Principal Attack Surface Management - Remote or Hybrid in MN or DC

UnitedHealth GroupEden Prairie, MN
$112,700 - $193,200Hybrid

About The Position

The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions. You’ll enjoy the flexibility to work remotely from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

Requirements

  • 7+ years of experience in cybersecurity, security engineering, or a related field
  • 3+ years of hands on experience in attack surface management, vulnerability management, external exposure monitoring, or a closely related discipline
  • Proven solid understanding of internet facing infrastructure, cloud services, networking, DNS, certificates, and common exposure patterns
  • Experience working cross functionally to drive remediation of security risks

Nice To Haves

  • 2+ years of scripting or automation experience (PowerShell, Python, REST APIs)
  • Experience with ASM, exposure management, or scanning tools such as Shodan, Tenable, or similar platforms
  • Demonstrated familiarity with dark web monitoring, credential exposure analysis, and brand protection tooling
  • Experience with network security policy analysis tools (e.g., AlgoSec) or similar technologies
  • Experience supporting secure email platforms or SMTP migrations (e.g., Proofpoint)
  • Experience integrating security tooling with SIEM, SOAR, or ticketing systems

Responsibilities

  • Design, implement, and operate the organization’s Attack Surface Management (ASM) program with a focus on continuous discovery, monitoring, and risk reduction
  • Identify and maintain an accurate inventory of external-facing assets, services, domains, IP ranges, cloud resources, and third party exposures
  • Configure and manage attack surface discovery and monitoring tools, including: External scanning and exposure monitoring platforms (e.g., Shodan, Tenable, similar ASM tools), Dark web monitoring solutions for credential leakage, data exposure, and brand risk, Network and application exposure analysis tools (e.g., AlgoSec or comparable platforms)
  • Analyze exposed services, misconfigurations, and vulnerabilities to determine true business risk and exploitation likelihood
  • Partner with infrastructure, network, cloud, application, and third party teams to drive remediation of identified exposures
  • Support secure email and messaging initiatives, including SMTP migrations and exposure reduction using platforms such as Proofpoint
  • Develop and maintain risk based prioritization models for attack surface findings
  • Track and report on attack surface reduction metrics, trends, and program maturity over time
  • Automate asset discovery, exposure analysis, reporting, and validation workflows using scripting and APIs (PowerShell, Python, REST)
  • Build repeatable processes to improve visibility, accuracy, and operational efficiency of ASM tooling
  • Integrate ASM tools and findings with SIEM, SOAR, ticketing, and vulnerability management platforms
  • Evaluate new attack surface and exposure management capabilities, recommending tooling or process improvements based on risk and business impact
  • Leverage enterprise-approved AI tools to enhance productivity and innovation by streamlining workflows and automating repetitive tasks
  • Evaluate emerging trends to drive continuous improvement and strategic innovation
  • Work closely with IT, infrastructure, network, cloud, application, and security teams to embed attack surface awareness into system design and change processes
  • Provide technical guidance on secure architecture, exposure reduction, and preventative controls
  • Clearly communicate attack surface risks, findings, and remediation strategies to both technical and non technical stakeholders
  • Contribute to security standards, policies, and architectural guidance related to external exposure management

Benefits

  • comprehensive benefits package
  • incentive and recognition programs
  • equity stock purchase
  • 401k contribution
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service