Senior Information Security Analyst - Attack Surface Management Lead

Mass General BrighamSomerville, MA
$93,954 - $136,739Hybrid

About The Position

The Mass General Brigham Senior Information Security Analyst – Attack Surface Management Function Lead will be responsible for advancing and coordinating the MGB Attack Surface Management capability across vulnerability discovery, penetration testing, attack surface analysis, and attack simulation. This role will help lead the function into a risk-driven, validation-focused capability that identifies meaningful exposure, prioritizes remediation based on exploitability and business impact, and connects findings to detection engineering, threat hunting, threat intelligence, and broader Cyber Defense priorities. The ideal candidate is a deeply technical security professional with experience in vulnerability management, offensive security, exposure analysis, penetration testing, or adversary simulation. They should be comfortable translating technical findings into actionable risk narratives, guiding engineers through complex analysis, and helping prioritize work based on business risk, asset criticality, threat relevance, and exploitability.

Requirements

  • Associate’s degree in a related field of study required, or bachelor’s degree in a related field of study required.
  • Experience may be accepted in lieu of a degree.
  • 5–7 years of relevant experience required.
  • Authority in cybersecurity concepts within the role’s domain.
  • Proficient understanding of cybersecurity concepts outside of a specific individual domain.
  • Expertise with the tools and solutions supported by the team.
  • Ability to apply original and innovative thinking to produce new ideas.
  • Strong leadership, communication, and project management skills.
  • Strong decision-making skills, with the ability to weigh the relative costs and benefits of potential actions and identify the most appropriate path forward.

Nice To Haves

  • Relevant professional certifications preferred or required, such as GCIH, GPEN, CISSP, OSCP, or similar credentials.

Responsibilities

  • Support and mature processes to identify vulnerabilities across infrastructure, applications, cloud environments, endpoints, and externally exposed assets. Ensure findings are enriched with asset context, ownership, severity, exploitability, and business impact to support effective prioritization and remediation.
  • Analyze exposed assets, services, technologies, identities, ownership gaps, and environmental risk to identify meaningful exposure. Translate attack surface data into actionable recommendations for risk reduction.
  • Support penetration testing activities, including scoping, methodology, technical validation, reporting, and remediation follow-up. Ensure findings are clearly documented, risk-ranked, and connected to broader Cyber Defense improvement opportunities.
  • Coordinate and support attack simulation and adversary emulation activities to validate security controls, response processes, and detection coverage. Map activity to MITRE ATT&CK where appropriate and recommend improvements to preventive, detective, and response capabilities.
  • Prioritize remediation activity based on exploitability, asset criticality, business context, exposure, and threat relevance. Partner with technology owners to communicate findings clearly and track remediation through appropriate workflows.
  • Partner with Security Detections, Threat Intelligence, and Threat Hunting teams to ensure ASM findings inform detection engineering, hunt development, and intelligence-driven security priorities.
  • Develop and maintain repeatable processes, SOPs, playbooks, reporting standards, and quality expectations for ASM workflows. Identify opportunities to improve consistency, scalability, and operational maturity across the function.
  • Support the incident response team by providing insight into potential attack paths, exploitable vulnerabilities, exposed assets, and adversary techniques that may be relevant during a cyber incident.
  • Create, review, and update documentation related to attack surface management processes, findings, reports, remediation recommendations, playbooks, and security controls.
  • Provide clear and concise written and verbal communication, including technical reporting, long-form documentation, stakeholder updates, and executive presentations. Translate technical detail into language appropriate for the intended audience.
  • Maintain awareness of emerging vulnerabilities, attacker techniques, offensive security methods, exposure management practices, and technologies that may impact MGB’s security posture.
  • Use Mass General Brigham values to guide decisions, actions, and behaviors, including Patients, Affordability, Accountability & Service Commitment, Decisiveness, Innovation & Thoughtful Risk, Diversity & Inclusion, Integrity & Respect, Learning, Continuous Improvement & Personal Growth, and Teamwork & Collaboration.
  • Other duties as assigned.

Benefits

  • Comprehensive benefits
  • Career advancement opportunities
  • Differentials
  • Premiums
  • Bonuses as applicable
  • Recognition programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service