×
Register Here to Apply for Jobs or Post Jobs. X

IAM Engineer; ASM - Attack Surface Management - Scanning L2

Job in Somerset, Somerset County, New Jersey, 08875, USA
Listing for: Diamondpick
Full Time position
Listed on 2026-06-08
Job specializations:
  • IT/Tech
    Cybersecurity, Data Security
Salary/Wage Range or Industry Benchmark: 65 USD Hourly USD 65.00 HOUR
Job Description & How to Apply Below
Position: IAM Engineer(ASM - Attack Surface Management - Scanning) L2
Title: IAM Engineer(ASM - Attack Surface Management - Scanning) L2

Location:


Somerset, New Jersey
Client: HCL
Client Job  


Client SPOC:
Gayathri J

DP POC:
Dinesh Babu T


Bill rate: $65/hr

Job Description

Summary
We are seeking a technically strong Vulnerability Management Analyst / Engineer to lead vulnerability identification, prioritization, and remediation across infrastructure, web applications, and cloud environments. This role combines hands-on scanning, threat-informed prioritization, cross functional remediation coordination to reduce risk and improve time-to-remediation.

Experience
  • 5+ years of vulnerability management, application security, or penetration testing experience preferred.
Key Responsibilities
  • Lead the end-to-end vulnerability management lifecycle: discovery, validation, risk-based prioritization, remediation coordination, and remediation verification.
  • Execute vulnerability assessments across on-premises, cloud (AWS, Azure, GCP), containerized, infrastructure, and web application environments to maintain comprehensive asset coverage and risk visibility.
  • Perform and validate infrastructure, application, and dynamic web testing (DAST), including manual verification of OWASP Top 10 and SANS Top 25 vulnerabilities (e.g., SQLi, XSS, CSRF, SSRF, IDOR, auth bypass) using industry-standard tools (Tenable, Wiz, Qualys, Rapid7, Burp Suite, OWASP ZAP).
  • Apply threat-informed prioritization using CVSS, EPSS, CISA advisories, exploit intelligence, and business impact to reduce critical risk and mean time to remediation (MTTR).
  • Operate, tune, and optimize vulnerability scanning platforms, asset discovery, and reporting pipelines to ensure accurate coverage and actionable findings.
  • Partner with Infrastructure, Engineering, Dev Ops, Application, Cloud, Threat Intelligence, and Automation teams to drive remediation, establish secure baselines, and respond to zero-day or imminent threats.
  • Produce and present technical and executive-level reports, dashboards, and metrics highlighting remediation SLAs, risk reduction, and program maturity.
  • Contribute to security best practices, secure coding standards, threat modeling, and risk assessments for application and infrastructure initiatives.
  • Stay current on emerging vulnerabilities, attack techniques, and vulnerability management tooling to continuously improve program effectiveness.
Required Qualifications & Skills
  • Proven experience identifying, validating, and remediating vulnerabilities across web applications, networks, systems, and cloud environments.
  • Hands-on proficiency with VM assessment and application security tools like:
    Tenable (Nessus/VMDR), Wiz, Qualys, Rapid7, Burp Suite, OWASP ZAP, Check marks, Veracode, Insight App Sec.
  • Familiarity with vulnerability prioritization frameworks and metrics (OWASP Top 10, SANS Top 25, CVSS, EPSS/CISA).
  • Strong analytical, problem-solving, and written/verbal communication skills with ability to translate technical findings to business stakeholders.
Preferred
  • Relevant certifications: OSCP, GWAPT, CEH, CSSLP, or equivalent.
  • Experience with penetration testing, exploit development, or application security architecture reviews.
  • Knowledge of regulatory and compliance frameworks (PCI DSS, GDPR, HIPAA, CIS, NIST, ISO).
  • Experience with external exposure monitoring and third-party risk tools (Shodan, SSLScan, Security Scorecard, Bit Sight).
  • Demonstrated success driving scale-ready VM processes, SLAs, and executive reporting.
  • Conduct cloud-native and container vulnerability scanning and embed security controls and testing into CI/CD pipelines.
  • Strong manual testing skills for web application vulnerabilities and exploit validation.
  • Basic to intermediate programming/scripting skills (Python required/preferred; also Power Shell, Bash; familiarity with JavaScript, Java, or C# a plus).
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary