Skip to content
Remote Co Logo
  • Remote
    JOBS
  • Remote
    COMPANIES
  • Remote Work
    RESOURCES
    • Remote Work Articles
    • Remote Worker Q&A
  • Get Started
  • Log In
  • Home
  • Remote Jobs
  • Senior Information Security Analyst - Attack Surface Management Lead
Mass General Brigham

Senior Information Security Analyst - Attack Surface Management Lead

Mass General Brigham

ApplySave Job
  • Date Posted

    Today

    New!
  • Remote Work Level

    Hybrid Remote

  • Location

    Hybrid Remote in Somerville, MA

  • Job Schedule

    Full-Time

  • Salary

    $93,953 - $136,739 ANNUALLY

  • Categories

    IT,  Cyber Security,  Consulting,  Product Manager,  Project Manager,  QA,  Software Engineer

  • Job Type

    Employee

  • Career Level

    Experienced

  • Travel Required

    No Specification

  • Education Level

    We're sorry, the employer did not include education information for this job.

About the Role

Title: Senior Information Security Analyst - Attack Surface Management Lead

Location: Somerville United States

Full time

Hybrid

Job Description:

Site: Mass General Brigham Incorporated

Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.

Job Summary

Position Summary

The Mass General Brigham Senior Information Security Analyst - Attack Surface Management Function Lead will be responsible for advancing and coordinating the MGB Attack Surface Management capability across vulnerability discovery, penetration testing, attack surface analysis, and attack simulation. This role will help lead the function into a risk-driven, validation-focused capability that identifies meaningful exposure, prioritizes remediation based on exploitability and business impact, and connects findings to detection engineering, threat hunting, threat intelligence, and broader Cyber Defense priorities.

The ideal candidate is a deeply technical security professional with experience in vulnerability management, offensive security, exposure analysis, penetration testing, or adversary simulation. They should be comfortable translating technical findings into actionable risk narratives, guiding engineers through complex analysis, and helping prioritize work based on business risk, asset criticality, threat relevance, and exploitability.

Key Areas of Experience

  • Vulnerability discovery and vulnerability management
  • Attack surface analysis and exposure management
  • Penetration testing and exploit validation
  • Attack simulation, adversary emulation, or breach and attack simulation

Principal Duties and Responsibilities

  • Vulnerability Discovery: Support and mature processes to identify vulnerabilities across infrastructure, applications, cloud environments, endpoints, and externally exposed assets. Ensure findings are enriched with asset context, ownership, severity, exploitability, and business impact to support effective prioritization and remediation.
  • Attack Surface Analysis: Analyze exposed assets, services, technologies, identities, ownership gaps, and environmental risk to identify meaningful exposure. Translate attack surface data into actionable recommendations for risk reduction.
  • Penetration Testing Coordination: Support penetration testing activities, including scoping, methodology, technical validation, reporting, and remediation follow-up. Ensure findings are clearly documented, risk-ranked, and connected to broader Cyber Defense improvement opportunities.
  • Attack Simulation: Coordinate and support attack simulation and adversary emulation activities to validate security controls, response processes, and detection coverage. Map activity to MITRE ATT&CK where appropriate and recommend improvements to preventive, detective, and response capabilities.
  • Remediation Prioritization: Prioritize remediation activity based on exploitability, asset criticality, business context, exposure, and threat relevance. Partner with technology owners to communicate findings clearly and track remediation through appropriate workflows.
  • Detection and Threat Hunting Handoffs: Partner with Security Detections, Threat Intelligence, and Threat Hunting teams to ensure ASM findings inform detection engineering, hunt development, and intelligence-driven security priorities.
  • Program Maturity: Develop and maintain repeatable processes, SOPs, playbooks, reporting standards, and quality expectations for ASM workflows. Identify opportunities to improve consistency, scalability, and operational maturity across the function.
  • Incident Response Support: Support the incident response team by providing insight into potential attack paths, exploitable vulnerabilities, exposed assets, and adversary techniques that may be relevant during a cyber incident.
  • Written Documentation: Create, review, and update documentation related to attack surface management processes, findings, reports, remediation recommendations, playbooks, and security controls.
  • Communication: Provide clear and concise written and verbal communication, including technical reporting, long-form documentation, stakeholder updates, and executive presentations. Translate technical detail into language appropriate for the intended audience.
  • Industry Knowledge: Maintain awareness of emerging vulnerabilities, attacker techniques, offensive security methods, exposure management practices, and technologies that may impact MGB's security posture.
  • MGB Values: Use Mass General Brigham values to guide decisions, actions, and behaviors, including Patients, Affordability, Accountability & Service Commitment, Decisiveness, Innovation & Thoughtful Risk, Diversity & Inclusion, Integrity & Respect, Learning, Continuous Improvement & Personal Growth, and Teamwork & Collaboration.
  • Other duties as assigned.

Qualifications

Education

  • Associate's degree in a related field of study required, or bachelor's degree in a related field of study required.
  • Experience may be accepted in lieu of a degree.

Licenses and Credentials

  • Relevant professional certifications preferred or required, such as GCIH, GPEN, CISSP, OSCP, or similar credentials.

Experience

  • 5-7 years of relevant experience required.

Knowledge, Skills, and Abilities

  • Authority in cybersecurity concepts within the role's domain.
  • Proficient understanding of cybersecurity concepts outside of a specific individual domain.
  • Expertise with the tools and solutions supported by the team.
  • Ability to apply original and innovative thinking to produce new ideas.
  • Strong leadership, communication, and project management skills.
  • Strong decision-making skills, with the ability to weigh the relative costs and benefits of potential actions and identify the most appropriate path forward.

Additional Job Details (if applicable)

Working Model Required

  • Monday-Friday, Eastern business hours.
  • Onsite presence required one day per week.
  • Flexibility required for additional onsite days for meetings or business needs, as planned and scheduled.
  • Remote workdays require a stable, secure, quiet, and compliant workstation using MGB-provided equipment.

Remote Type

Hybrid

Work Location

399 Revolution Drive

Scheduled Weekly Hours

40

Employee Type

Regular

Work Shift

Day (United States of America)

Pay Range

$93,953.60 - $136,739.20/Annual

Grade

7

At Mass General Brigham, we believe in recognizing and rewarding the unique value each team member brings to our organization. Our approach to determining base pay is comprehensive, and any offer extended will take into account your skills, relevant experience if applicable, education, certifications and other essential factors. The base pay information provided offers an estimate based on the minimum job qualifications; however, it does not encompass all elements contributing to your total compensation package. In addition to competitive base pay, we offer comprehensive benefits, career advancement opportunities, differentials, premiums and bonuses as applicable and recognition programs designed to celebrate your contributions and support your professional growth. We invite you to apply, and our Talent Acquisition team will provide an overview of your potential compensation and benefits package.

Apply

FAQs About Senior Information Security Analyst - Attack Surface Management Lead Jobs at Mass General Brigham

This job offers Hybrid Remote Work.
Full-Time
$93,953 - $136,739 ANNUALLY
IT, Cyber Security, Consulting, Product Manager, Project Manager, QA, Software Engineer
You can apply directly using the apply button given on the page.
Residents of Somerville, MA or United States
The work location for this position will be Somerville, MA
Experienced
The employer has not disclosed any minimum education requirements for this job

Meet Remote.co

  • About & Contact
  • CCPA/GDPR
  • Do Not Sell or Share My Personal Information
  • Fraud Awareness
  • Press & Media
  • Sitemap

Remote Work Q&A

  • All Remote Companies
  • Why Remote
  • Hiring Remotely
  • Managing Remotely
  • Working Remotely
  • Remote Worker Insights
  • All Remote Workers

Remote Work Articles

  • All Articles
  • Why Go Remote
  • Build a Remote Team
  • Remote Management
  • Work Remotely

Remote Jobs

  • Find Remote Jobs
  • Remote Accounting Jobs
  • Remote Account Manager Jobs
  • Remote Bookkeeping Jobs
  • Remote Customer Service Jobs
  • Online Data Entry Jobs
  • Remote Data Science Jobs
  • Remote Design Jobs
  • Remote Developer Jobs
  • Online Editing Jobs
  • Remote Healthcare Jobs
  • Remote IT Jobs
  • Remote Marketing Jobs
  • Remote Medical Coding Jobs
  • Remote Nursing Jobs
  • Remote Legal Jobs

More Remote Jobs

  • Remote Operations Jobs
  • Remote Product Manager Jobs
  • Remote Project Manager Jobs
  • Remote QA Jobs
  • Remote Recruiter Jobs
  • Remote Sales Jobs
  • Remote Social Media Jobs
  • Online Teaching Jobs
  • Virtual Assistant Jobs
  • Remote Writing Jobs
  • Entry-Level Remote Jobs
  • Online Freelance Jobs
  • International Remote Jobs
  • Part-Time Remote Jobs
© 2015 - 2026 Remote.co | TOS | Privacy Policy | Manage Cookies | Accessibility
Next App