FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Vulnerability & Attack Surface Management Analyst II
OpenLoop. Run the vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, including discovery, validation, prioritization, remediation tracking, verification, and reporting .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in vulnerability management, attack surface management, and cloud security posture management, with a strong focus on risk-based prioritization and remediation. Proficient in using AI tools for security tasks and managing compliance in regulated environments such as HIPAA.
Highest-signal resume keywords
Vulnerability ManagementCloud Security Posture ManagementRisk-Based PrioritizationScripting Skills in PythonExperience with Vulnerability Scanning Platforms
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability ManagementAttack Surface ManagementCloud Security FundamentalsRisk Model ApplicationVulnerability ScanningContainer Vulnerability ManagementDependency ScanningAPI QueryingDynamic Application Security TestingData Sensitivity Handling
Soft Skills
Strong Writing SkillsCollaboration with Engineering TeamsCommunication with Researchers
Tools & Technologies
CNAPP PlatformsAI ToolsWAFDynamic Scanning ToolsVulnerability Disclosure Management ToolsHardened Base ImagesKubernetesCloudflareBug Bounty PlatformsSaaS Discovery Tools
Certifications & Qualifications
GCLDGCPNGWEBGSECAWS Security SpecialtyGCP Security SpecialtyOSCP
Industry Keywords
HIPAAHITRUSTSOC 2HealthcareFintech
Tech Stack
Tools & technologiesAssemblyAWSCloudDNSGoogle Cloud PlatformKubernetesPython
About the role
Key responsibilities & impact- Run the vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, including discovery, validation, prioritization, remediation tracking, verification, and reporting
- Apply and improve a risk model using internet exposure, exploitability, asset criticality, and data sensitivity
- Build a reliable asset inventory combining cloud, endpoint, and SaaS inventory, with named owners
- Conduct scheduled external attack surface discovery to identify internet-exposed assets
- Drive remediation through Engineering, IT, and Platform teams; create actionable tickets, agree timelines, escalate blockers, and verify fixes
- Roll out hardened base images and dependency baselines to address root causes
- Connect scanner and CNAPP APIs to ticketing and reporting systems and automate repetitive reporting
- Own web application security through dynamic scanning, application-team remediation, and temporary edge/WAF mitigation
- Establish security checks for internally built, externally published applications before launch
- Manage vulnerability disclosure and bug bounty intake, including report validation, researcher communication, duplicate handling, and verified remediation
- Use AI tools to triage findings, correlate data, draft remediation guidance, and produce reports while protecting PHI
- Track mean time to remediate, backlog burn-down, and SLA coverage
- Prepare leadership reporting and evidence for client, partner, and auditor requests in a HIPAA-regulated environment
- Report to the Director of Information Security and advise on changing program priorities
Requirements
What you’ll need- 3 to 6 years in security, with significant hands-on experience in vulnerability management, attack surface management, or cloud security posture management
- Hands-on experience running and tuning a vulnerability scanning or CNAPP platform
- Experience prioritizing a large set of findings with a risk-based model
- Working knowledge of CVSS, EPSS, and the CISA KEV catalog
- Cloud security fundamentals in at least one major provider, preferably GCP or AWS
- Experience with container and image vulnerabilities and dependency (SCA) findings in code repositories
- Comfort starting with an incomplete inventory and determining what exists and who owns it
- Experience working directly with engineering teams to get fixes shipped
- Scripting skills in Python, PowerShell, or similar, sufficient to query APIs and automate reporting
- Regular, hands-on use of AI tools such as Claude, ChatGPT, or GitHub Copilot in security work
- Ability to explain safe handling of PHI, credentials, and sensitive data in AI tools
- Strong writing skills for engineering tickets and executive risk summaries
- Preferred experience with Wiz, Orca, Prisma Cloud, Defender for Cloud, Lacework, CrowdStrike Falcon Exposure Management or Spotlight, Tenable, Qualys, or Rapid7
- Preferred experience with external ASM tools, DNS, certificate transparency, subdomain and shadow IT discovery, CAASM, Axonius, runZero, and SaaS discovery tools
- Preferred experience with DAST, WAF, Invicti, Burp Suite, Cloudflare, Akamai, HackerOne, or Bugcrowd
- Preferred experience with hardened base images, Kubernetes, GKE, EKS, Vercel, Netlify, Cloudflare Pages, SBOMs, and software supply chain security
- Preferred experience in healthcare, fintech, or another regulated industry, including HIPAA, HITRUST, or SOC 2 work
- Preferred certifications include GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialty, OSCP, or equivalent experience
Benefits
Comp & perks- Competitive compensation
- Medical, Dental & Vision
- Flexible Spending / Health Savings Accounts
- Generous PTO and hybrid-work flexibility
- 401(k) with Company Match
- Life Insurance, Pet Insurance, and more