Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Analyst Consultant - Attack Surface Management

$110k - $140k

Kalles Group

ABOUT KALLES GROUP:

Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.

While our expertise spans multiple disciplines, our method remains consistent: building trust and relationship with people -- whether you are a client, a consultant, or--in this case--a candidate.

No matter what role you come from--whether you're an executive or just starting your career-you can expect our highest level of attention and respect. We want to find the right fit for each role, but we also want you to find the right fit for your career.

We believe the best way to show you what our team is like is to treat you like you're already a part of it . We hope you'll consider joining our team of experienced professionals who are building their careers at Kalles Group-and having fun while doing it.

WHAT YOU WILL DO:


As a Senior Security Analyst Consultant - Attack Surface Management , you will lead and evolve our client's enterprise Attack Surface Management (ASM) program, helping reduce cyber risk through proactive discovery, analysis, automation, and collaboration. This is a highly visible role that combines strategic leadership with hands-on technical execution, requiring expertise across vulnerability management, cloud security, threat intelligence, and offensive security disciplines.

You will be responsible for developing a comprehensive view of the organization's attack surface, identifying opportunities to reduce exposure, and driving remediation efforts in partnership with engineering, cloud, DevOps, and security teams. Leveraging data, automation, and threat intelligence, you will help prioritize risk reduction initiatives while influencing architectural decisions that strengthen the organization's security posture. This role is ideal for someone who enjoys building programs, solving complex security challenges, and partnering across the enterprise to create meaningful security outcomes.

KEY RESPONSIBILITIES:

  • Lead and mature the organization's Attack Surface Management (ASM) program , identifying opportunities to expand capabilities and improve visibility
  • Develop and maintain a comprehensive understanding of the enterprise attack surface across cloud, network, and application environments
  • Continuously identify, assess, and prioritize vulnerabilities and exposures based on business and security risk
  • Partner with security, engineering, infrastructure, and cloud teams to drive remediation efforts and reduce risk
  • Leverage metrics and analytics to measure program effectiveness and inform risk-based decision making
  • Conduct external reconnaissance activities, OSINT research, and threat intelligence analysis to identify potential exposure points
  • Monitor emerging threats, attacker techniques, and industry trends to proactively strengthen defensive capabilities
  • Collaborate with Application Security, DevOps, and Cloud Engineering teams to promote secure-by-design practices
  • Contribute to incident response investigations and post-incident analysis as needed
  • Design and implement automation solutions that improve visibility, efficiency, and risk management workflows
  • Develop and maintain operational standards, procedures, documentation, and runbooks
  • Mentor team members and share expertise across security domains
  • Support compliance initiatives including PCI DSS, SOC 2, and related regulatory requirements
  • Validate security controls and identify opportunities for continuous improvement
ABOUT YOU:
  • Your values:
    • Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly.
    • Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
    • Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.
YOUR EXPERIENCE:
Required Qualifications
  • 6+ years of experience in cybersecurity, including security operations, threat hunting, offensive security, red teaming, or related disciplines
  • Experience building, scaling, or leading Attack Surface Management (ASM) capabilities and programs
  • Strong understanding of vulnerability management methodologies and risk prioritization frameworks
  • Experience working within multi-cloud environments, including AWS, Azure, and GCP
  • Deep knowledge of attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK
  • Expertise in network security, cloud security, attack path analysis, and external attack surface discovery
  • Experience conducting OSINT, reconnaissance, and threat intelligence activities
  • Proficiency with scripting and automation technologies such as Python and PowerShell
  • Strong understanding of enterprise infrastructure, application architectures, and data flows
  • Ability to evaluate and influence architectural decisions that reduce organizational risk
  • Experience leading cross-functional security initiatives and driving collaboration across multiple teams
  • Excellent written and verbal communication skills with the ability to communicate effectively with both technical and non-technical stakeholders
  • Strong analytical and problem-solving skills with a data-driven approach to risk management
Preferred Qualifications

  • Industry certifications such as CISSP, OSCE, GREM, or similar cybersecurity credentials
  • Experience applying AI and automation technologies to security operations or attack surface management programs
  • Experience with cloud-native security platforms and exposure management tooling
  • Familiarity with threat modeling, purple teaming, or advanced adversary simulation exercises
  • Experience working in large-scale enterprise environments with complex security requirements
WHAT WE OFFER:
  • The annual salary range for this role is $110,000-$140,000.
  • We offer Medical, Dental, Vision plans, 401K with matching, and PTO for salaried employees.
  • Work/life balance - we know there's more to life than work! We encourage our team to pursue other passions, get outside, and spend time with family. We work with clients and consultants to set expectations for a manageable workload.

LOCATION:

This role can be remote, but we have a strong preference for client who live in Seattle, WA.


HOW TO APPLY:

Please fill out the form below (including uploading your most recent resume) and we'll be in touch! We know imposter syndrome can be a barrier to many great applicants. We hope you'll still consider applying. That's why we've made the application process as short and simple as possible.

Even if you're not a fit for the role, you can expect to hear back from us! We want you to have the best experience as a candidate, so please feel free to share feedback at any stage of the process to View email address on click.appcast.io.

Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed, nationality, race, ethnicity, disability, gender, or other protected class.
Vacancy posted 16 hours ago
Similar jobs that could be interesting for youBased on the Security Analyst Consultant - Attack Surface Management in Seattle, WA vacancy
  • $136.2k - $178.7k

     ...people. About this team The Security Operations Center (SOC) is responsible...  ...As a Senior Cybersecurity Analyst, you will apply deep...  ...investigations involving advanced attack techniques, forensic analysis...  ...establishing vulnerability management approaches integrating threat... 
    Suggested
    Permanent employment
    Full time
    Part time
    Local area
    Immediate start
    Work visa

    Lululemon Athletica

    Seattle, WA
    21 hours ago
  • $18k

     ...ITSM Security Analyst - WA ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum of Risk Management, Compliance... 
    Suggested
    For contractors
    Work experience placement
    Work at office
    Immediate start
    Flexible hours

    ProSidian Consulting

    Seattle, WA
    2 days ago
  •  ...AI / Emerging Tech Security Analyst (AI Training) About the Role What if your security...  ...powerful AI systems defend themselves against attack? We're looking for AI Security Analysts...  ...of security threat modeling, attack surfaces, and risk classification Familiar... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    3 days ago
  • $191k - $253k

     ...cutting-edge technology and proactive security. Focused on safeguarding our mission, people...  ...team is looking for a Staff Security Analyst to protect our organization from...  ...implementing controls to reduce Anduril's attack surface from an insider threat. Produce metrics... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Seattle, WA
    2 days ago
  • $120k - $140k

     ...Join to apply for the Consultant - Endpoint Security Analyst role at Kalles GroupJoin to apply for the Consultant - Endpoint Security Analyst role at...  ...design and implement a standardized approach to Patch Management across their organization. This role plays a key part in... 
    Suggested
    Remote work
    Flexible hours

    Kalles Group

    Seattle, WA
    1 day ago
  • $100k - $130k

    Senior Security Operations Analyst OCT Consulting is a business management and technology consulting firm that supports Federal Government clients. We provide consulting services in the areas of Strategy, Process Improvement, Change Management, Program and Project Management... 
    Contract work
    Temporary work
    Remote work

    OCT Consulting, LLC

    Seattle, WA
    4 days ago
  • $100k - $120k

    Journeyman Information Security Analyst OCT Consulting is a business management and technology consulting firm that provides support to Federal Government clients. We provide consulting services in the areas of Strategy, Process Improvement, Change Management, Program... 
    Contract work
    Temporary work
    Work at office

    OCT Consulting, LLC

    Seattle, WA
    2 days ago
  • $114.5k - $179.1k

    A global technology company is looking for a Senior Information Security Analyst to provide guidance on information security, focusing on risk assessments and security architectures. The role requires 8+ years of IT experience and includes advising on legal statutes. Notable... 

    PACCAR

    Renton, WA
    4 days ago
  • $80k - $105k

    A leading construction firm in Seattle seeks an Information Security Analyst to enhance its security posture. The ideal candidate will have...  ...in information security, focusing on vulnerability management, auditing, and risk assessment. Responsibilities include leading... 

    JHKelly, LLC

    Seattle, WA
    1 day ago
  • $23 - $25 per hour

     ...to join a dynamic team focused on preventing cargo loss and ensuring timely deliveries. As part of the Cargo Signal team, you will manage real-time monitoring and customer communication, utilizing advanced technology to support effective logistics operations. Applicants... 
    Hourly pay

    Expeditors International

    Seattle, WA
    1 day ago
  •  ...Offensive Security Analyst (Structured / Non-Exploit) About the Role What if your hard-won knowledge of how real attacks unfold could directly shape how AI understands cyber threats? We're looking for Offensive Security Analysts to bring adversarial thinking to... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    3 days ago
  •  ...Senior Security Analyst Who we are We are an innovative performance apparel...  ...networks, devices, and data from malicious attack, damage, or unauthorized access....  ...firewalls, IDS/IPS, anti spam, content management, server and network device hardening, etc... 

    Procyon TS

    Seattle, WA
    21 hours ago
  •  ...SOC 2 - Junior Security Analyst Location: Hybrid – local - Seattle, WA Role Description...  ...networks, devices, and data from malicious attack, damage, or unauthorized access....  ...firewalls, IDS/IPS, anti-spam, content management, server and network device hardening, etc... 
    Work experience placement
    Work at office
    Local area

    RIT Solutions

    Seattle, WA
    2 days ago
  •  ...Security Analyst Who we are We are an innovative performance apparel company for yoga,...  ...networks, devices, and data from malicious attack, damage, or unauthorized access....  ...firewalls, IDS/IPS, anti-spam, content management, server and network device hardening, etc... 
    Work experience placement
    Work at office

    Kaav Inc.

    Seattle, WA
    1 day ago
  • $23 - $25 per hour

     ...real‑time monitoring using advanced cargo sensors, our team of security and logistics professionals keeps an eye on shipments in transit...  ...monitor customer shipments, analyze cargo risk events, and manage response protocols. Agents communicate directly with customers... 
    Hourly pay
    Work at office
    Local area
    Worldwide
    Shift work
    Afternoon shift

    Expeditors International

    Seattle, WA
    1 day ago
  • $166k - $220k

     ...Senior Security Operations Analyst Seattle, Washington, United States Anduril Industries is a defense technology company with a mission to...  ...identity, application, and cloud infrastructure Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows,... 
    Full time
    Work experience placement

    anduril

    Seattle, WA
    2 days ago
  • $146k

     ...re building a more open world. Join us.Security Analyst IIIOur Technology Team partners with teams...  ...advanced cybersecurity (vulnerability management, threat hunting, specialization areas...  ...solutions.Provide in-depth knowledge of cyber-attack analysis and cyber kill-chain... 
    Local area
    Immediate start
    Flexible hours
    Shift work

    Expedia Group

    Seattle, WA
    4 days ago
  • Alignerr is looking for Offensive Security Analysts who can leverage their expertise in cyber threats to shape AI understanding. The role is remote and flexible, requiring analysis of attack paths and identification of weaknesses in production environments. Ideal candidates... 
    Remote job
    Flexible hours

    Alignerr

    Seattle, WA
    3 days ago
  • A leading recruitment firm in Seattle seeks an Information Security Analyst to manage operations of the Agency's Information Security program. This role involves supporting service owners, handling security incidents, and ensuring systems' confidentiality and integrity... 

    Insight Global

    Seattle, WA
    21 hours ago
  • $191k - $225k

    Overview Staff Security Analyst, Threat Intelligence - Join us in building the future of finance...  ...’s business operations. Investigate attacker infrastructure across domains, DNS,...  ...pipelines, data analysis tools, and case management systems to scale analysis and... 
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood

    Bellevue, WA
    21 hours ago
  •  ...Security Analyst Position Type: Contract (08-11-2025 - 02-13-2026) Location: Seattle, WA - Hybrid Primary Skills: SOX, Azure, Oracle...  ...remediation. Assists with quarterly SOX control certifications and management attestations. Automates and assists in gathering audit... 
    Permanent employment
    Contract work

    Staffing the Universe

    Seattle, WA
    2 days ago
  •  ...Ping Security Analyst Location: Seattle, WA / Plano, TX / St. Louis, MO Duration: Fulltime Job Description: PingFederate,...  ...Adapters and contract mapping in PingFederate ~ Access Token Management, Access Token Mapping, OIDC policies in PingFederate ~... 
    Full time
    Contract work
    Immediate start
    Relocation

    JConnect Infotech

    Seattle, WA
    1 day ago
  • $136k - $187k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking...  ...customers so they can effectively manage their risk. As a senior level analyst of Customer Assurance, you will...  ...simply answering questions) to a "consultant" (helping the customer and Field... 
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    Okta, Inc.

    Bellevue, WA
    2 days ago
  •  ...PCI Security Analyst Location: Seattle, WA (Hybrid) Duration: 10/07/2024 - 04/11/2025 Rate: DOE US Citizens & Green Card holders are preferred. Qualifications: ~5+ years in Security GRC or a related field with in-depth working knowledge of PCI DSS Standards (3... 
    Remote work

    Georgia IT Inc

    Seattle, WA
    2 days ago
  • $120k - $130k

     ...ability • Setting up Idp and SP connections, Policies, Selectors, Adapters and contract mapping in PingFederate • Access Token Management, Access Token Mapping, OIDC polices in PingFederate • Creating Applications, Rules, Rulesets, coarse grain authorization etc in... 
    Contract work

    Tata Consultancy Services

    Seattle, WA
    2 days ago
  •  ...cybersecurity team enables us to conduct its global operations in a secure manner and safeguard the trusted information of its guests and...  ...our team, we are looking for an experienced PCI Security Analyst, with demonstrated expertise in the Payment Card Industry - Data... 
    Remote work

    Kaav Inc.

    Seattle, WA
    1 day ago
  •  ...Overview: Cybersecurity GRC Security Analyst - Risk and Issue Management Who we are We are a yoga-inspired technical apparel company up to big things. The practice and philosophy of yoga informs our overall purpose to elevate the world through the power of... 

    Voluble Systems LLC

    Seattle, WA
    3 days ago
  •  ...Request ID: 86391-1 Title: Ping security Analyst Location: Seattle WA 98108 Open to 100% on-site: Dallas/ Plano 75024 or St. Louis...  ...contract mapping in PingFederate Knowledge of Access Token Management, Access Token Mapping, and OIDC policies in PingFederate... 
    Contract work
    Work experience placement

    Artech Inc

    Seattle, WA
    3 days ago
  •  ...experience. What you will do: • Engineer, deploy, and support a multitude of class-leading cyber security toolsets • ssist our team of SOC analysts with Incident Response activities and participate in an on-call support rotation. You will be required to... 
    Remote work
    Weekend work

    Omni Inclusive

    Bellevue, WA
    21 hours ago
  •  ...Security Operations Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of intelligent security systems - and we need experienced SOC professionals to make it happen. Your hands-on knowledge of real-... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Analyst Consultant - Attack Surface Management. Be the first to apply!