×
Register Here to Apply for Jobs or Post Jobs. X

Senior Information Security Analyst - Attack Surface Management Lead

Job in Somerville, Middlesex County, Massachusetts, 02145, USA
Listing for: Mass General Brigham
Full Time position
Listed on 2026-08-10
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Mass General Brigham Senior Information Security Analyst – Attack Surface Management Function Lead

Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.

Position Summary:

The Mass General Brigham Senior Information Security Analyst – Attack Surface Management Function Lead will be responsible for advancing and coordinating the MGB Attack Surface Management capability across vulnerability discovery, penetration testing, attack surface analysis, and attack simulation. This role will help lead the function into a risk-driven, validation-focused capability that identifies meaningful exposure, prioritizes remediation based on exploitability and business impact, and connects findings to detection engineering, threat hunting, threat intelligence, and broader Cyber Defense priorities.

The ideal candidate is a deeply technical security professional with experience in vulnerability management, offensive security, exposure analysis, penetration testing, or adversary simulation. They should be comfortable translating technical findings into actionable risk narratives, guiding engineers through complex analysis, and helping prioritize work based on business risk, asset criticality, threat relevance, and exploitability.

Key Areas of

Experience:

  • Vulnerability discovery and vulnerability management
  • Attack surface analysis and exposure management
  • Penetration testing and exploit validation
  • Attack simulation, adversary emulation, or breach and attack simulation

Principal Duties and Responsibilities:

  • Vulnerability Discovery:
    Support and mature processes to identify vulnerabilities across infrastructure, applications, cloud environments, endpoints, and externally exposed assets. Ensure findings are enriched with asset context, ownership, severity, exploitability, and business impact to support effective prioritization and remediation.
  • Attack Surface Analysis:
    Analyze exposed assets, services, technologies, identities, ownership gaps, and environmental risk to identify meaningful exposure. Translate attack surface data into actionable recommendations for risk reduction.
  • Penetration Testing Coordination:
    Support penetration testing activities, including scoping, methodology, technical validation, reporting, and remediation follow-up. Ensure findings are clearly documented, risk-ranked, and connected to broader Cyber Defense improvement opportunities.
  • Attack Simulation:
    Coordinate and support attack simulation and adversary emulation activities to validate security controls, response processes, and detection coverage. Map activity to MITRE ATT&CK where appropriate and recommend improvements to preventive, detective, and response capabilities.
  • Remediation Prioritization:
    Prioritize remediation activity based on exploitability, asset criticality, business context, exposure, and threat relevance. Partner with technology owners to communicate findings clearly and track remediation through appropriate workflows.
  • Detection and Threat Hunting Handoffs:
    Partner with Security Detections, Threat Intelligence, and Threat Hunting teams to ensure ASM findings inform detection engineering, hunt development, and intelligence-driven security priorities.
  • Program Maturity:
    Develop and maintain repeatable processes, SOPs, playbooks, reporting standards, and quality expectations for ASM workflows. Identify opportunities to improve consistency, scalability, and operational maturity across the function.
  • Incident Response Support:
    Support the incident response team by providing insight into potential attack paths, exploitable vulnerabilities, exposed assets, and adversary techniques that may be relevant during a cyber incident.
  • Written Documentation:
    Create, review, and update documentation related to attack surface management…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary