True Zero Technologies, LLC Logo

True Zero Technologies, LLC

Threat Exposure & Attack Surface Analyst (R-00191)

Posted 6 Days Ago
Remote
Hiring Remotely in USA
Mid level
Remote
Hiring Remotely in USA
Mid level
Analyze enterprise vulnerability and exposure data to prioritize real-world cyber risks for NIH. Correlate KEVs, threat intelligence, attack paths, and asset criticality; validate penetration findings; recommend remediation priorities; support RMF/POA&M activities; and produce technical and executive exposure assessments to drive risk-based remediation.
The summary above was generated by AI
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
 




True Zero is seeking a Threat Exposure & Attack Surface Analyst to help identify, validate, and prioritize the cybersecurity risks that present the greatest operational threat to the National Institutes of Health (NIH). This role sits at the intersection of vulnerability management, threat intelligence, penetration testing, and attack surface management to provide a comprehensive understanding of enterprise cyber exposure.

Rather than treating vulnerabilities as isolated technical findings, this position evaluates the complete operational picture by correlating Known Exploited Vulnerabilities (KEVs), threat intelligence, attack paths, asset criticality, penetration testing results, and system context to determine where the organization is most vulnerable to real world attack. The analyst works closely with vulnerability management, incident response, security engineering, RMF, and system owners to ensure remediation efforts focus on the risks most likely to impact NIH’s mission.

Job Responsibilities

  • Analyze enterprise vulnerability data to identify the highest priority cyber exposures across the NIH environment.
  • Maintain awareness of CISA Known Exploited Vulnerabilities (KEVs), emerging threats, and active adversary campaigns that may affect NIH systems.
  • Correlate vulnerability findings with threat intelligence, exploit availability, attack techniques, and operational risk to improve remediation prioritization.
  • Evaluate the enterprise attack surface, identify high value targets, and assess how changes in infrastructure, cloud services, identities, or external exposure influence organizational risk.
  • Validate penetration testing findings and determine whether identified vulnerabilities create realistic attack paths or opportunities for privilege escalation and lateral movement.
  • Assess compensating controls and remediation effectiveness to ensure corrective actions meaningfully reduce enterprise risk.
  • Support vulnerability management teams by recommending remediation priorities based on exploitability, mission impact, and threat activity rather than vulnerability severity alone.
  • Collaborate with incident responders, penetration testers, ISSOs, and security engineers to continuously refine enterprise risk prioritization.
  • Develop technical analyses, exposure assessments, executive summaries, and operational reporting that clearly communicate enterprise cyber exposure to technical and executive audiences.
  • Support RMF activities by providing technical justification for POA&M prioritization, risk acceptance decisions, and continuous monitoring efforts.
  • Recommend improvements to attack surface management, threat-informed vulnerability prioritization, and enterprise exposure management processes.

Job Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related technical discipline.
  • Three or more years of experience supporting vulnerability management, attack surface management, cyber threat intelligence, penetration testing, security operations, or enterprise risk analysis.
  • Experience analyzing vulnerability data and translating technical findings into operational risk.
  • Working knowledge of CVSS, Common Vulnerabilities and Exposures (CVEs), CISA Known Exploited Vulnerabilities (KEV), MITRE ATT&CK, and modern threat intelligence methodologies.
  • Understanding of attack paths, identity based attacks, lateral movement, privilege escalation, and common adversary tactics, techniques, and procedures (TTPs).
  • Familiarity with NIST RMF, FISMA, and Federal cybersecurity practices.
  • Strong analytical, investigative, and technical writing skills.
  • Preferred Qualifications:
  • Experience supporting NIH, HHS, or other Federal civilian agencies.
  • Experience with Tenable, Qualys, Rapid7, Armis, CrowdStrike Exposure Management, Microsoft Defender, ServiceNow, or similar enterprise security platforms.
  • Experience supporting penetration testing activities and remediation validation.
  • Experience with external attack surface management (EASM), cyber asset attack surface management (CAASM), or exposure management platforms.
  • Familiarity with cloud security, Zero Trust, and enterprise architecture concepts.
  • Experience supporting continuous monitoring, RMF, and POA&M management.
  • Preferred Certifications:

    One or more of the following is preferred:

    • GIAC Certified Vulnerability Assessor (GCVA)
    • GIAC Penetration Tester (GPEN)
    • GIAC Defending Advanced Threats (GDAT)
    • CompTIA CySA+
    • Certified Ethical Hacker (CEH)
    • Security+

We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:
 
- Competitive salary, paid twice per month
- Best in class medical coverage
- 100% of medical premiums covered by True Zero
- Company wide new business incentive programs
- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
- 3 weeks of PTO starting + 11 Paid Holidays Annually
- 401k Program with 100% company match on the first 4%
- Monthly reimbursement of Cell Phone and Home Internet costs
- Paternity/Maternity Leave
- Investment in training and certifications to broaden and deepen your technical skills

Similar Jobs

35 Minutes Ago
Remote or Hybrid
CA, USA
164K-297K Annually
Senior level
164K-297K Annually
Senior level
eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Lead end-to-end delivery of high-priority, cross-functional Revenue initiatives including product and partnership launches. Develop integrated program plans, establish governance and operating cadences, drive cross-functional alignment, manage risks and dependencies, and create repeatable launch frameworks and executive communications to ensure successful market readiness and post-launch stabilization.
An Hour Ago
Remote or Hybrid
United States
88K-118K Annually
Senior level
88K-118K Annually
Senior level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Lead buy- and sell-side Quality of Earnings engagements: analyze financials, assess earnings quality, working capital, and net debt; prepare diligence reports and presentations; manage VDRs; mentor junior staff; support valuation, deal structuring, integration planning, and business development.
Top Skills: ExcelFinancial DatabasesVirtual Data Rooms
An Hour Ago
Remote or Hybrid
73K-109K Annually
Mid level
73K-109K Annually
Mid level
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
The Senior Auditor will conduct audits, assess risk, test internal controls, and mentor junior staff, while maintaining client communications.
Top Skills: Aicpa StandardsCpaGaapGaasPcaob

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account