Security Analyst Consultant - Attack Surface Management
$110k - $140kKalles Group
Job Description
Job Description
ABOUT KALLES GROUP:
Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.
While our expertise spans multiple disciplines, our method remains consistent: building trust and relationship with people -- whether you are a client, a consultant, or--in this case--a candidate.
No matter what role you come from--whether you're an executive or just starting your career-you can expect our highest level of attention and respect. We want to find the right fit for each role, but we also want you to find the right fit for your career.
We believe the best way to show you what our team is like is to treat you like you're already a part of it . We hope you'll consider joining our team of experienced professionals who are building their careers at Kalles Group—and having fun while doing it.
WHAT YOU WILL DO:
As a Senior Security Analyst Consultant – Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through proactive discovery, analysis, automation, and collaboration. This is a highly visible role that combines strategic leadership with hands-on technical execution, requiring expertise across vulnerability management, cloud security, threat intelligence, and offensive security disciplines.
You will be responsible for developing a comprehensive view of the organization's attack surface, identifying opportunities to reduce exposure, and driving remediation efforts in partnership with engineering, cloud, DevOps, and security teams. Leveraging data, automation, and threat intelligence, you will help prioritize risk reduction initiatives while influencing architectural decisions that strengthen the organization's security posture. This role is ideal for someone who enjoys building programs, solving complex security challenges, and partnering across the enterprise to create meaningful security outcomes.
KEY RESPONSIBILITIES:
- Lead and mature the organization's Attack Surface Management (ASM) program , identifying opportunities to expand capabilities and improve visibility
- Develop and maintain a comprehensive understanding of the enterprise attack surface across cloud, network, and application environments
- Continuously identify, assess, and prioritize vulnerabilities and exposures based on business and security risk
- Partner with security, engineering, infrastructure, and cloud teams to drive remediation efforts and reduce risk
- Leverage metrics and analytics to measure program effectiveness and inform risk-based decision making
- Conduct external reconnaissance activities, OSINT research, and threat intelligence analysis to identify potential exposure points
- Monitor emerging threats, attacker techniques, and industry trends to proactively strengthen defensive capabilities
- Collaborate with Application Security, DevOps, and Cloud Engineering teams to promote secure-by-design practices
- Contribute to incident response investigations and post-incident analysis as needed
- Design and implement automation solutions that improve visibility, efficiency, and risk management workflows
- Develop and maintain operational standards, procedures, documentation, and runbooks
- Mentor team members and share expertise across security domains
- Support compliance initiatives including PCI DSS, SOC 2, and related regulatory requirements
- Validate security controls and identify opportunities for continuous improvement
ABOUT YOU:
- Your values:
- Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly.
- Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
- Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.
YOUR EXPERIENCE:
Required Qualifications- 6+ years of experience in cybersecurity, including security operations, threat hunting, offensive security, red teaming, or related disciplines
- Experience building, scaling, or leading Attack Surface Management (ASM) capabilities and programs
- Strong understanding of vulnerability management methodologies and risk prioritization frameworks
- Experience working within multi-cloud environments, including AWS, Azure, and GCP
- Deep knowledge of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK
- Expertise in network security, cloud security, attack path analysis, and external attack surface discovery
- Experience conducting OSINT, reconnaissance, and threat intelligence activities
- Proficiency with scripting and automation technologies such as Python and PowerShell
- Strong understanding of enterprise infrastructure, application architectures, and data flows
- Ability to evaluate and influence architectural decisions that reduce organizational risk
- Experience leading cross-functional security initiatives and driving collaboration across multiple teams
- Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non-technical stakeholders
- Strong analytical and problem-solving skills with a data-driven approach to risk management
- Industry certifications such as CISSP, OSCE, GREM, or similar cybersecurity credentials
- Experience applying AI and automation technologies to security operations or attack surface management programs
- Experience with cloud-native security platforms and exposure management tooling
- Familiarity with threat modeling, purple teaming, or advanced adversary simulation exercises
- Experience working in large-scale enterprise environments with complex security requirements
- The annual salary range for this role is $110,000-$140,000.
- We offer Medical, Dental, Vision plans, 401K with matching, and PTO for salaried employees.
- Work/life balance – we know there's more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload.
LOCATION:
This role is on-site at our client location in Seattle, WA. At this time, we are only considering candidates who currently live in Seattle, WA.
HOW TO APPLY:
Please fill out the form below (including uploading your most recent resume) and we'll be in touch! We know imposter syndrome can be a barrier to many great applicants. We hope you'll still consider applying. That's why we've made the application process as short and simple as possible.
Even if you're not a fit for the role, you can expect to hear back from us! We want you to have the best experience as a candidate, so please feel free to share feedback at any stage of the process to View email address on ziprecruiter.com.
Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.
$136.2k - $178.7k
...people. About this team The Security Operations Center (SOC) is responsible... ...As a Senior Cybersecurity Analyst, you will apply deep... ...investigations involving advanced attack techniques, forensic analysis... ...establishing vulnerability management approaches integrating threat...SuggestedPermanent employmentFull timePart timeLocal areaImmediate startWork visa- ...AI / Emerging Tech Security Analyst (AI Training) About the Role What if your security... ...powerful AI systems defend themselves against attack? We're looking for AI Security Analysts... ...of security threat modeling, attack surfaces, and risk classification Familiar...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
$120k - $140k
Join to apply for the Consultant - Endpoint Security Analyst role at Kalles Group Join to apply for the Consultant - Endpoint Security Analyst role at... ...design and implement a standardized approach to Patch Management across their organization. This role plays a key part in...SuggestedFull timeRemote workFlexible hours$114.5k - $179.1k
...A global technology company is looking for a Senior Information Security Analyst to provide guidance on information security, focusing on risk assessments and security architectures. The role requires 8+ years of IT experience and includes advising on legal statutes....Suggested$80k - $105k
A leading construction firm in Seattle seeks an Information Security Analyst to enhance its security posture. The ideal candidate will have... ...in information security, focusing on vulnerability management, auditing, and risk assessment. Responsibilities include leading...Suggested$192.95k - $261.05k
Senior Product Security Analyst Company: The Boeing Company The Boeing Company is seeking a Senior... ...customers. Position Responsibilities: Consults on the integration of security and... ...complex product security risk/attack surface/vulnerability analyses and security audits...Permanent employmentFull timeInterim roleRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift work- ...Senior Security Analyst Who we are We are an innovative performance apparel... ...networks, devices, and data from malicious attack, damage, or unauthorized access.... ...firewalls, IDS/IPS, anti spam, content management, server and network device hardening, etc...
- ...A cloud identity solutions company is seeking a Staff level analyst in Customer Assurance to manage security inquiries and bridge communications between clients and internal teams. The role requires strong security knowledge, analytical skills, and effective communication...
- ...Offensive Security Analyst (Structured / Non-Exploit) About the Role What if your hard-won knowledge of how real attacks unfold could directly shape how AI understands cyber threats? We're looking for Offensive Security Analysts to bring adversarial thinking to...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$100k
...Threat Hunter / SOC Analyst Galvanick protects the industrial world against cyber attacks. Our threat detection platform defends... ...in enhancing our operational security by conducting manual threat detection... ...conducting threat hunting or managing incident response for...Permanent employmentWork at officeRelocation$23 - $25 per hour
...real-time monitoring using advanced cargo sensors, our team of security and logistics professionals keeps an eye on shipments in transit... ...monitor customer shipments, analyze cargo risk events, and manage response protocols. Agents communicate directly with customers...Hourly payWork at officeLocal areaWorldwideShift workAfternoon shift- A leading recruitment firm in Seattle seeks an Information Security Analyst to manage operations of the Agency's Information Security program. This role involves supporting service owners, handling security incidents, and ensuring systems' confidentiality and integrity...
$50 - $53 per hour
...Request ID:93175-1 Job Title : Ping security Analyst Ping security Analyst Location: :Seattle WA, Dallas Texas Duration: 6-12 Months... ...the security and efficiency of our identity and access management systems. The ideal candidate will have a strong background in...Contract workWork experience placementImmediate start- ...A software development company based in Bellevue is looking for a skilled Mobile Security Analyst to participate in security assessments and perform thorough analysis of vulnerabilities across applications. The ideal candidate will have substantial experience handling...
- ...integrations, policies, authentication flows, and access controls. Manage application onboarding and SSO integrations across enterprise... .... Collaborate with application, infrastructure, and security teams to ensure secure and reliable IAM operations....Contract work
- ...About the job Security Analyst We are seeking a highly skilled Security Analyst to join our team. The Security Analyst will be... ...will have a strong background in information security, risk management, and compliance. Key Responsibilities: - Conduct regular...
- ...Overview: Cybersecurity GRC Security Analyst - Risk and Issue Management Who we are We are a yoga-inspired technical apparel company up to big things. The practice and philosophy of yoga informs our overall purpose to elevate the world through the power of...
- ...Alignerr is seeking an AI / Emerging Tech Security Analyst to probe and evaluate AI systems for vulnerabilities. This fully remote role allows you to impact the safety and reliability of cutting-edge AI technologies. The ideal candidate has a background in cybersecurity...FreelanceRemote work
$120k - $130k
...ability • Setting up Idp and SP connections, Policies, Selectors, Adapters and contract mapping in PingFederate • Access Token Management, Access Token Mapping, OIDC polices in PingFederate • Creating Applications, Rules, Rulesets, coarse grain authorization etc in...Contract work- ...Okta in Seattle is seeking a Staff Analyst for the Customer Audit program, responsible for leading audits and creating evidence collections... ...communication skills. This role involves coordination of security audits both virtually and on-site. Join us to strengthen customer...
- ...Security Operations Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of intelligent security systems - and we need experienced SOC professionals to make it happen. Your hands-on knowledge of real-...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- We are seeking a highly skilled and experienced Security Analyst to join our team. The Security Analyst will be responsible for ensuring... ...candidate will have a strong background in cybersecurity and risk management, as well as excellent communication and problem-solving...
$23 - $25 per hour
...Cargo Signal Solutions, LLC is seeking a dedicated Command Center agent in Bellevue, WA. Responsible for managing customer communication, tracking shipments, and maintaining data accuracy, this role focuses on providing excellent customer service and promoting customer...Hourly pay- ...based on model view controller architecture and content management system. Our services also extend to the domain of Cloud Computing... ...a radical change. Job Description Participate in security planning and analyst activities. Performs security assessments and security attestations...
$120k - $130k
...adapters, and contract mapping in PingFederate Access token management, access token mapping, and OIDC policies in PingFederate Creating... ...college fund, student loan refinancing Base Salary Range: $120,000 to $130,000 Per Annum. #J-18808-Ljbffr Tata Consultancy ServicesContract work- Job Description Under general direction, the Information Security Analyst assists with the operations of the Agency's Information Security program for its technology assets. The Information Security Analyst's role is to support service owners and system owners in ensuring...Work experience placement
$1,600 per month
...Overview Location: Washington, USA Role: Information Security Analyst / Cybersecurity Professional We are hiring an experienced Information Security Analyst to join our growing team in Washington, USA. The Cybersecurity Professional will be responsible for securing the...$114.5k - $179.1k
...Senior Information Security Analyst (G32) Apply now » Apply now Apply Now Start applying... ...to varying levels, including upper management. Prepare positioning papers for PACCAR... ...to provide systems development, consulting, voice and data communications services...Temporary workH1bLocal areaFlexible hours- ...Our client's Information Security team is growing, and we are looking for a motivated, detail... ...and collaborative Information Security Analyst to join us. We operate in a fast-paced... ...and respond to security alerts from our Managed Detection & Response (MDR) service, as...Work experience placement
- Terrestris Global Solutions is seeking an IT Security Operations Analyst for their IT Technology Services contract, providing essential support... ...role involves compliance with security protocols, patch management, and collaboration with various teams. Candidates should...Contract workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst Consultant - Attack Surface Management. Be the first to apply!
- entry level security analyst Seattle, WA
- cloud security analyst Seattle, WA
- information security compliance analyst Seattle, WA
- application security analyst Seattle, WA
- security operations analyst Seattle, WA
- entry level information security analyst Seattle, WA
- information security analyst Seattle, WA
- bond analyst Seattle, WA
- work from home security analyst Seattle, WA
- network security analyst Seattle, WA

