Attack Surface Management Analyst - 845 in Broomfield, Colorado at Quantinuum
Explore Related Opportunities
Job Description
We are seeking an Attack Surface Management Analyst in our Broomfield, CO, Location.
The Attack Surface Management Analyst, reporting to the Director of Security Architecture & Assurance, is responsible for developing and executing the Attack Surface Management & Vulnerability Management Program at Quantinuum. This program will encompass the identification of security defects across the environment, coordination of remediation activities with system owners, and ongoing communication and reporting of risk status. This position will work closely with other security teams, along with IT and infrastructure teams, and product teams. This role will also work to coordinate 3rd party penetration tests.
Build Vulnerability Management solution
- Build and deploy vulnerability management solutions, including infrastructure and any necessary agents or services.
- Identify & report security defects
- Configure and execute scans to identify security defects.
- Prioritize the remediation timelines of security defects based on overall risk.
- Prepare and communicate risk reports.
Identify and work with stakeholders to address security defects
- Work with system and application owners on identifying and building processes to operate the program effectively, tracking within manageable tolerances.
- Liaise with vendors and suppliers as necessary for remediation activities if none are provided by scanning vendor(s), or if the solution provided by the scanning vendor(s) is otherwise untenable.
- Validate security defects are remediated satisfactorily
- Create and report metrics to show the effectiveness of the overall program
- High School Diploma/ GED minimum required
- Minimum 5+ years of experience in systems development, infrastructure management or cyber security required
- Due to Contractual requirements, must be a U.S. Person defined as, U.S. citizen permanent resident or green card holder, workers granted asylum or refugee status.
- Due to national security requirements imposed by the U.S. Government, candidates for this position must not be a People's Republic of China national or Russian national unless the candidate is also a U.S. citizen.
- Strong knowledge of networking and endpoint infrastructure, with basic knowledge of application development processes or penetration testing.
- Proven ability to communicate effectively and work collaboratively amongst multiple disciplines and organizations
- Excellent communication, analytical, and relationship-building skills.
- Knowledge or experience with vulnerability scanning and reporting tools (specifically Qualys and BitSight), methods and processes
- Ability to write custom programs or scripts (or modify existing code as necessary)
Compensation & Benefits:
The pay range for this role is $84,000– $105,000 annually. Actual compensation within this range may vary based on the candidate’s skills, educational background, professional experience, and unique qualifications for the role.
$84,000 - $105,000 a year