





Tier-1 employer and metro location increase applicants, but niche EASM/CAASM skills limit candidate pool.
Specialized attack-surface and CAASM expertise creates strong security-domain bias, limiting cross-industry transferability.
Explicit 5+ years plus mandatory EASM/CAASM, cloud and scripting requirements make shortlisting stringent.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own and continuously evolve the enterprise external attack surface inventory including internet-facing assets, domains, IP ranges, cloud services, and third-party integrations using EASM and CAASM tooling.
Model attack paths across hybrid environments (on-premises, cloud, identity infrastructure) to identify and prioritize remediation of lateral movement and privilege escalation risks beyond CVSS metrics.
Build and maintain asset intelligence by integrating telemetry from multiple sources, automate data collection and analytics, develop dashboards and reports for operational and executive risk posture communication.
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, or related field.
5+ years progressive experience in Cybersecurity, Security Operations, Vulnerability/Exposure Management, or Attack Surface Management.
Hands-on experience with EASM, CAASM, attack path/graph modeling, cloud environments (AWS, Azure, or GCP), scripting (Python preferred), and API integration for security tools.
Working knowledge of MITRE ATT&CK techniques and ability to communicate technical risk to senior stakeholders clearly.
Experienced in managing complex hybrid environment security with a focus on asset discovery, attack path analysis, and exposure prioritization using advanced tooling.
Capable of partnering cross-functionally with Vulnerability Management, Cloud Security, SOC, and Application Security teams to drive end-to-end risk reduction.
Strong automation and data analytics skills to enhance security operations and reporting, with proven ability to translate technical risk into business language for executive audiences.