Attack Surface Management Engineer - Remote US

Allen, Texas, United States

Applications have closed

Experian

Experian is committed to helping you protect, understand, and improve your credit. Start with your free Experian credit report and FICO® score.

View company page

Company Description

Experian is the world’s leading global information services company. During life’s big moments – from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers – we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control and access financial services, businesses to make smarter decisions and thrive, lenders to lend more responsibly, and organizations to prevent identity fraud and crime.

We have 20,000 people operating across 44 countries and every day we’re investing in new technologies, talented people, and innovation to help all our clients maximize every opportunity.

Job Description

The Attack Surface Management Engineer is responsible for activities related to the full scope of attack surface management, with the goal to ensure comprehensive visibility and actionability of Experian’s entire attack surface, exposures, and vulnerabilities, minimizing Experian’s risk potential. Reports to the Director Attack Surface Management.

Responsibilities:

  • Executes and iteratively improves on Attack Surface Management processes to continuously monitor and strengthen visibility of the attack surface in order to detect anomalies faster and reduce incidences or potential of cyber-attacks
  • Perform verification/validation testing for vulnerabilities across all asset types; demonstrate exploitation steps and verify remediation/fixes
  • Perform programmatic and ad-hoc asset discovery in order to find and eliminate coverage gaps
  • Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniques
  • Engage with business stakeholders to ensure they fully understand their Attack Surface, providing them clear prioritization of vulnerabilities. Coordinate with IT and geographically dispersed Business Units on vulnerability remediation and mitigation strategies
  • Establish an accountable culture for improving the security posture, through vulnerability KPIs and metrics on coverage and remediation effectiveness
  • Assist in the identification of internal and external risks based on scanning results
  • Assist in the attribution of findings to appropriate partners
  • Identify improvements to scan coverage
  • Assist in the documentation and standardization of process and procedures related to Attack Surface Management
  • Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.

Qualifications

  • Bachelor's degree in computer science or computer engineering, or equivalent work experience.
  • 3+ years of experience in attack surface/vulnerability management role.
  • 5+ years in security and/or technology engineering roles.
  • Strong engineering knowledge and experience in support of Attack Surface Management in one or more of the following: Web Application, Networking/Protocols, Network Infrastructure, Network Appliances, APIs, Cloud Infrastructure, Cloud Services, Mobile Devices, Mobile Applications, IoT, Endpoints, Operating Systems, Wireless networking, Third-party Integrations, Data Storage, Databases, CICD, Application Dependencies.
  • Strong vulnerability, remediation, and mitigation knowledge as it applies to several of the following:  Common web applications, APIs, misconfigurations, hosts, mobile, IoT, endpoints, infrastructure, cloud, network appliance, OS, firmware, software supply-chain.
  • Experience with one or more scripting languages such as Bash, Python, Perl, PowerShell, etc. 
  • Knowledge of architecture, engineering, and operations of one or more vulnerability management tools, such as Cycognito, Wiz, Qualys, Rapid7 and ServiceNow. 
  • Understanding of the application of the following frameworks and how they are applied to identifying and rating risk: OWASP, SANS, NIST, CIS, and MITRE ATT&CK. 
  • Knowledge of systems hardening and other risk mitigation factors on multiple technologies and operating systems (Window, Linux, Mac, routers, switches, Kubernetes). 
  • Working knowledge of networking standards and protocols: IPv4 IPv6, TCP/IP, DNS, HTTPS, TLS, BGP, Firewalls and NAT, SMTP, VPN, ICMP, SSH, IPSec, etc.
  • Certification that could be helpful but not required: CISSP, Security+, CEH, GIAC certifications. 
  • Ability to clearly communicate risk of vulnerabilities to all levels within an organization. 

Additional Information

All your information will be kept confidential according to EEO guidelines.

Experian is proud to be an Equal Opportunity and Affirmative Action employer. Our goal is to create a thriving, inclusive and diverse team where people love their work and love working together. We believe that diversity, equity and inclusion is essential to our purpose of creating a better tomorrow. We value the uniqueness of every individual and want you to bring your whole, authentic self to work. For us, this is The Power of YOU and and it reflects what we believe.  See our DEI work in action!

Please contact us at JobPostingInquiry@experian.com to request the salary range of this position (please include the exact Job Title as it reads above in your email). In addition to a competitive base salary and variable pay opportunity, Experian offers a comprehensive benefits package including health, life and disability insurance, generous paid time off including 12 company paid holidays and parental and family care leave, an employee stock purchase plan and a 401(k) plan with a company match.

Experian Careers - Creating a better tomorrow together

Find out what its like to work for Experian by clicking here

Our compensation reflects the cost of labor across several U.S. geographic markets. The base pay range for this position is listed above.  Within this range, individual pay is determined by work location and additional factors such as job-related skills, experience and education.  This position is also eligible for a variable pay opportunity and a comprehensive benefits package which includes health, life and disability insurance, generous paid time off including paid parental and family care leave, an employee stock purchase plan and a 401(k) plan with a company match.

Experian is proud to be an Equal Opportunity and Affirmative Action employer. We’re passionate about unlocking the power of data to transform lives and create opportunities for consumers, businesses, and society. For more than 125 years, we’ve helped people and economies flourish – and we’re not done.

We take our people’s agenda very seriously. We focus on what truly matters; diversity and inclusion, work/life balance, flexible working, development, collaboration, wellness, reward & recognition, volunteering, making an impact... the list goes on. See our DEI work in action!

The power of YOU. We are building a culture where everyone is comfortable bringing their whole self to work. A place where we not only respect our differences and values but celebrate them in a positive and supportive environment.

Find out what is like to work for Experian and discover the Unexpected!

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: APIs Bash CEH CISSP Cloud Computer Science DNS Firewalls GIAC KPIs Kubernetes Linux MITRE ATT&CK NIST OWASP Perl PowerShell Python Qualys SANS Scripting SMTP SSH TCP/IP TLS VPN Vulnerabilities Vulnerability management

Perks/benefits: 401(k) matching Competitive pay Equity Flex hours Flex vacation Health care Insurance Parental leave Team events Wellness

Regions: Remote/Anywhere North America
Country: United States
Job stats:  26  4  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.