Why This Role Stands Out
This hybrid role offers a fantastic opportunity to shape and lead a critical security program from the ground up, with competitive hourly compensation of $65-70. You'll thrive here if you possess senior-level CTEM/ASM experience and are eager to drive strategic initiatives, enhance operational processes, and build a mature attack surface management program. Don't miss out on this chance to make a significant impact!
Quick Overview
Job Description
Job Title: CTEM / ASM Architect / Lead
Location: Milpitas, CA or Irvine, CA
Work Model: Hybrid
Engagement Type: Contract-to-Hire
Start Date: To be confirmed
Pay Rate: $65-70 per hr
Required Experience: Senior-level CTEM / ASM experience
Top Skills
- Asset Discovery and Inventory
- Vulnerability Management
- Cloud Security Posture Management
- Web Application Security
- API Integration and Automation
Summary
We are seeking a CTEM / Attack Surface Management (ASM) Architect / Lead to help design, lead, and operationalize the maturity of the organization s ASM program.
The current ASM environment is in a nascent stage, with processes that are largely manual and ad hoc. This role will provide the senior-level leadership, structure, and strategic direction required to establish a more mature and scalable attack surface management program.
The Architect / Lead will work hands-on with the existing ASM team, providing day-to-day direction on vulnerability prioritization, identifying risks related to existing architecture and security tooling, and improving operational processes.
In addition to driving operational improvements, this role will be responsible for developing a cohesive CTEM / ASM strategy and partnering with internal stakeholders to define a long-term roadmap. The roadmap will align attack surface visibility and exposure management capabilities with broader organizational security objectives.
Key Responsibilities
Asset Discovery and Inventory- Lead and mature asset discovery and inventory processes across the organization.
- Perform and oversee passive and active asset discovery and scanning.
- Conduct DNS enumeration and certificate-transparency analysis.
- Identify and maintain visibility into cloud assets across AWS, Azure, and Google Cloud Platform.
- Work with asset discovery and inventory platforms such as RunZero and Claroty.
- Identify unknown, unmanaged, or previously undiscovered assets across the environment.
- Lead vulnerability identification, assessment, triage, and prioritization.
- Perform CVE triage and CVSS-based assessment.
- Work with vulnerability-management platforms including Qualys, Tenable, Rapid7, Invicti, and Nessus.
- Establish practical vulnerability prioritization frameworks based on technical exposure and business risk.
- Identify vulnerabilities requiring immediate remediation based on exposure, exploitability, and organizational impact.
- Work with existing security teams to improve vulnerability remediation workflows.
- Manage and mature external attack surface visibility and monitoring capabilities.
- Identify exposed systems, services, domains, applications, and infrastructure.
- Work with platforms such as Censys, Shodan, IONIX, CyCognito, Axonius, and Mandiant ASM.
- Identify shadow IT, unknown internet-facing assets, exposed services, and other external attack-surface risks.
- Establish repeatable processes for continuous monitoring and exposure identification.
- Assess cloud environments for security posture and exposure risks.
- Apply CSPM concepts to identify cloud misconfigurations and security weaknesses.
- Identify exposed cloud resources, including S3 buckets, APIs, identities, services, and other internet-facing assets.
- Work across AWS, Azure, and Google Cloud Platform environments.
- Partner with cloud and infrastructure teams to prioritize and remediate cloud exposure.
- Analyze IP addresses, CIDR ranges, and network infrastructure.
- Perform BGP and ASN lookups to understand external network ownership and exposure.
- Conduct port and service fingerprinting.
- Review firewall rules and identify unnecessary or risky exposure.
- Assess externally accessible infrastructure and services from an attacker s perspective.
- Conduct subdomain enumeration and web asset discovery.
- Identify exposed administrative interfaces and potentially vulnerable internet-facing applications.
- Identify shadow IT and unmanaged web applications.
- Perform web technology fingerprinting to understand application exposure.
- Identify security gaps across externally accessible web applications and services.
- Integrate threat intelligence into CTEM and ASM processes.
- Map exposed assets and vulnerabilities to relevant threat actor TTPs.
- Use OSINT techniques to identify additional organizational exposure.
- Perform reconnaissance using tools and techniques such as WHOIS, Shodan, Google dorks, recon-ng, and Maltego.
- Maintain an attacker-perspective approach when assessing external exposure.
- Support basic dark-web monitoring and exposure identification.
- Develop automation to reduce manual ASM and CTEM processes.
- Build and integrate APIs with security and exposure-management platforms.
- Use scripting languages such as Python, Bash, and Golang.
- Automate asset discovery, enrichment, alert processing, and exposure-management workflows.
- Build automated alert and remediation pipelines where appropriate.
- Improve consistency, scalability, and operational efficiency through automation.
- Integrate ASM and CTEM findings into existing SIEM and SOAR workflows.
- Route critical exposure findings into security monitoring and response processes.
- Integrate findings with ticketing and workflow-management platforms such as Jira and ServiceNow.
- Support automated enrichment, escalation, and remediation workflows.
- Ensure relevant attack-surface findings are actionable for security operations teams.
- Translate technical attack-surface exposure into understandable business-risk language.
- Establish risk-based prioritization approaches for executive stakeholders.
- Develop and maintain KPIs and KRIs for CTEM / ASM performance.
- Create executive-facing dashboards and reports.
- Track exposure trends over time.
- Report on asset visibility, vulnerability trends, remediation progress, and overall exposure reduction.
Required Qualifications
- Strong senior-level experience in Continuous Threat Exposure Management (CTEM), Attack Surface Management (ASM), or closely related security domains.
- Hands-on experience with asset discovery, attack-surface visibility, and exposure management.
- Strong understanding of passive and active scanning, DNS enumeration, certificate transparency, and cloud asset discovery.
- Experience with vulnerability-management processes, including CVE triage, CVSS scoring, vulnerability prioritization, and remediation.
- Experience with vulnerability-management tools such as Qualys, Tenable, Rapid7, Invicti, or Nessus.
- Strong understanding of external attack-surface management concepts and tooling.
- Experience with CSPM concepts and cloud security exposure across AWS, Azure, and/or Google Cloud Platform.
- Strong knowledge of networking concepts including IP/CIDR, BGP, ASN, ports, services, and firewall exposure.
- Experience with web application reconnaissance, subdomain discovery, technology fingerprinting, and exposed-application identification.
- Strong OSINT and reconnaissance capabilities.
- Experience with tools such as Shodan, WHOIS, Google dorks, recon-ng, or Maltego.
- Hands-on scripting or automation experience using Python, Bash, and/or Golang.
- Experience integrating security platforms through APIs.
- Familiarity with SIEM/SOAR, Jira, ServiceNow, and security workflow integrations.
- Ability to translate technical security findings into business-risk language.
- Strong analytical, communication, documentation, and stakeholder-management skills.
- Ability to work effectively with security, infrastructure, cloud, application, and business stakeholders.
Preferred Qualifications
- Experience building or maturing a CTEM / ASM program from a nascent or manual state.
- Experience with RunZero, Claroty, Censys, Shodan, IONIX, CyCognito, Axonius, or Mandiant ASM.
- Experience across multiple cloud platforms including AWS, Azure, and Google Cloud Platform.
- Experience with dark-web monitoring and threat-intelligence integrations.
- Experience developing executive-level KPI/KRI dashboards and exposure-management reporting.
- Experience establishing long-term CTEM / ASM strategies and security roadmaps.
- Experience integrating ASM findings with enterprise SIEM, SOAR, ITSM, and remediation workflows.
- Strong understanding of attacker reconnaissance techniques and external exposure assessment.
Similar jobs
- SC
Senior Program Development Manager (Clearance Required) with Security Clearance
NewSciTec, Inc.
Herndon, VA🇺🇸$182k - $232k/yrHybrid20 hours ago - LH
Part Time Floor Leader - Jordan Creek Town Center
NewLush Handmade Cosmetics
West Des Moines🇺🇸$17/hrHybrid3 hours agoSOAPArticulateReconciliation - LH
Seasonal Ambassador - Roosevelt Field
NewLush Handmade Cosmetics
Garden City🇺🇸Hybrid3 hours agoSOAPArticulateReconciliation - LE
Client Services Representative
NewLendingTree
Seattle🇺🇸Hybrid4 hours agoSalesforceMicrosoft Office - LH
Seasonal Ambassador - Destiny USA Mall
NewLush Handmade Cosmetics
Syracuse🇺🇸$17/hrHybrid5 hours agoSOAPArticulateReconciliation - LH
Seasonal Ambassador - Stonestown Galleria
NewLush Handmade Cosmetics
San Francisco🇺🇸Hybrid6 hours agoSOAPArticulateReconciliation