOLUTIONS ANALYST (HYBRID/COSTA RICA)** **MAJOR RESPONSIBILITES**: - Coordinate, lead, validate and implement the introduction of new systems or processes for the Human resources, Finance and Supply chain organizations, according with the quality...

  • Jr. Software Engineer

    hace 3 semanas


    Heredia, Costa Rica Sysco Costa Rica A tiempo completo

    Delivers high quality software and technical solutions to meet product/platform needs. Works across the full stack and possesses a flexible mindset and passion for programming. **Requirements**: **Responsibilities**: - Produce high quality code to meet product/platform requirements - Adheres to architecture standards and development best practices like...

  • Compliance Engineer

    hace 2 meses


    Heredia, Costa Rica First Factory, Inc. A tiempo completo

    First Factory is looking for a Compliance Engineer to join our team. A Compliance Engineer plays a critical role in ensuring that an organization operates in accordance with relevant laws, regulations, industry standards, and internal policies. This position involves assessing, implementing, and monitoring processes to maintain compliance and minimize risk...

  • Quality Engineer Ii

    hace 1 semana


    Heredia, Costa Rica Boston Scientific Corporation A tiempo completo

    **Work mode**:Hybrid**Onsite Location(s)**:Heredia, H, CR**Additional Locations**: N/A**Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance** - At Boston Scientific, we’ll give you the opportunity to harness all that’s within you by working in teams of diverse and high-performing employees, tackling some of the most...

  • Facilities Engineer

    hace 4 semanas


    Heredia, Costa Rica Qorvo A tiempo completo

    **Facilities Engineer**: - Experience Level: Individual Contributor- Job Type: Full-Time- Location: Costa Rica - Heredia, CR- Requisition ID: 7150**Facilities Engineer - Heredia, Costa Rica** Corporate Site Services (CSS) touches Qorvo employees every single day. The CSS scope is broad and includes maintaining Qorvo sites, offices, labs and factories as...


  • Heredia, Costa Rica Kyndryl A tiempo completo

    Who We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The...