Haystack
← Back to Jobs
Other
PI

CTEM / ASM Architect / Lead

Prama Innovations India Pvt. Ltd.Irvine, CA🇺🇸United StatesPosted Sep 14, 2026

Why This Role Stands Out

This on-site role offers a significant opportunity to shape and lead a critical security program, driving impactful change within a growing company. You'll thrive here if you have expertise in asset discovery, vulnerability management, and cloud security, and are eager to build robust strategies and mentor a team. Apply today to make your mark and advance your career in a dynamic environment.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Irvine, CA, United States
Posted
3 days ago
AWSAzureBashDNSGoGoogle CloudJiraPythonServiceNowTriage

Job Description

Location: Milpitas, CA
Work Model: Onsite 4 days/week; flexible when needed
Employment Type: Contract-to-Hire

Non-Negotiable Skills

  • Asset Discovery & Inventory
  • Vulnerability Management
  • Cloud Security Posture
  • Web Application Security
  • API & Automation

Role Overview

We are seeking a Continuous Threat Exposure Management (CTEM) / Attack Surface Management (ASM) Architect to design, lead, and operationalize the maturation of the ASM program.

The current environment is relatively nascent, with largely manual and ad hoc processes. This role will provide senior-level leadership, establish structure and discipline, and develop the strategy and roadmap for the ASM program.

The candidate will work hands-on with the existing ASM team, provide guidance on vulnerability prioritization, identify architectural and tooling risks, and partner with stakeholders to improve attack-surface visibility and exposure management.

Key Skills

  • Asset discovery and inventory
    • Passive/active scanning
    • DNS enumeration
    • Certificate transparency
    • Cloud asset discovery across AWS, Azure, and Google Cloud Platform
    • RunZero, Claroty
  • Vulnerability Management
    • CVE triage
    • CVSS scoring
    • Qualys, Tenable, Rapid7, Invicti, Nessus
    • Vulnerability prioritization frameworks
  • External Attack Surface Management
    • Censys, Shodan, IONIX, CyCognito
    • Axonius, Mandiant ASM
  • Cloud Security Posture
    • CSPM concepts
    • Cloud misconfiguration detection
    • Exposed S3 buckets, APIs, and other cloud assets
  • Network & Infrastructure
    • IP/CIDR
    • BGP/ASN lookups
    • Port/service fingerprinting
    • Firewall rule analysis
  • Web Application Security
    • Subdomain enumeration
    • Exposed administrative panels
    • Shadow IT detection
    • Web technology fingerprinting
  • Threat Intelligence / OSINT
    • Threat actor TTP mapping
    • OSINT and reconnaissance
    • WHOIS, Shodan, Google dorks, recon-ng, Maltego
    • Dark web monitoring basics
  • APIs & Automation
    • Python, Bash, Golang
    • Security platform API integrations
    • Alert pipeline automation
  • SIEM/SOAR
    • ASM-to-detection workflows
    • Jira / ServiceNow integrations
  • Risk Quantification & Reporting
    • Translating technical exposure into business risk
    • KPI/KRI development
    • Executive-facing dashboards

Similar jobs