Montefiore Health System Logo

Montefiore Health System

Attack Surface Management Engineer

Posted 2 Days Ago
Be an Early Applicant
In-Office
Bronx, NY, USA
112K-140K Annually
Mid level
In-Office
Bronx, NY, USA
112K-140K Annually
Mid level
The Attack Surface Management Engineer is responsible for vulnerability management and reducing cyber risk in a healthcare environment through collaboration with IT and clinical teams, maintaining security tools, and managing vendor relationships.
The summary above was generated by AI

City/State:

Elmsford, New York

Grant Funded:

No

Department:

Work Shift:

Day

Work Days:

MON-FRI

Scheduled Hours:

8:30 AM-5 PM

Scheduled Daily Hours:

7.5 HOURS

Pay Range:

$112,000.00-$140,000.00

Montefiore is ranked among the top hospitals nationally and regionally by U.S. News & World Report. For more than 100 years we have been innovating new treatments, procedures, and approaches to patient care, producing stellar outcomes and raising the bar for academic medical centers in the region and around the world. Our work to improve health outcomes in underserved communities is unparalleled in the United States. Our workforce is among the most diverse in the US: Montefiore associates speak 60+ languages.

As a Cybersecurity Engineer in Montefiore Technology, you directly support patient safety, clinical operations, and the protection of sensitive health information. This role provides the opportunity to work deeply with modern security technologies while contributing to our mission-driven organization where cybersecurity is essential to care delivery. 

 
The Attack Surface Management (ASM) Engineer is a security engineering role responsible for conducting and supporting attack surface discovery, vulnerability management, and exposure reduction activities across a complex healthcare environment. Building upon foundational ASM analyst experience, this role emphasizes hands-on technical execution, operational discipline, and collaboration with IT, Clinical Engineering, Cloud, and Security Operations teams to reduce cyber risk while supporting patient care. 
 

Responsibilities:

  • Work with architecture and engineering personnel to implement automation and orchestration solutions where appropriate to improve efficiency and reduce manual effort.
  • Collaborate with IT, clinical teams, and other departments to ensure cybersecurity measures are integrated into everyday operations without disrupting patient care.
  • Manage vendor relationships related to security solutions, testing services, and consulting engagements.
  • Maintain security tools and services ensuring continued uptime and efficient execution of scanning activities.
  • Work with DevOps, cloud, and IT infrastructure teams to incorporate secure development practices and vulnerability remediation into their workflows.
  • Perform continuous device and asset discovery across IT, cloud, medical, and IoT/OT environments using approved ASM tooling.
  • Review and validate asset discovery and vulnerability findings to identify unmanaged, unknown, or misclassified assets.
  • Correlate exposure and vulnerability data with CMDBs, internal inventories, and cloud asset repositories to improve accuracy.
  • Support the enterprise vulnerability management lifecycle by tracking findings from identification through remediation.
  • Apply risk-based vulnerability prioritization using exploitability, asset criticality, and business impact.
  • Coordinate with system, application, and device owners to validate their proposed remediation actions and timelines.
  • Review third-party penetration testing results and assist with remediation tracking and validation.
  • Collaborate with SOC and incident response teams to contextualize vulnerabilities during investigations.
  • Develop and maintain technical documentation, SOPs, and workflows related to ASM processes.
  • Contribute to dashboards, KPIs, and reporting that measure attack surface coverage, vulnerability aging, and risk reduction.
  • Monitor vulnerability and threat trends relevant to healthcare and emerging technologies.
  • Assist with automation and orchestration initiatives to improve ASM efficiency under manager guidance.

Requirements:

  • Bachelor's degree or equivalent work experience. 

  • 4 - 6 years Cybersecurity or IT experience with progression from vulnerability analysis, exposure management, or ASM analyst functions.  

  • 4 - 6 years prior experience in highly regulated environments. 

  • Strong proficiency with asset discovery and attack surface management technologies across onprem IT, cloud, and IoMT environments. 

  • Strong ability to interpret, validate, and assess findings from attack surface management (ASM) and vulnerability management platforms. 

  • Strong understanding of the vulnerability management lifecycle, including remediation processes and governance requirements. 

  • Foundational experience correlating data across CMDBs, cloud inventories, and security tools. 

  • Ability to communicate technical findings to non-technical stakeholders with guidance. 

  • Working knowledge of healthcare cybersecurity frameworks including HIPAA, HITECH, NIST CSF, HITRUST, HICP, and NYSDOH 405.46. 

  • Strong analytical skills with attention to detail and data accuracy. 

  • Ability to operate effectively within defined processes and escalate appropriately. 

 

Preferred:

  • Prior experience in healthcare
  • One of the following certifications required or obtained within 18 months of hire:
    • CompTIA PenTest+
    • GIAC Security Essentials (GSEC)
    • Tenable Certified Nessus Auditor (TCNA)
    • CREST Registered Vulnerability Specialist (RVS)

#SF-DICE-MIT

#LI-MF1

Montefiore Health System, Inc. is an equal employment opportunity employer. Montefiore Health System, Inc. will recruit, hire, train, transfer, promote, layoff and discharge associates in all job classifications without regard to their race, color, religion, creed, national origin, alienage or citizenship status, age, gender, actual or presumed disability, history of disability, sexual orientation, gender identity, gender expression, genetic predisposition or carrier status, pregnancy, military status, marital status, or partnership status, or any other characteristic protected by law.
HQ

Montefiore Health System New York, New York, USA Office

111 East 210th Street, New York, NY, United States, 10467

Montefiore Health System New York, New York, USA Office

3415 Brainbridge Avenue, New York, NY, United States, 10467

Montefiore Health System New York, New York, USA Office

1825 Eastchester Road, New York, NY, United States, 10461

Montefiore Health System New York, New York, USA Office

600 East 233rd Street, New York, NY, United States, 10466

Similar Jobs

42 Minutes Ago
Remote or Hybrid
United States
42K-42K Annually
Entry level
42K-42K Annually
Entry level
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
The Customer Care Advocate assists customers with insurance inquiries via phone and digital channels, providing support and resolving complex issues with professionalism. Requires customer service experience, operates within guidelines, and utilizes AI tools for efficiency, ensuring compliance and accuracy in documentation.
Top Skills: Ai-Assisted Service ToolsCompliance StandardsCrm Platforms
2 Hours Ago
Remote or Hybrid
New York, NY, USA
113K-176K Annually
Expert/Leader
113K-176K Annually
Expert/Leader
Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
As a Client Director, you will manage and grow complex enterprise accounts, build executive relationships, drive account growth, and ensure financial performance in a fast-paced digital employee experience market.
Top Skills: AIDigital Employee ExperienceIt Operations ManagementIt Service Management
2 Hours Ago
Remote or Hybrid
New York, NY, USA
109K-170K Annually
Senior level
109K-170K Annually
Senior level
Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
As an Enterprise Account Executive, you will drive new business revenue, create demand, and manage enterprise sales cycles in the Northeast region for Nexthink's digital employee experience solutions.
Top Skills: AIB2B SaasDigital Experience Platforms

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account