Mimecast Logo

Mimecast

Attack Surface Management Specialist

Posted 11 Days Ago
Be an Early Applicant
In-Office
Lexington, MA
124K-186K Annually
Senior level
In-Office
Lexington, MA
124K-186K Annually
Senior level
Lead and improve Attack Surface Management initiatives, enhancing security strategies and automating processes while coordinating cross-functional teams and managing vulnerabilities.
The summary above was generated by AI

We are seeking an advanced Attack Surface Management (ASM) professional to join Mimecast's Information Security organization as a Senior ASM Specialist. This is a strategic, hands-on role leading the design, implementation, and continuous improvement of our attack surface reduction initiatives. The successful candidate will bring strong technical expertise in ASM methodologies and broad project management capabilities.

What You'll Do:

Attack Surface Management Strategy & Architecture

  • Lead the design and evolution of comprehensive attack surface management strategies aligned with organizational risk reduction targets
  • Architect ASM discovery, monitoring, and validation frameworks that identify and track external assets across cloud, network, and application environments
  • Develop and implement advanced detection methodologies for shadow IT and rogue assets
  • Establish baseline metrics and KPIs for attack surface visibility and coordinate their achievement across security operations teams

Process Improvement & Automation

  • Make improvements to existing ASM processes, tools, and workflows; own the end-to-end execution of these enhancements, improve automation
  • Evaluate and drive adoption of new ASM tooling, platforms, and technologies.
  • Improve team efficiency and document standard operating procedures

Cross-Functional Leadership & Collaboration

  • Communicate with security operations, vulnerability management, infrastructure, development, and business teams to establish priorities.
  • Gain organizational cooperation on the adoption of new ASM processes and procedures by clearly demonstrating business value
  • Coordinate with external stakeholders including cloud service providers, domain registrars, and security vendors
  • Partner with the vulnerability management function to ensure discovered all assets are properly scanned, classified, and prioritized

Vulnerability & Risk Management Integration

  • Ensure attack surface visibility feeds directly into vulnerability management workflows and Jira tracking systems
  • Prioritize discovered assets and vulnerabilities using business impact, EPSS scoring
  • Support executive reporting on attack surface reduction progress
  • Maintain oversight of critical vulnerabilities tied to external-facing assets and coordinate remediation timelines

Complex Project Management

  • Manage complex, multi-phase ASM initiatives with general oversight; define scope, timelines, resource requirements, and success criteria
  • Lead projects such as cloud security posture assessments, third-party risk management integrations, or regional attack surface reduction campaigns
  • Work with minimal day-to-day direction; escalate strategic decisions and blockers appropriately to leadership
  • Track project health through metrics and maintain stakeholder visibility on progress and risks

Threat Intelligence & Compliance Integration

  • Incorporate relevant threat intelligence (zero-day vulnerabilities, attack trends, industry-specific risks) into attack surface prioritization decisions
  • Ensure processes align with compliance (SOC 2, ISO 27001, regional data protection)
  • Contribute to security assessments and audit responses related to external assets.

What You'll Bring:

  • 6+ years of experience in information security, with at least 4 years directly focused on attack surface management, external vulnerability management, or asset discovery
  • Advanced technical knowledge, methodologies and tools (e.g., Tenable, Shodan, Rapid7 Insight VM, Qualys VMDR, or similar platforms)
  • Broad knowledge of project management methodologies; experience managing complex, multi-stakeholder initiatives, ability to design and implement process improvements
  • Strong understanding of cloud security (AWS, Azure, GCP), network reconnaissance, and vulnerability assessment
  • Excellent written and verbal communication skills; ability to explain complex security concepts to technical and non-technical audiences
  • Experience with JIRA, vulnerability management workflows, and security automation tools
  • Bachelor's degree in Computer Science/Information Security or equivalent professional experience
  • Experience with threat intelligence platforms and CSIRT coordination
  • Knowledge of OWASP, NIST Cybersecurity Framework, or similar security standards
  • Experience in responsible disclosure program management
  • Experience in a large SaaS organization, world distributed security teams

The base salary range for this position is $124,000−$186,000 plus benefits. This range represents the minimum and maximum new hire compensation for this role. The position may also be eligible for incentive plans and additional benefits, in accordance with company policy and local regulations. Our salary ranges are determined by role, level, and location with individual compensation also dependent on factors such as qualifications, experience, and skills. Final offers will reflect these considerations and may vary accordingly.

#LI-ND1

Belonging at Mimecast

Cybersecurity is a community effort. That’s why we’re committed to building an inclusive, diverse community that celebrates and welcomes everyone – unless they’re a cybercriminal, of course.

We’re proud to be an Equal Opportunity and Affirmative Action Employer, and we’d encourage you to join us whatever your background. We particularly welcome applicants from traditionally underrepresented groups.

We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won’t affect your application.

If you require any adjustments or accommodations due to a disability, or any other reason that may help you in your interview process, please let us know by emailing [email protected].

Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.

Top Skills

AWS
Azure
GCP
JIRA
Qualys Vmdr
Rapid7 Insight Vm
Shodan
Tenable

Mimecast Lexington, Massachusetts, USA Office

191 Spring St, Lexington, MA, United States, 02421

Similar Jobs

An Hour Ago
In-Office
Needham, MA, USA
28-37 Hourly
Internship
28-37 Hourly
Internship
Beauty • Robotics • Design • Appliances • Manufacturing
The Mechanical Engineering Co-op involves working on product design and development, collaborating with engineers and designers, prototyping, testing, and analyzing performance of consumer products.
Top Skills: ArduinoCadCreoPythonRaspberry PiSolidworks
An Hour Ago
In-Office
Needham, MA, USA
26-35 Hourly
Internship
26-35 Hourly
Internship
Beauty • Robotics • Design • Appliances • Manufacturing
The Product Development Co-op will support product optimization, define product specifications, and enhance user experience in a fast-paced environment.
Top Skills: ExcelMicrosoft Suite (WordOutlook)PowerPoint
An Hour Ago
In-Office
Needham, MA, USA
26-35 Hourly
Internship
26-35 Hourly
Internship
Beauty • Robotics • Design • Appliances • Manufacturing
The Retail Excellence Systems & Analytics Co-op supports data analytics and digital systems for SharkNinja's Global Retail Excellence organization, enhancing retail execution with actionable insights and system management.
Top Skills: AirtableJIRAPower BISalesforce

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account