Security Engineer - Exposure Management
$97.6k - $138.6kXcel Energy
Are you looking for an exciting job where you can put your skills and talents to work at a company you can feel proud to be a part of? Do you want a workplace that will challenge you and offer you opportunities to learn and grow? A position at Xcel Energy could be just what you're looking for.
Role Summary
The Security Engineer - Exposure Management is responsible for building and maturing the attack surface management capability with a focus on answering where the organization is most exposed and what the actual risk is. This role owns external visibility, correlates external exposure to internal systems and accountable owners, and provides clear, actionable risk insight to stakeholders. The role operates in an advisory capacity and drives informed remediation through visibility, analysis, and communication, not direct system changes.
Primary Objectives
Establish and maintain authoritative visibility of externally exposed assets across domains, IP space, applications, and services.
Correlate external exposure to internal systems and accountable owners, including complex non-1:1 relationships.
Answer where risk exists and what exposure means in practical terms to the business.
Build workflows to manage external findings with minimal manual effort using integration and automation.
Improve coverage, mapping accuracy, and data quality to reduce unknown external exposure.
Responsibilities
Build and operate the attack surface management capability, including processes, integrations, and workflows.
Maintain visibility into externally exposed assets including domains, IPs, web applications, APIs, certificates, load balancers, and DMZ services.
Correlate external findings to internal systems and ownership across complex, indirect relationships.
Coordinate with threat intelligence, network, firewall, DNS, and load balancing teams to validate exposure and ownership.
Develop and maintain integrations to support discovery, enrichment, and correlation of external assets.
Drive routing accuracy by ensuring findings map to the correct owners and identifying ownership gaps.
Identify and resolve data quality issues impacting visibility, coverage, and correlation.
Integrate findings into ServiceNow workflows where applicable to support routing and tracking.
Reduce manual effort by standardizing and automating repeatable processes.
Analyze exposure and vulnerability data in context to determine actual risk beyond tool-based severity.
Communicate complex technical risk clearly to non-technical stakeholders with actionable recommendations.
Document processes, playbooks, and operational standards to sustain the capability.
Required Qualifications
Minimum 5 years of experience in information security.
Minimum 3 years of hands-on experience in enterprise vulnerability management, exposure management, or network security.
Strong understanding of networking fundamentals including firewalls, ACLs, routing, load balancing, and externally exposed architectures.
Strong understanding of DNS, web infrastructure, certificates, and DMZ environments.
Understanding of infrastructure vulnerability assessment and discovery scanning concepts.
Basic understanding of cloud-hosted and externally exposed services.
Basic understanding of web applications and externally facing service risk.
Strong experience correlating external data to internal systems and ownership across inconsistent datasets.
Strong analytical and complex technical problem-solving skills.
Ability to assess and communicate risk beyond tool-generated severity using context.
Experience working with CMDB or similar systems for asset and ownership tracking.
Ability to operate independently in a greenfield program environment.
Preferred Qualifications
Experience integrating external exposure data into ServiceNow workflows for routing and tracking.
Experience improving data quality, deduplication, and correlation across multiple data sources.
Experience working with externally exposed enterprise environments and perimeter infrastructure.
Experience automating data collection, normalization, or correlation using scripting or APIs.
Certifications
Sec+ required.
Higher-level security or risk-related certifications preferred.
Work Location
Hybrid role requiring three days per week in the office. Must be located within Xcel Energy territory and reasonably close to an Xcel Energy facility. Denver, Colorado and Minnesota areas preferred.
As a leading combination electricity and natural gas energy company, Xcel Energy offers a comprehensive portfolio of energy-related products and services to 3.4 million electricity and 1.9 million natural gas customers across eight Western and Midwestern states. At Xcel Energy, we strive to be the preferred and trusted provider of the energy our customers need. If you're ready to be a part of something big, we invite you to join our team.
All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Individuals with a disability who need an accommodation to apply please contact us at View email address on click.appcast.io .
Non-Bargaining
The anticipated starting base pay for this position is: $97,600.00 to $138,600.00 per year
This position is eligible for the following benefits: Annual Incentive Program, Medical/Pharmacy Plan, Dental, Vision, Life Insurance, Dependent Care Reimbursement Account, Health Care Reimbursement Account, Health Savings Account (HSA) (if enrolled in eligible health plan), Limited-Purpose FSA (if enrolled in eligible health plan and HSA), Transportation Reimbursement Account, Short-term disability (STD), Long-term disability (LTD), Employee Assistance Program (EAP), Fitness Center Reimbursement (if enrolled in eligible health plan), Tuition reimbursement, Transit programs, Employee recognition program, Pension, 401(k) plan, Paid time off (PTO), Holidays, Volunteer Paid Time Off (VPTO), Parental Leave
Benefit plans are subject to change and Xcel Energy has the right to end, suspend, or amend any of its plans, at any time, in whole or in part.
In any materials you submit, you may redact or remove age-identifying information including but not limited to dates of school attendance and graduation. You will not be penalized for redacting or removing this information.
Deadline to Apply: 06/21/26
EEO is the Law ( | EEO is the Law Supplement ( | Pay Transparency Nondiscrimination ( | Equal Opportunity Policy (PDF) ( | Employee Rights (PDF) (
All Xcel Energy employees and contractors share responsibility for protecting the company's information and systems by adhering to cybersecurity policies, standards, and best practices, recognizing that cybersecurity is everyone's responsibility.
ACCESSIBILITY STATEMENT
Xcel Energy endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact Xcel Energy Talent Acquisition at View email address on click.appcast.io. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
$131k - $169k
...global leader in AI-powered practice management software for accounting firms. We provide... ...Small Workplaces™ List. Senior Security Engineer Our Engineering Standards at Karbon... ...a fast moving company and you'll get exposure to many different security domains; you...SuggestedWork at officeWork from homeFlexible hoursDay shift- Security Engineer, Vulnerability & Attack Surface Management You will operate across the full vulnerability lifecycle. Act as the technical engine of the VM program... ...to attack surface management using AI‑powered exposure analysis to map external trends and model risk reduction...Suggested
$115k - $130k
...Ibotta is seeking a Security Engineer with a deep expertise in Application Security, Vulnerability Management, and Cloud Infrastructure to join our innovative team and contribute to our mission to Make Every Purchase Rewarding. In this role, you will be ensuring the...SuggestedFull timeLive inWork at officeRelocation packageFlexible hours$218.03k - $256.5k
...most trusted crypto platform. The Identity and Access Management (IAM) program, housed within Security, is a cross-functional team that designs, builds,... ...technical leader within the IAM program, partnering with Engineering, IT, Platform, and business teams to architect and...SuggestedFor contractorsLocal area- ...Vulnerability Management Analyst (AI Training) About the Role We're looking for experienced security practitioners to help evaluate and improve AI systems that reason about... ...management. Your expertise in CVEs, exposure analysis, and remediation workflows will...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
$104k - $156k
...Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will... ...~ Partner with IT on device management, deployment, and lifecycle security... ...standards (e.g., GDPR, HIPAA). ~ Exposure to other cloud platforms(AWS, GCP)....Remote work$188k - $235k
...mission to make the world’s health data secure, accessible and actionable, we provide... ...We’re looking for a Product Security Engineering Manager who can lead a high-performing security... ...security ecosystems, system inventory, or exposure/secrets-related data domains. Prior...$164.11k
EchoStar is looking for a Staff Engineer in Information Technology to design and implement advanced security architectures in Littleton, Colorado. The ideal candidate will have a master's degree in a relevant field and experience in security compliance design. Responsibilities...- ...we deploy deep expertise in operations management and technology to supercharge performance... ...for implementing and monitoring technical security controls to ensure compliance with Re:... ...closely with security, IT personnel, software engineers, and partners across our businesses to...Permanent employmentWork at officeRemote work1 day per week
$160.2k - $183.3k
...Information Security Engineer - Customer Identity Access Management (Western Union, LLC, Denver, CO) Monitor, evaluate, and maintain systems and procedures to safeguard internal information systems and databases and define, implement, maintain information security...Temporary workWork at officeRemote workWork from homeFlexible hours2 days per week3 days per week- ...Security Operations Center (SOC) Information Security Analyst The Business Technologies Division is seeking a qualified Security... ...responding to alerts generated by Security Event and Incident Management (SEIM) platforms, experience with threat hunting, threat client...
$155k - $180k
...matter experts, work on complex projects, and contribute to the value Chatham delivers every day. We are seeking a Security Engineering Manager to lead and evolve our security engineering function within a growing financial risk and advisory SaaS business. This role...Immediate startShift work$92k - $120k
...Description Summary: The Senior IT Security Engineer is responsible for planning, deploying... ...responsibilities include incident response, risk management, and collaboration to enhance security... ..., IdP, IAM, CSPM, DLP, Vulnerability/Exposure Management, CIEM, DevSecOps and SSDLC,...Full timeWork experience placementWork at officeRemote workWork from homeFlexible hours2 days per week$60 - $80 per hour
...Network Security Engineer We are hiring a hands-on Network Security Engineer to support and... ...requires deep experience in Firewall Management, VPN configuration, Network Segmentation... ...trust architecture implementations Exposure to micro-segmentation technologies...Hourly payRemote work- ...SNI has teamed with a valued client in Denver on a search for a Manager of Security Engineering. The Manager of Security Engineering is going to be responsible for leading a team of 5 professionals. The Manager of Security Engineering will work in a hybrid role with one...Work at office
$240k - $310k
...Candid Health Security Leader You will be the first dedicated security leader at Candid Health. You won't just be managing a checklist; you will be building the team and systems that... .... You will partner closely with our Engineering and Product leadership to ensure...Flexible hours$240k - $310k
A leading healthcare technology company seeks a dedicated Security Leader to build and manage their security engineering team. The role requires 10+ years of experience in security, with a strong focus on compliance (HIPAA) and risk management. You will work closely with...- Senior Manager, Security Architecture & Engineering Build the Future with AspenView Technology Partners At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help...Work at officeRemote workFlexible hours
$165.01k - $226.89k
...Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR... ...you! As a Principal Systems Security Engineer, you will act as a key leader in... ...will oversee the security architecture, manage high-stakes security incidents, and provide...Full timeFor contractorsWork experience placementWork at officeImmediate start$97.6k - $138.6k
...re looking for. Role Summary The Security Engineer - Cloud Security (AWS) is responsible for... ...preventative controls to reduce exposure over time. The role operates in an advisory... ...is mature. This position reports to the Manager, Vulnerability Management. Primary Objectives...Temporary workFor contractorsWork at office3 days per week$90k - $120k
...Job Location: Littleton, CO (Hybrid) Security Clearance: Active Secret clearance... ...highly motivated and skilled Vulnerability Management Analyst to join our team. We build... ...exploitability. Work collaboratively with engineering and operations teams to drive timely...Interim role- True Anomaly in Colorado is seeking a Senior Enterprise Security Engineer to lead the Linux security program. You'll architect solutions for centralized identity management and ensure compliance requirements are met while working in a fast-paced environment. Ideal candidates...
$90k - $120k
Job Location: Littleton, CO (Hybrid). Security Clearance: Active Secret clearance required... ...motivated and skilled Vulnerability Management Analyst to join our team. We build mission... .... Work collaboratively with engineering and operations teams to drive timely remediation...Interim role$90k - $120k
A cybersecurity solutions firm in Littleton, CO, is seeking a Vulnerability Management Analyst. This role requires 7+ years of experience in cybersecurity and a strong understanding of vulnerability management tools. The Analyst will perform vulnerability scans, analyze...- Sherpa 6, Inc. is seeking a highly motivated Vulnerability Management Analyst in Littleton, CO (Hybrid) to enhance our cybersecurity efforts. You will play a critical role in identifying, assessing, and tracking vulnerabilities across various software processes, ensuring...
$125k
Manager of Security Engineering & Operations Opportunity: Manager of Security Engineering & Operations Company: FocusConnect Compensation: up to $125k annually + annual leadership bonus opportunity For the technical manager who thrives on working with people and solving...Contract work- ...Impact Starts Here We're looking for a hands-on Staff Security Engineer to own and shape Homebase's Application Security domain.... ...continuous security validation at scale. Own the vulnerability management program: design modern systems for detection, prioritization...Hourly payTemporary workWork at officeLocal areaFlexible hours
$75 - $90 per hour
The Cigna Group is seeking a Security Architect in Denver, Colorado. The role involves collaborating with various teams to enhance security throughout the solution lifecycle. Candidates should have at least 5 years in IT, and 1 year in security architecture, along with...Hourly pay- A security consulting firm is seeking a Principal Consultant to work remotely anywhere in the U.S. The role involves driving technical relationships with clients, leading complex projects, and providing advanced security solutions. Candidates should have a Bachelor's degree...Remote job
- A technology services company is seeking an engineer to deploy, manage, and integrate file transfer systems, including Axway SecureTransport and JIRA. This role requires a strong background in managed FTP and network architecture. The candidate should have excellent communication...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - Exposure Management. Be the first to apply!
- security infrastructure engineer Denver, CO
- senior cloud security engineer Denver, CO
- senior application security engineer Denver, CO
- physical security engineer Denver, CO
- security engineering manager Denver, CO
- endpoint security engineer Denver, CO
- sr information security engineer Denver, CO
- senior security operations engineer Denver, CO
- IT security engineer Denver, CO
- information technology security engineer Denver, CO


