Haystack
← Back to Jobs
Technology
RD

Senior Cyber Exposure Management Analyst

Randstad DigitalDC🇺🇸United StatesPosted 29 Aug 2026

Quick Overview

Salary
$55 - $60/hr
Seniority
Mid Senior
Work mode
Hybrid
Location
DC, United States
Posted
22 hours ago
401kComplianceSCADAServiceNow

Job Description

job summary:

Randstad is seeking a Senior Cyber Exposure Management Analyst for a premier client located in Washington, DC. In this high-visibility role, you will lead the identification, risk-based prioritization, and remediation coordination of security exposures, vulnerabilities, misconfigurations, and attack paths across both enterprise IT and operational technology (OT) environments. Operating within modern Continuous Threat Exposure Management (CTEM) and NIST framework guidelines, you will serve as a strategic partner to Technology Owners, Security Engineering, Cloud Services, and OT stakeholders, leveraging threat intelligence, business impact metrics, and asset criticality data to translate complex technical risks into actionable executive insights and drive measurable risk reduction.





location: Washington, Washington, D.C.

job type: Contract

salary: $55 - 60 per hour

work hours: 9am to 5pm

education: Bachelors



responsibilities:

Conduct continuous vulnerability, misconfiguration, and exposure assessments across complex infrastructure, applications, networks, cloud services, and OT/ICS/SCADA environments.


Lead risk-based prioritization and cross-functional remediation coordination using asset criticality, exploitability, threat intelligence, and business impact context.


Utilize and optimize enterprise exposure and vulnerability management tools, including Tenable, Qualys, Rapid7, Microsoft Defender, and ServiceNow.


Perform external attack surface management (EASM) and detailed attack-path analysis to identify and mitigate security control gaps.


Develop cybersecurity metrics, executive dashboards, and tracking frameworks to report overall enterprise exposure and compliance status to senior leadership.


Partner with IT, Cloud, Network, Security Engineering, Cyber Fusion, and OT operational teams to ensure timely remediation while accommodating operational safety, system availability, and vendor constraints.


Translate complex technical vulnerability data into clear business and operational risk assessments for diverse technical and non-technical stakeholders.




qualifications:

Demonstrated experience supporting large, complex enterprise cybersecurity programs, with proven expertise in exposure management and risk-based vulnerability prioritization.


Hands-on technical experience with OT, ICS, or SCADA environments, including an understanding of maintenance windows, operational safety, and system availability constraints.


Practical knowledge of major industry frameworks and controls, including NIST CSF, NIST SP 800-53, and CIS Controls.


Proficiency with enterprise-grade scanning, exposure management, and ticketing platforms (Tenable, Qualys, Rapid7, Defender, ServiceNow).


Strong technical writing and communication skills, with a track record of effective cross-functional stakeholder engagement and executive reporting.


Relevant industry certifications strongly preferred (e.g., CISSP, CISM, CRISC, CISA, GICSP, GSEC, Security+, CASP+, or equivalent).




skills:

CIS Controls,Cloud,Cloud Services,Security+,enterprise cybersecurity,Cyber Fusion,executive dashboards,operational technology (OT),Qualys,ServiceNow,vulnerability management tools,SCADA,system availability,communication skills,leadership,business impact,assessments,CISM,CISA,CISSP,CRISC,GSEC,GICSP,NIST CSF,NIST SP 800-53,industry frameworks,infrastructure,maintenance,metrics,NIST,operational risk,path analysis,executive reporting,risk,risks,Exposure Management,risk reduction,safety,security control,Security Engineering,stakeholder engagement,strategic partner,technical writing,vulnerabilities,vulnerability




Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.

At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact

Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).

This posting is open for thirty (30) days.


Similar jobs