Security Analyst Consultant - Attack Surface Management
$110k - $140kKalles Group
Security Analyst Consultant - Attack Surface Management
Seattle, WA
Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.
While our expertise spans multiple disciplines, our method remains consistent: building trust and relationship with people -- whether you are a client, a consultant, or--in this case--a candidate.
No matter what role you come from--whether you're an executive or just starting your career--you can expect our highest level of attention and respect. We want to find the right fit for each role, but we also want you to find the right fit for your career.
We believe the best way to show you what our team is like is to treat you like you're already a part of it. We hope you'll consider joining our team of experienced professionals who are building their careers at Kalles Group—and having fun while doing it.
As a Senior Security Analyst Consultant – Attack Surface Management, you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through proactive discovery, analysis, automation, and collaboration. This is a highly visible role that combines strategic leadership with hands-on technical execution, requiring expertise across vulnerability management, cloud security, threat intelligence, and offensive security disciplines.
You will be responsible for developing a comprehensive view of the organization's attack surface, identifying opportunities to reduce exposure, and driving remediation efforts in partnership with engineering, cloud, DevOps, and security teams. Leveraging data, automation, and threat intelligence, you will help prioritize risk reduction initiatives while influencing architectural decisions that strengthen the organization's security posture. This role is ideal for someone who enjoys building programs, solving complex security challenges, and partnering across the enterprise to create meaningful security outcomes.
Key responsibilities:
- Lead and mature the organization's Attack Surface Management (ASM) program, identifying opportunities to expand capabilities and improve visibility
- Develop and maintain a comprehensive understanding of the enterprise attack surface across cloud, network, and application environments
- Continuously identify, assess, and prioritize vulnerabilities and exposures based on business and security risk
- Partner with security, engineering, infrastructure, and cloud teams to drive remediation efforts and reduce risk
- Leverage metrics and analytics to measure program effectiveness and inform risk-based decision making
- Conduct external reconnaissance activities, OSINT research, and threat intelligence analysis to identify potential exposure points
- Monitor emerging threats, attacker techniques, and industry trends to proactively strengthen defensive capabilities
- Collaborate with Application Security, DevOps, and Cloud Engineering teams to promote secure-by-design practices
- Contribute to incident response investigations and post-incident analysis as needed
- Design and implement automation solutions that improve visibility, efficiency, and risk management workflows
- Develop and maintain operational standards, procedures, documentation, and runbooks
- Mentor team members and share expertise across security domains
- Support compliance initiatives including PCI DSS, SOC 2, and related regulatory requirements
- Validate security controls and identify opportunities for continuous improvement
About you:
- Your values:
- Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly.
- Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
- Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.
Your experience:
Required qualifications
- 6+ years of experience in cybersecurity, including security operations, threat hunting, offensive security, red teaming, or related disciplines
- Experience building, scaling, or leading Attack Surface Management (ASM) capabilities and programs
- Strong understanding of vulnerability management methodologies and risk prioritization frameworks
- Experience working within multi-cloud environments, including AWS, Azure, and GCP
- Deep knowledge of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK
- Expertise in network security, cloud security, attack path analysis, and external attack surface discovery
- Experience conducting OSINT, reconnaissance, and threat intelligence activities
- Proficiency with scripting and automation technologies such as Python and PowerShell
- Strong understanding of enterprise infrastructure, application architectures, and data flows
- Ability to evaluate and influence architectural decisions that reduce organizational risk
- Experience leading cross-functional security initiatives and driving collaboration across multiple teams
- Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non-technical stakeholders
- Strong analytical and problem-solving skills with a data-driven approach to risk management
Preferred qualifications
- Industry certifications such as CISSP, OSCE, GREM, or similar cybersecurity credentials
- Experience applying AI and automation technologies to security operations or attack surface management programs
- Experience with cloud-native security platforms and exposure management tooling
- Familiarity with threat modeling, purple teaming, or advanced adversary simulation exercises
- Experience working in large-scale enterprise environments with complex security requirements
What we offer:
- The annual salary range for this role is $110,000-$140,000.
- We offer Medical, Dental, Vision plans, 401K with matching, and PTO for salaried employees.
- Work/life balance – we know there's more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload.
This role is on-site at our client location in Seattle, WA. At this time, we are only considering candidates who currently live in Seattle, WA.
Please fill out the form below (including uploading your most recent resume) and we'll be in touch! We know imposter syndrome can be a barrier to many great applicants. We hope you'll still consider applying. That's why we've made the application process as short and simple as possible.
Even if you're not a fit for the role, you can expect to hear back from us! We want you to have the best experience as a candidate, so please feel free to share feedback at any stage of the process to View email address on click.appcast.io.
Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.
$136.2k - $178.7k
...people. About this team The Security Operations Center (SOC) is responsible... ...As a Senior Cybersecurity Analyst, you will apply deep... ...investigations involving advanced attack techniques, forensic analysis... ...establishing vulnerability management approaches integrating threat...SuggestedPermanent employmentFull timePart timeLocal areaImmediate startWork visa$120k - $140k
...Join to apply for the Consultant - Endpoint Security Analyst role at Kalles Group Join to apply for the Consultant - Endpoint Security Analyst... ...design and implement a standardized approach to Patch Management across their organization. This role plays a key part in...SuggestedFull timeRemote workFlexible hours$80k - $105k
...A leading construction firm in Seattle seeks an Information Security Analyst to enhance its security posture. The ideal candidate will have... ...in information security, focusing on vulnerability management, auditing, and risk assessment. Responsibilities include leading...Suggested$114.5k - $179.1k
...A global technology company is looking for a Senior Information Security Analyst to provide guidance on information security, focusing on risk assessments and security architectures. The role requires 8+ years of IT experience and includes advising on legal statutes....Suggested$192.95k - $261.05k
Senior Product Security Analyst Company: The Boeing Company The Boeing Company is seeking a Senior... ...customers. Position Responsibilities: Consults on the integration of security and... ...complex product security risk/attack surface/vulnerability analyses and security audits...SuggestedPermanent employmentFull timeInterim roleRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift work- ...Alignerr is seeking an Offensive Security Analyst to leverage adversarial thinking in AI development. This fully remote role offers flexible hours and requires analyzing attack paths to strengthen AI systems against cyber threats. The ideal candidate should have over 2...Remote workFlexible hours
- ...Senior Security Analyst Who we are We are an innovative performance apparel... ...networks, devices, and data from malicious attack, damage, or unauthorized access.... ...firewalls, IDS/IPS, anti spam, content management, server and network device hardening, etc...
- ...Alignerr is seeking an experienced Application Security Analyst to improve security in AI systems. In this role, you will analyze real-world... ..., is familiar with vulnerabilities, and can think like an attacker. Enjoy the flexibility of remote work on impactful AI projects...Remote work
$23 - $25 per hour
...Logistics Security Analyst Expeditors is a global logistics company headquartered in Seattle, Washington. A Fortune 500 company, Expeditors... ...monitor customer shipments, analyze cargo risk events, and manage response protocols. Agents communicate directly with...Hourly payWork at officeLocal areaWorldwideShift workAfternoon shift- A leading recruitment firm in Seattle seeks an Information Security Analyst to manage operations of the Agency's Information Security program. This role involves supporting service owners, handling security incidents, and ensuring systems' confidentiality and integrity...
$100k
...Threat Hunter / SOC Analyst Galvanick protects the industrial world against cyber attacks. Our threat detection platform defends... ...in enhancing our operational security by conducting manual threat detection... ...conducting threat hunting or managing incident response for...Permanent employmentWork at officeRelocation$23 - $25 per hour
...Cargo Signal Solutions, LLC is seeking Command Center agents in Seattle to manage customer communications and track shipments using cutting-edge technology. You will be responsible for providing excellent customer service and maintaining data accuracy. The ideal candidate...Hourly pay$166k - $220k
...TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense... ...identity, application, and cloud infrastructure Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows,...Full timeWork experience placementRelocation package$120k - $130k
...and ability Setting up IdP and SP connections, policies, selectors, adapters, and contract mapping in PingFederate Access token management, access token mapping, and OIDC policies in PingFederate Creating applications, rules, rule sets, and coarse‑grain authorization...Contract work- ...We are seeking a highly skilled and experienced Security Analyst to join our team. The Security Analyst will be responsible for ensuring... ...candidate will have a strong background in cybersecurity and risk management, as well as excellent communication and problem-solving...
- ...Qualifications 5+ years of experiencein Security GRC, IT Audit, or a related field, with a strong focus onSOX complianceandIT General... ...Experience working withineral and external auditors, including managing walkthroughs, evidence collection, and audit issue resolution....
- ...VigorCare Pediatric Services is seeking a highly skilled Security Analyst to join their team in Seattle. The role involves ensuring the... ...will have a strong background in information security, risk management, and compliance. Responsibilities include conducting security...
$120k - $130k
...skills/ability Setting up Idp and SP connections, Policies, Selectors, Adapters and contract mapping in PingFederate Access Token Management, Access Token Mapping, OIDC policies in PingFederate Onboarding Applications into PingAccess and PingFederate Working on...Contract work- ...based on model view controller architecture and content management system. Our services also extend to the domain of Cloud Computing... ...a radical change. Job Description Participate in security planning and analyst activities. Performs security assessments and security attestations...
- ...integrations, policies, authentication flows, and access controls. Manage application onboarding and SSO integrations across enterprise... ...PagerDuty. Collaborate with application, infrastructure, and security teams to ensure secure and reliable IAM operations. Required Skills...Contract work
- ...A software development company based in Bellevue is looking for a skilled Mobile Security Analyst to participate in security assessments and perform thorough analysis of vulnerabilities across applications. The ideal candidate will have substantial experience handling...
$120k - $130k
...ability • Setting up Idp and SP connections, Policies, Selectors, Adapters and contract mapping in PingFederate • Access Token Management, Access Token Mapping, OIDC polices in PingFederate • Creating Applications, Rules, Rulesets, coarse grain authorization etc in...Contract work$136k - $187k
...Secure Every Identity, from AI to Human Identity is the key to unlocking... ...customers so they can effectively manage their risk. As a senior level analyst of Customer Assurance, you will... ...simply answering questions) to a "consultant" (helping the customer and Field...Work experience placementLocal areaWorldwideFlexible hours- ...Overview: Cybersecurity GRC Security Analyst - Risk and Issue Management Who we are We are a yoga-inspired technical apparel company up to big things. The practice and philosophy of yoga informs our overall purpose to elevate the world through the power of...
- ...About the job Security Analyst We are seeking a highly skilled Security Analyst to join our team. The Security Analyst will be... ...will have a strong background in information security, risk management, and compliance. Key Responsibilities: - Conduct regular...
$50 - $53 per hour
...Request ID:93175-1 Job Title : Ping security Analyst Ping security Analyst Location: :Seattle WA, Dallas Texas Duration: 6-12 Months... ...the security and efficiency of our identity and access management systems. The ideal candidate will have a strong background in...Contract workWork experience placementImmediate start- ...Okta in Seattle is seeking a Staff Analyst for the Customer Audit program, responsible for leading audits and creating evidence collections... ...communication skills. This role involves coordination of security audits both virtually and on-site. Join us to strengthen customer...
- ...Terrestris Global Solutions is seeking an IT Security Operations Analyst for their IT Technology Services contract, providing essential support... ...role involves compliance with security protocols, patch management, and collaboration with various teams. Candidates should...Contract workRemote work
$23 - $25 per hour
...Cargo Signal Solutions, LLC, based in Seattle, WA, seeks Command Center agents to monitor shipments and enhance security protocols for cargo. You will engage with customers globally through various communication methods and maintain detailed records of shipments. The...Hourly payWeekend workAfternoon shift- Job Description Under general direction, the Information Security Analyst assists with the operations of the Agency's Information Security program for its technology assets. The Information Security Analyst's role is to support service owners and system owners in ensuring...Work experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Analyst Consultant - Attack Surface Management. Be the first to apply!
- entry level security analyst Seattle, WA
- cloud security analyst Seattle, WA
- information security compliance analyst Seattle, WA
- application security analyst Seattle, WA
- security operations analyst Seattle, WA
- entry level information security analyst Seattle, WA
- information security analyst Seattle, WA
- bond analyst Seattle, WA
- work from home security analyst Seattle, WA
- network security analyst Seattle, WA

