Senior Information Security Analyst Attack Surface Management Lead
Somerville, NJ - USA
Job Summary
Mass General Brigham relies on a wide range of professionals including doctors nurses business people tech experts researchers and systems analysts to advance our mission. As a not-for-profit we support patient care research teaching and community service striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.
Job Summary
Position SummaryThe Mass General Brigham Senior Information Security Analyst Attack Surface Management Function Lead will be responsible for advancing and coordinating the MGB Attack Surface Management capability across vulnerability discovery penetration testing attack surface analysis and attack simulation. This role will help lead the function into a risk-driven validation-focused capability that identifies meaningful exposure prioritizes remediation based on exploitability and business impact and connects findings to detection engineering threat hunting threat intelligence and broader Cyber Defense priorities.
The ideal candidate is a deeply technical security professional with experience in vulnerability management offensive security exposure analysis penetration testing or adversary simulation. They should be comfortable translating technical findings into actionable risk narratives guiding engineers through complex analysis and helping prioritize work based on business risk asset criticality threat relevance and exploitability.
Key Areas of Experience
Vulnerability discovery and vulnerability management
Attack surface analysis and exposure management
Penetration testing and exploit validation
Attack simulation adversary emulation or breach and attack simulation
Principal Duties and Responsibilities
Vulnerability Discovery: Support and mature processes to identify vulnerabilities across infrastructure applications cloud environments endpoints and externally exposed assets. Ensure findings are enriched with asset context ownership severity exploitability and business impact to support effective prioritization and remediation.
Attack Surface Analysis: Analyze exposed assets services technologies identities ownership gaps and environmental risk to identify meaningful exposure. Translate attack surface data into actionable recommendations for risk reduction.
Penetration Testing Coordination: Support penetration testing activities including scoping methodology technical validation reporting and remediation follow-up. Ensure findings are clearly documented risk-ranked and connected to broader Cyber Defense improvement opportunities.
Attack Simulation: Coordinate and support attack simulation and adversary emulation activities to validate security controls response processes and detection coverage. Map activity to MITRE ATT&CK where appropriate and recommend improvements to preventive detective and response capabilities.
Remediation Prioritization: Prioritize remediation activity based on exploitability asset criticality business context exposure and threat relevance. Partner with technology owners to communicate findings clearly and track remediation through appropriate workflows.
Detection and Threat Hunting Handoffs: Partner with Security Detections Threat Intelligence and Threat Hunting teams to ensure ASM findings inform detection engineering hunt development and intelligence-driven security priorities.
Program Maturity: Develop and maintain repeatable processes SOPs playbooks reporting standards and quality expectations for ASM workflows. Identify opportunities to improve consistency scalability and operational maturity across the function.
Incident Response Support: Support the incident response team by providing insight into potential attack paths exploitable vulnerabilities exposed assets and adversary techniques that may be relevant during a cyber incident.
Written Documentation: Create review and update documentation related to attack surface management processes findings reports remediation recommendations playbooks and security controls.
Communication: Provide clear and concise written and verbal communication including technical reporting long-form documentation stakeholder updates and executive presentations. Translate technical detail into language appropriate for the intended audience.
Industry Knowledge: Maintain awareness of emerging vulnerabilities attacker techniques offensive security methods exposure management practices and technologies that may impact MGBs security posture.
MGB Values: Use Mass General Brigham values to guide decisions actions and behaviors including Patients Affordability Accountability & Service Commitment Decisiveness Innovation & Thoughtful Risk Diversity & Inclusion Integrity & Respect Learning Continuous Improvement & Personal Growth and Teamwork & Collaboration.
Other duties as assigned.
Qualifications
- Associates degree in a related field of study required or bachelors degree in a related field of study required.
- Experience may be accepted in lieu of a degree.
- Relevant professional certifications preferred or required such as GCIH GPEN CISSP OSCP or similar credentials.
- 57 years of relevant experience required.
- Authority in cybersecurity concepts within the roles domain.
- Proficient understanding of cybersecurity concepts outside of a specific individual domain.
- Expertise with the tools and solutions supported by the team.
- Ability to apply original and innovative thinking to produce new ideas.
- Strong leadership communication and project management skills.
- Strong decision-making skills with the ability to weigh the relative costs and benefits of potential actions and identify the most appropriate path forward.
Additional Job Details (if applicable)
- MondayFriday Eastern business hours.
- Onsite presence required one day per week.
- Flexibility required for additional onsite days for meetings or business needs as planned and scheduled.
- Remote workdays require a stable secure quiet and compliant workstation using MGB-provided equipment.
Remote Type
Work Location
Scheduled Weekly Hours
Employee Type
Work Shift
Pay Range
$93953.60 - $136739.20/AnnualGrade
7EEO Statement:
At Mass General Brigham our competency framework defines what effective leadership looks like by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance make hiring decisions identify development needs mobilize employees across our system and establish a strong talent pipeline.
Required Experience:
Senior IC
About Company
Patients at Mass General have access to a vast network of physicians, nearly all of whom are Harvard Medical School faculty and many of whom are leaders within their fields.