Attack Surface Management Engineer

hace 4 días


San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

**Job Title**:
Attack Surface Management Engineer

**Job Category**:
Professional

**Department/Group**:
Attack Surface Management

**Position Type**:
Full time

**Location**:
Remote, Costa Rica

**Reports to**:
Director Attack Surface Management
- Attack Surface Management EngineerDescription

The Attack Surface Management Engineer is responsible for activities related to Attack Surface Management, with the goal to ensure comprehensive visibility and actionability of the companies external attack surface, exposures, and vulnerabilities, minimizing the companies risk potential.
Functions
- Follows Attack Surface Mgmt processes to continuously monitor and improve visibility of the attack surface in order to detect anomalies faster and reduce incidences or potential of cyber-attacks.
- Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniques.
- Engage with business stakeholders to ensure they fully understand their Attack Surface, and helps them identify prioritization of vulnerabilities.
- Develops vulnerability KPIs/metrics to demonstrate coverage and remediation effectiveness.
- Execute daily operations of the Attack Surface Mgmt program, including the interpretation of scanning results.
- Asist in the identification of internal and external risks based on scanning results.
- Assist in the attribution of findings to appropriate business owner.
- Identify improvements to scan coverage.
- Coordinate with IT and geographically dispersed Business Units on vulnerability remediation and mitigation strategies.
- Assist in the documentation and standardization of process and procedures related to Attack Surface Mgmt
- Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.
Responsibilities/Requirements
- Familiarity with common web vulnerabilities including: XSS, XXE, SQL Injection, Deserialization Attacks, Path Traversal Attacks, Remote Execution Flaws, and Authentication Flaws.
- Experience with one or more scripting languages such as Bash, Python, Perl, PowerShell, etc.
- Working knowledge of networking standards and protocols: IPv4 IPv6, TCP/IP, DNS, HTTPS, TLS, BGP, Firewalls and NAT, SMTP, VPN, ICMP, SSH, IPSec, etc.
- In-depth knowledge of architecture, engineering, and operations of one or more vulnerability management tools, such as Wiz, Qualys, Rapid7 and ServiceNow.
- Ability to provide creative solutions to complex problems.
- Ability to clearly communicate risk of vulnerabilities to all levels within an organization.
- Knowledge of major cloud platforms (AWS, Azure, or GCP).
- Knowledge of systems hardening and other risk mitigation factors on multiple technologies and operating systems (Window, Linux, Mac, routers, switches, Kubernetes).
- Ability to manage, organize, analyze, and present substantial amounts of data.
- Experience selecting and deploying product.
Position Requirements

Formal Education & Certification
- Four-year college diploma or university degree in computer science or computer engineering, and/or 3 years equivalent work experience.
Knowledge & Experience
- Certification that could be helpful but not required: CISSP, Security+, CEH, GIAC certifications.
- 2-4+ years of experience in information security vulnerability management role.
6+ years in security and/or technology engineering roles.
- Experience with large scale and complex environments.
- A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies.
- Applied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management and security and controls.
- Excellent interpersonal skills and strong verbal and written communication.
- An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood and actionable manner.
- Strong organizational skills with proven ability to manage multiple high visibility issues simultaneously.
- Proactive attitude, seeking for improvement opportunities which can positively impact the security posture and the business.
Personal Attributes
- Excellent oral and interpersonal communication skills.
- Outstanding writing and documentation skills.
- Able to communicate ideas in both technical and user-friendly language.
- Highly self-motivated and directed, with keen attention to detail.
- Able to prioritize and execute tasks in a high-pressure environment.
- Experience working in a team-oriented, collaborative environment.
- Willing to travel globally as required.



  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    Job Description:The Bma Group seeks a skilled Attack Surface Management Engineer to join their team. The successful candidate will be responsible for ensuring comprehensive visibility and actionability of the company's external attack surface, exposures, and vulnerabilities.Main Responsibilities:Monitor and improve visibility of the attack surface to detect...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Job DescriptionThe Attack Surface Management engineer is responsible for activities related to Attack Surface Management.This includes continuously monitoring and improving visibility of the attack surface to detect anomalies faster and reduce incidences of cyber-attacks.The ideal candidate will have advanced English proficiency, familiarity with common web...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    Job OverviewThe Bma Group is looking for a skilled Attack Surface Management Professional to help us protect our external attack surface from potential threats.Key Responsibilities:Monitor and analyze data from various sources to identify vulnerabilities and potential threats.Collaborate with stakeholders to develop and implement strategies to mitigate risks...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    About the OpportunityWe are seeking an External Attack Surface Expert to join our team at Bma Group. In this role, you will be responsible for managing and mitigating external attack surfaces, ensuring the security and integrity of our organization.Your responsibilities will include:Monitoring and improving visibility of the attack surface to detect...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    About the JobBma Group is looking for a Vulnerability Management Specialist to join our team. In this role, you will be responsible for identifying, classifying, and remediating vulnerabilities within our external attack surface.Your responsibilities will include:Following established processes to continuously monitor and improve visibility of the attack...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    About the RoleWe are seeking a highly skilled Cybersecurity Engineer to join our team at Bma Group. As a key member of our cybersecurity department, you will be responsible for managing and mitigating external attack surfaces.In this role, you will:Monitor and improve visibility of the attack surface to detect anomalies faster and reduce the risk of...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Key ResponsibilitiesFollows Attack Surface Mgmt processes to continuously monitor and improve visibility of the attack surface in order to detect anomalies faster and reduce incidences of cyber-attacksGenerate comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniquesEngage with business stakeholders to ensure they...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    Job DescriptionThe Bma Group is seeking an experienced Cybersecurity Threat Hunter to join our team. This role involves identifying and mitigating external vulnerabilities that could potentially impact the company's security posture.Key Responsibilities:Follow established processes to continuously monitor and improve visibility of the attack surface.Generate...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Company Description**About us, but we'll be brief**Experian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society.We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for.In addition, for the last five years we've...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    Job Summary:The Bma Group is looking for a seasoned Security Vulnerability Analyst Lead to oversee their security vulnerability analysis efforts. This individual will be responsible for developing and implementing effective security measures to protect against external threats.Main Responsibilities:Identify improvements to scan coverage and develop...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    Job Overview:The Bma Group is seeking a highly skilled External Threat Risk Engineer to lead their Security Vulnerability Analysis efforts. This role requires strong analytical and communication skills to identify and mitigate external threats.Main Responsibilities:Develop and implement strategies to continuously monitor and improve visibility of the attack...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Company OverviewAt Experian, we're passionate about unlocking the power of data to create more opportunities for consumers, businesses, and society. Our mission is to help organizations make informed decisions by providing accurate and actionable insights.Job Description: Security Vulnerability Metrics RoleWe're seeking a highly skilled individual to join...


  • San Francisco, Heredia, Costa Rica Bma Group A tiempo completo

    Job SummaryWe are seeking an External Vulnerability Specialist to join our team at the Bma Group. This role involves identifying and remediating external vulnerabilities that could potentially impact our security posture.Key Responsibilities:Identify and prioritize vulnerabilities based on risk assessment and business impact.Collaborate with IT teams to...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    RequirementsTo succeed in this role, you will need:Bachelor's degree in computer science/engineering or equivalent experience 5+ years.3+ years of industry experience on Cyber security preferable on the Identity & Access management domain.3+ years supporting or managing PAM platforms such Centrify, CyberArk, CyberArk EPM, Secret server or any other similar...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Cybersecurity Reporting Specialist Job SummaryWe are seeking an experienced Cybersecurity Reporting Specialist to join our team at Experian. As a key member of our security team, you will be responsible for developing and implementing vulnerability management metrics, communicating metrics to stakeholders, and ensuring the effective implementation of...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    We're seeking an Information Protection Engineer to join our Threat Detection Engineering team at Experian.This team plays a critical role in maintaining the security posture of our organization, working closely with our global security operations center (GSOC).The Information Protection Engineer will be responsible for designing and implementing...

  • Security Vuln Metrics

    hace 6 días


    San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Company Description**About us, but we'll be brief**Experian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society.We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for.In addition, for the last five years we've...

  • Validation Engineer Ii

    hace 2 semanas


    San Francisco, Heredia, Costa Rica Sgf Global A tiempo completo

    As a Validation Engineer II, you will be responsible for ensuring that our products meet the highest standards of quality. Your key responsibilities will include:Designing and implementing validation plans to meet customer requirementsConducting thorough testing to identify potential issuesDeveloping and maintaining documentation to support testing...


  • San Francisco, Heredia, Costa Rica Ntt Data A tiempo completo

    We are seeking a Senior Identity Management Engineer to design and implement Okta Identity and Access Management (IAM) solutions for our organization's Customer Identity and Access Management (CIAM) initiatives.ResponsibilitiesDesign and develop Okta IAM solutions to support our organization's CIAM initiatives.Collaborate with cross-functional teams to...


  • San Francisco, Heredia, Costa Rica Ntt Data A tiempo completo

    Ntt Data is an equal opportunity employer committed to creating a diverse and inclusive environment for all employees. We are seeking a Database Management Engineer to join our team in Costa Rica.Job Summary:The successful candidate will be responsible for maintaining and troubleshooting database systems to ensure optimal performance and availability. This...