Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Analyst Consultant - Attack Surface Management

$110k - $140k

Kalles Group

Security Analyst Consultant - Attack Surface Management

Seattle, WA

Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.

While our expertise spans multiple disciplines, our method remains consistent: building trust and relationship with people -- whether you are a client, a consultant, or--in this case--a candidate.

No matter what role you come from--whether you're an executive or just starting your career--you can expect our highest level of attention and respect. We want to find the right fit for each role, but we also want you to find the right fit for your career.

We believe the best way to show you what our team is like is to treat you like you're already a part of it. We hope you'll consider joining our team of experienced professionals who are building their careers at Kalles Group—and having fun while doing it.

As a Senior Security Analyst Consultant – Attack Surface Management, you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through proactive discovery, analysis, automation, and collaboration. This is a highly visible role that combines strategic leadership with hands-on technical execution, requiring expertise across vulnerability management, cloud security, threat intelligence, and offensive security disciplines.

You will be responsible for developing a comprehensive view of the organization's attack surface, identifying opportunities to reduce exposure, and driving remediation efforts in partnership with engineering, cloud, DevOps, and security teams. Leveraging data, automation, and threat intelligence, you will help prioritize risk reduction initiatives while influencing architectural decisions that strengthen the organization's security posture. This role is ideal for someone who enjoys building programs, solving complex security challenges, and partnering across the enterprise to create meaningful security outcomes.

Key responsibilities:

  • Lead and mature the organization's Attack Surface Management (ASM) program, identifying opportunities to expand capabilities and improve visibility
  • Develop and maintain a comprehensive understanding of the enterprise attack surface across cloud, network, and application environments
  • Continuously identify, assess, and prioritize vulnerabilities and exposures based on business and security risk
  • Partner with security, engineering, infrastructure, and cloud teams to drive remediation efforts and reduce risk
  • Leverage metrics and analytics to measure program effectiveness and inform risk-based decision making
  • Conduct external reconnaissance activities, OSINT research, and threat intelligence analysis to identify potential exposure points
  • Monitor emerging threats, attacker techniques, and industry trends to proactively strengthen defensive capabilities
  • Collaborate with Application Security, DevOps, and Cloud Engineering teams to promote secure-by-design practices
  • Contribute to incident response investigations and post-incident analysis as needed
  • Design and implement automation solutions that improve visibility, efficiency, and risk management workflows
  • Develop and maintain operational standards, procedures, documentation, and runbooks
  • Mentor team members and share expertise across security domains
  • Support compliance initiatives including PCI DSS, SOC 2, and related regulatory requirements
  • Validate security controls and identify opportunities for continuous improvement

About you:

  • Your values:
    • Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly.
    • Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
    • Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.

Your experience:

Required qualifications
  • 6+ years of experience in cybersecurity, including security operations, threat hunting, offensive security, red teaming, or related disciplines
  • Experience building, scaling, or leading Attack Surface Management (ASM) capabilities and programs
  • Strong understanding of vulnerability management methodologies and risk prioritization frameworks
  • Experience working within multi-cloud environments, including AWS, Azure, and GCP
  • Deep knowledge of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK
  • Expertise in network security, cloud security, attack path analysis, and external attack surface discovery
  • Experience conducting OSINT, reconnaissance, and threat intelligence activities
  • Proficiency with scripting and automation technologies such as Python and PowerShell
  • Strong understanding of enterprise infrastructure, application architectures, and data flows
  • Ability to evaluate and influence architectural decisions that reduce organizational risk
  • Experience leading cross-functional security initiatives and driving collaboration across multiple teams
  • Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non-technical stakeholders
  • Strong analytical and problem-solving skills with a data-driven approach to risk management
Preferred qualifications
  • Industry certifications such as CISSP, OSCE, GREM, or similar cybersecurity credentials
  • Experience applying AI and automation technologies to security operations or attack surface management programs
  • Experience with cloud-native security platforms and exposure management tooling
  • Familiarity with threat modeling, purple teaming, or advanced adversary simulation exercises
  • Experience working in large-scale enterprise environments with complex security requirements
What we offer:
  • The annual salary range for this role is $110,000-$140,000.
  • We offer Medical, Dental, Vision plans, 401K with matching, and PTO for salaried employees.
  • Work/life balance – we know there's more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload.

This role is on-site at our client location in Seattle, WA. At this time, we are only considering candidates who currently live in Seattle, WA.

Please fill out the form below (including uploading your most recent resume) and we'll be in touch! We know imposter syndrome can be a barrier to many great applicants. We hope you'll still consider applying. That's why we've made the application process as short and simple as possible.

Even if you're not a fit for the role, you can expect to hear back from us! We want you to have the best experience as a candidate, so please feel free to share feedback at any stage of the process to View email address on click.appcast.io.

Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Security Analyst Consultant - Attack Surface Management in Seattle, WA vacancy
  • $136.2k - $178.7k

     ...people. About this team The Security Operations Center (SOC) is responsible...  ...As a Senior Cybersecurity Analyst, you will apply deep...  ...investigations involving advanced attack techniques, forensic analysis...  ...establishing vulnerability management approaches integrating threat... 
    Suggested
    Permanent employment
    Full time
    Part time
    Local area
    Immediate start
    Work visa

    Lululemon athletica

    Seattle, WA
    4 days ago
  • $120k - $140k

     ...Join to apply for the Consultant - Endpoint Security Analyst role at Kalles Group Join to apply for the Consultant - Endpoint Security Analyst...  ...design and implement a standardized approach to Patch Management across their organization. This role plays a key part in... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Kalles Group

    Seattle, WA
    1 day ago
  • $80k - $105k

     ...A leading construction firm in Seattle seeks an Information Security Analyst to enhance its security posture. The ideal candidate will have...  ...in information security, focusing on vulnerability management, auditing, and risk assessment. Responsibilities include leading... 
    Suggested

    JH Kelly

    Seattle, WA
    4 days ago
  • $114.5k - $179.1k

     ...A global technology company is looking for a Senior Information Security Analyst to provide guidance on information security, focusing on risk assessments and security architectures. The role requires 8+ years of IT experience and includes advising on legal statutes.... 
    Suggested

    PACCAR

    Renton, WA
    4 days ago
  • $192.95k - $261.05k

    Senior Product Security Analyst Company: The Boeing Company The Boeing Company is seeking a Senior...  ...customers. Position Responsibilities: Consults on the integration of security and...  ...complex product security risk/attack surface/vulnerability analyses and security audits... 
    Suggested
    Permanent employment
    Full time
    Interim role
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    Shift work

    Boeing

    Seattle, WA
    2 days ago
  •  ...Alignerr is seeking an Offensive Security Analyst to leverage adversarial thinking in AI development. This fully remote role offers flexible hours and requires analyzing attack paths to strengthen AI systems against cyber threats. The ideal candidate should have over 2... 
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    13 hours ago
  •  ...Senior Security Analyst Who we are We are an innovative performance apparel...  ...networks, devices, and data from malicious attack, damage, or unauthorized access....  ...firewalls, IDS/IPS, anti spam, content management, server and network device hardening, etc... 

    Procyon TS

    Seattle, WA
    5 days ago
  •  ...Alignerr is seeking an experienced Application Security Analyst to improve security in AI systems. In this role, you will analyze real-world...  ..., is familiar with vulnerabilities, and can think like an attacker. Enjoy the flexibility of remote work on impactful AI projects... 
    Remote work

    Alignerr

    Seattle, WA
    1 day ago
  • $23 - $25 per hour

     ...Logistics Security Analyst Expeditors is a global logistics company headquartered in Seattle, Washington. A Fortune 500 company, Expeditors...  ...monitor customer shipments, analyze cargo risk events, and manage response protocols. Agents communicate directly with... 
    Hourly pay
    Work at office
    Local area
    Worldwide
    Shift work
    Afternoon shift

    Expeditors

    Seattle, WA
    5 days ago
  • A leading recruitment firm in Seattle seeks an Information Security Analyst to manage operations of the Agency's Information Security program. This role involves supporting service owners, handling security incidents, and ensuring systems' confidentiality and integrity... 

    Insight Global

    Seattle, WA
    5 days ago
  • $100k

     ...Threat Hunter / SOC Analyst Galvanick protects the industrial world against cyber attacks. Our threat detection platform defends...  ...in enhancing our operational security by conducting manual threat detection...  ...conducting threat hunting or managing incident response for... 
    Permanent employment
    Work at office
    Relocation

    Galvanick

    Seattle, WA
    4 days ago
  • $23 - $25 per hour

     ...Cargo Signal Solutions, LLC is seeking Command Center agents in Seattle to manage customer communications and track shipments using cutting-edge technology. You will be responsible for providing excellent customer service and maintaining data accuracy. The ideal candidate... 
    Hourly pay

    Cargo Signal

    Seattle, WA
    13 hours ago
  • $166k - $220k

     ...TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense...  ...identity, application, and cloud infrastructure Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows,... 
    Full time
    Work experience placement
    Relocation package

    Anduril

    Seattle, WA
    4 days ago
  • $120k - $130k

     ...and ability Setting up IdP and SP connections, policies, selectors, adapters, and contract mapping in PingFederate Access token management, access token mapping, and OIDC policies in PingFederate Creating applications, rules, rule sets, and coarse‑grain authorization... 
    Contract work

    Tata Consultancy Services

    Seattle, WA
    4 days ago
  •  ...We are seeking a highly skilled and experienced Security Analyst to join our team. The Security Analyst will be responsible for ensuring...  ...candidate will have a strong background in cybersecurity and risk management, as well as excellent communication and problem-solving... 

    Vigorcare Pediatric Services

    Seattle, WA
    4 days ago
  •  ...Qualifications 5+ years of experiencein Security GRC, IT Audit, or a related field, with a strong focus onSOX complianceandIT General...  ...Experience working withineral and external auditors, including managing walkthroughs, evidence collection, and audit issue resolution.... 

    CeDent

    Seattle, WA
    4 days ago
  •  ...VigorCare Pediatric Services is seeking a highly skilled Security Analyst to join their team in Seattle. The role involves ensuring the...  ...will have a strong background in information security, risk management, and compliance. Responsibilities include conducting security... 

    Vigorcare Pediatric Services

    Seattle, WA
    4 days ago
  • $120k - $130k

     ...skills/ability Setting up Idp and SP connections, Policies, Selectors, Adapters and contract mapping in PingFederate Access Token Management, Access Token Mapping, OIDC policies in PingFederate Onboarding Applications into PingAccess and PingFederate Working on... 
    Contract work

    Tata Consultancy Services

    Seattle, WA
    5 days ago
  •  ...based on model view controller architecture and content management system. Our services also extend to the domain of Cloud Computing...  ...a radical change. Job Description Participate in security planning and analyst activities. Performs security assessments and security attestations... 

    360 IT Professionals

    Bellevue, WA
    4 days ago
  •  ...integrations, policies, authentication flows, and access controls. Manage application onboarding and SSO integrations across enterprise...  ...PagerDuty. Collaborate with application, infrastructure, and security teams to ensure secure and reliable IAM operations. Required Skills... 
    Contract work

    Veriipro

    Seattle, WA
    5 days ago
  •  ...A software development company based in Bellevue is looking for a skilled Mobile Security Analyst to participate in security assessments and perform thorough analysis of vulnerabilities across applications. The ideal candidate will have substantial experience handling... 

    360 IT Professionals

    Bellevue, WA
    4 days ago
  • $120k - $130k

     ...ability • Setting up Idp and SP connections, Policies, Selectors, Adapters and contract mapping in PingFederate • Access Token Management, Access Token Mapping, OIDC polices in PingFederate • Creating Applications, Rules, Rulesets, coarse grain authorization etc in... 
    Contract work

    Tata Consultancy Services

    Seattle, WA
    2 days ago
  • $136k - $187k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking...  ...customers so they can effectively manage their risk. As a senior level analyst of Customer Assurance, you will...  ...simply answering questions) to a "consultant" (helping the customer and Field... 
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    Okta, Inc.

    Bellevue, WA
    1 day ago
  •  ...Overview: Cybersecurity GRC Security Analyst - Risk and Issue Management Who we are We are a yoga-inspired technical apparel company up to big things. The practice and philosophy of yoga informs our overall purpose to elevate the world through the power of... 

    Voluble Systems LLC

    Seattle, WA
    3 days ago
  •  ...About the job Security Analyst We are seeking a highly skilled Security Analyst to join our team. The Security Analyst will be...  ...will have a strong background in information security, risk management, and compliance. Key Responsibilities: - Conduct regular... 

    Vigorcare Pediatric Services

    Seattle, WA
    2 days ago
  • $50 - $53 per hour

     ...Request ID:93175-1 Job Title : Ping security Analyst Ping security Analyst Location: :Seattle WA, Dallas Texas Duration: 6-12 Months...  ...the security and efficiency of our identity and access management systems. The ideal candidate will have a strong background in... 
    Contract work
    Work experience placement
    Immediate start

    Artech Inc

    Seattle, WA
    3 days ago
  •  ...Okta in Seattle is seeking a Staff Analyst for the Customer Audit program, responsible for leading audits and creating evidence collections...  ...communication skills. This role involves coordination of security audits both virtually and on-site. Join us to strengthen customer... 

    Okta, Inc.

    Seattle, WA
    4 days ago
  •  ...Terrestris Global Solutions is seeking an IT Security Operations Analyst for their IT Technology Services contract, providing essential support...  ...role involves compliance with security protocols, patch management, and collaboration with various teams. Candidates should... 
    Contract work
    Remote work

    Terrestris Global Solutions

    Seattle, WA
    1 day ago
  • $23 - $25 per hour

     ...Cargo Signal Solutions, LLC, based in Seattle, WA, seeks Command Center agents to monitor shipments and enhance security protocols for cargo. You will engage with customers globally through various communication methods and maintain detailed records of shipments. The... 
    Hourly pay
    Weekend work
    Afternoon shift

    Cargo Signal

    Seattle, WA
    4 days ago
  • Job Description Under general direction, the Information Security Analyst assists with the operations of the Agency's Information Security program for its technology assets. The Information Security Analyst's role is to support service owners and system owners in ensuring... 
    Work experience placement

    Insight Global

    Seattle, WA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Analyst Consultant - Attack Surface Management. Be the first to apply!