Cyber Exposure Management Engineer

Stefanini International Holdings Ltd

  • Dallas, TX
  • 3 days ago
  • Remote

    Highlights

    During the early stages, the engineer will coordinate tool deployment, onboard business units, normalize data sources, validate integrations, and support solution rollout to ensure accurate visibility and effective operational use. Beyond implementation, the engineer integrates attack surface discovery, vulnerability insights, misconfiguration analysis, identity exposure review, and business context to provide a unified view of cyber risk.

    Numbers & Facts

    LocationDallas, TX (
    Remote
    )

    Description

    Details:

    Stefanini Group is hiring!

    Stefanini is looking for Cyber Exposure Management Engineer-Remote

    For quick apply, please contact Ayush Dwivedi; Ph: 248 728 2636

    [email protected]

    W2 Candidates Only!

    Summary

    The Exposure Management Engineer is responsible for continuously identifying, assessing, validating, and reducing the organization's cyber exposures across on-premises, cloud, and hybrid environments. This role supports both the long-term Exposure Management (CTEM) program and an initial onboarding phase as the organization integrates a new exposure management platform.

    During the early stages, the engineer will coordinate tool deployment, onboard business units, normalize data sources, validate integrations, and support solution rollout to ensure accurate visibility and effective operational use. Beyond implementation, the engineer integrates attack surface discovery, vulnerability insights, misconfiguration analysis, identity exposure review, and business context to provide a unified view of cyber risk. The engineer ensures the organization proactively mitigates high-impact exposures before they are exploited.

    Responsibilities:

    Initial Integrations, Solution Delivery, and Coordination:

    • Lead technical onboarding and configuration of the new exposure management platform.
    • Coordinate data source integrations (cloud, identity, infrastructure, vulnerability scanners, etc.).
    • Validate ingestion accuracy, asset correlation, and exposure signal quality across environments.
    • Partner with engineering, cloud, IAM, and application teams to ensure successful rollout and operational readiness.
    • Assist in defining workflows, reporting structures, and remediation processes that align with CTEM cycles.
    • Document integration steps, system behavior, and operational procedures to support long term program maturity.

    Attack Surface & Asset Visibility:

    • Discover, map, and inventory external and internal attack surfaces across cloud, network, application, and SaaS environments.
    • Identify unknown, shadow, misconfigured, or abandoned assets contributing to organizational exposure.
    • Monitor asset changes and ensure continuous visibility into evolving environments.

    Validation & Prioritization:

    • Prioritize remediation based on active threats, exploitability, data sensitivity, operational criticality, and compensating controls.
    • Align validation and prioritization activities with CTEM cycle objectives.
    • Remediation Support & Tracking
    • Partner with application, infrastructure, cloud, identity, and asset discovery teams to guide remediation plans.
    • Track remediation progress and verify full resolution of exposures.
    • Identify systemic or recurring issues and recommend long term improvements.

    Program Enablement & Governance:

    • Contribute to scoping CTEM cycles and defining focus areas (cloud posture, identity exposures, internet facing risks, etc.).
    • Maintain standards, processes, and documentation for exposure management activities.
    • Provide clear metrics and reporting to leadership on exposure trends, risk posture changes, and remediation performance.
    • Support integration of exposure management activities into broader security architecture and operations.
    • Partner with IAM teams to analyze privilege misuse, identity sprawl, and authentication weaknesses.

    #LI-AD2

    #LI-REMOTE

    Similar Jobs

    See more jobs