Hybrid Security Engineer – Attack Surface Management

Posted last week

Apply now

About the role

  • Security Engineer responsible for managing the vulnerability lifecycle for Exegy's technology infrastructure. Reducing the attack surface and ensuring organizational risk mitigation.

Responsibilities

  • Own the end-to-end vulnerability lifecycle: discovery, prioritization, remediation tracking, and validation
  • Maintain accurate asset and exposure visibility across endpoints, servers, cloud workloads, SaaS, and internet-facing systems
  • Perform regular vulnerability scanning and ad-hoc assessments
  • Prioritize remediation based on real-world risk, considering:
  • - Exploitability and threat intelligence
  • - Asset criticality and business impact
  • - Exposure (internet-facing, privileged systems, sensitive data)
  • Reduce vulnerability noise by deduplicating findings and focusing teams on what matters most
  • Track remediation progress and validate fixes
  • Identify and eliminate unmanaged or unknown assets, legacy systems with chronic vulnerabilities, and misconfigurations that expand attack surface
  • Partner with IT and Engineering to improve patching cadence
  • Conduct targeted threat analysis and light threat hunting to identify exploitation attempts and abnormal authentication or privilege activity
  • Work closely with IT, Engineering, and Infrastructure teams to drive remediation outcomes

Requirements

  • 3+ years of hands-on experience in security engineering, vulnerability management, or a closely related discipline
  • Strong working knowledge of common vulnerability classes, exploitation techniques, and attacker methodologies
  • Solid foundation in operating systems, networking concepts, and cloud fundamentals
  • Experience using vulnerability scanning, detection, and security monitoring tools to identify and assess risk
  • Demonstrated ability to prioritize remediation efforts based on business and technical risk rather than raw finding volume

Benefits

  • Health insurance
  • Retirement plans
  • Paid time off
  • Flexible work arrangements
  • Professional development
  • Bonuses

Job title

Security Engineer – Attack Surface Management

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

Bachelor's Degree

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job