Attack Surface Management Lead
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Data Security
Work Your Magic with us! Start your next chapter and join Millipore Sigma. Ready to explore, break barriers, and discover more? We know you’ve got big plans – so do we! Our colleagues across the globe love innovating with science and technology to enrich people’s lives with our solutions in Healthcare, Life Science, and Electronics. Together, we dream big and are passionate about caring for our rich mix of people, customers, patients, and planet.
That’s why we are always looking for curious minds that see themselves imagining the unimaginable with us.
Reports to Head of Cyber Enablement & Compliance
Your RoleAs a member of Cyber Enablement and Compliance, you play a pivotal role within Millipore Sigma s Life Science (LS) Cyber Security team. You are part of the global Cyber Security team, interfacing with the LS business and corporate Cyber Security. This is a strategic, hands-on role leading the design, implementation, and continuous improvement of our attack surface reduction initiatives. The successful candidate will bring strong technical expertise in Attack Surface Management (ASM) methodologies and broad project management capabilities.
Key Responsibilities- Attack Surface Management Strategy for Millipore Sigma Life Science
- Lead the design and evolution of comprehensive ASM strategies aligned with organizational risk reduction targets
- Architect ASM discovery, monitoring, and validation frameworks that identify and track external assets across cloud, network, application environments, websites and digital products
- Develop and implement advanced detection methodologies for shadow IT and rogue assets
- Establish baseline metrics and KPIs for attack surface visibility and coordinate their achievement across LS business and security operations teams
- Make improvements to existing ASM processes, tools, and workflows; collaborate across global Cyber Security team to implement these enhancements; improve automation
- Evaluate and drive adoption of new ASM tooling, platforms, and technologies
- Communicate with security operations, vulnerability management, infrastructure, development, and business teams to establish priorities.
- Gain organizational cooperation on the adoption of new ASM processes and procedures by clearly demonstrating business value
- Coordinate with external stakeholders including cloud service providers, domain registrars, and security vendors
- Partner with the vulnerability management function to ensure discovered all assets are properly scanned, classified, and prioritized
- Ensure attack surface visibility feeds directly into vulnerability management workflows and tracking systems
- Prioritize discovered assets and vulnerabilities using business impact, EPSS scoring
- Support executive reporting on attack surface reduction progress
- Maintain oversight of critical vulnerabilities tied to external-facing assets and coordinate remediation timelines
- Manage complex, multi-phase ASM initiatives with general oversight; define scope, timelines, resource requirements, and success criteria
- Lead projects such as cloud security posture assessments, third-party risk management integrations, or regional attack surface reduction campaigns
- Work with minimal day-to-day direction; escalate strategic decisions and blockers appropriately to leadership
- Track project health through metrics and maintain stakeholder visibility on progress and risks
- Incorporate relevant threat intelligence (zero-day vulnerabilities, attack trends, industry-specific risks) into attack surface prioritization decisions
- Ensure processes align with legal, regulatory, and industry standards and requirements (e.g. ISO/IEC 27001/27002, NIST CSF, NIS2, CRA, IEC
62443, PCI DSS) - Contribute to security assessments and audit responses related to external assets.
This position can be based in either our Burlington, MA or St. Louis, MO site. We do offer a hybrid flexible work arrangement.
Who You Are- Professional with a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).