Threat Mitigation Lead - Network and Systems Attack Surface
Job Details
- Experience
- At least 5 years of experience in threat surface management, vulnerability management, cyber defense, or a closely related cybersecurity discipline; at least 3 years of experience scoping and driving remediation or mitigation campaigns to completion across teams without direct management authority; at least 3 years of experience working with threat intelligence and exposure data and applying it to risk prioritization.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related discipline.
- At least 5 years of experience in threat surface management, vulnerability management, cyber defense, or a closely related cybersecurity discipline.
- At least 3 years of experience scoping and driving remediation or mitigation campaigns to completion across teams without direct management authority.
- At least 3 years of experience working with threat intelligence and exposure data and applying it to risk prioritization.
- Strong knowledge of vulnerability and threat prioritization frameworks and signals, including CVSS, EPSS, KEV, adversary TTPs, and active exploitation reporting.
- Hands-on experience with vulnerability scanning and prioritization platforms, endpoint detection and response (EDR), and security information and event management (SIEM) systems.
- Experience automating remediation workflows, including triage, deduplication, ownership identification, or stakeholder notification.
- Experience collaborating with cyber defense, security operations, or threat intelligence functions.
- Technical leadership experience, including mentoring analysts and leading technical deep dives.
- Relevant certifications such as CISSP, OSCP, GIAC Enterprise Vulnerability Assessor (GEVA), or equivalent are preferred.
Responsibilities
- Lead vulnerability, exposure, and threat mitigation campaigns from intake through closure, setting priorities, ownership, targets, and timelines.
- Analyze threat intelligence and exposure data to prioritize risks using CVSS, EPSS, KEV, active exploitation intelligence, and adversary TTPs.
- Develop automation for remediation triage, deduplication, ownership identification, and stakeholder notification.
- Track remediation progress, remove blockers, escalate stalled or high-severity items, and maintain accountability through completion.
- Capture root causes, technical recommendations, and lessons learned to improve security and remediation processes.
- Support application, platform, and infrastructure teams in interpreting mitigation requirements and developing security plans.
- Validate security controls and mitigation evidence in GRC systems and ensure records are complete and ready for closure.
- Lead technical investigations into vulnerabilities, threat intelligence, and adversary behavior; mentor analysts and identify capability gaps.
- Advise cybersecurity leadership and business stakeholders by translating technical risk and remediation information into actionable decisions.