Security Engineer II, Attack Surface Management

Apolis

Los Angeles, CA

JOB DETAILS
SALARY
$53–$60.50 Per Hour
SKILLS
Applications Security, Artificial Intelligence (AI), Best Practices, Cloud Applications, Cloud Computing, CompTIA Security+, Computer Science, Computer Security, Consulting, Enterprise Protection, Establish Priorities, Healthcare, Internet of Things, Medical Equipment, Metrics, Performance Metrics, Product Lifecycle, Reporting Dashboards, Risk, Risk Management, Root Cause Analysis, SDL (Specification and Description Language), SSCP - Systems Security Certified Practitioner, Software Engineering, Vulnerability Scanners
LOCATION
Los Angeles, CA
POSTED
30+ days ago
Work Location: Los Angeles, CA 90032 REMOTE
Job Title: Security Engineer II, Attack Surface Management
Assignment Duration: Direct Hire
Salary: $ 53/hr - $60.50/hr
Work Hours: 8:00 AM 5:00 PM
Interview Process: 2 3 steps via Video/Teams
Dress Code: Business Casual

Summary:
The Attack Surface Management (ASM) Security Engineer reduces enterprise risk by continuously discovering assets, identifying vulnerabilities, and driving remediation across infrastructure, cloud, applications, AI and connected/medical/IoT devices. The role supports a proactive, risk-based approach to vulnerability and exposure management aligned with healthcare security best practices.
Minimum Education:
" Associate's degree - Computer Science or a related field OR the equivalent combination of experience and education that would demonstrate the capability to successfully perform the essential functions of this position.
Minimum Experience:
" 5 7+ years in vulnerability management, security engineering, or cloud/app security.
" Experience with vulnerability scanning tools and remediation workflows.
" Strong understanding of CVSS scoring and risk-based prioritization.
Preferred
" Healthcare environment experience is a plus but not required.
" Security certifications such as Security+, SSCP, or cloud security certifications.
Key Responsibilities & Accountabilities:
" Operate continuous asset discovery and vulnerability scanning capabilities.
" Validate, prioritize, and track remediation of vulnerabilities and misconfigurations.
" Support cloud security posture management and configuration hardening.
" Assist with secure development lifecycle (SDL) activities and application risk findings.
" Coordinate medical and IoT device vulnerability remediation and compensating controls.
" Produce metrics, dashboards, and reports to support KPIs and KRIs.
Incident & RACI Expectations:
" Responsible for coordinating the remediation of non-active medical device vulnerabilities.
" Consulted during major incidents to identify root causes and remediation guidance.

About the Company

A

Apolis

Since 1996, RJT has provided successful SAP, Oracle, and IT consulting solutions and staffing services to clients around the world. The new Apolis brings you the same personalized service fortified with a greater array of IT solutions, global expertise, and cost-management strategies.

We are a global IT consultancy that seamlessly integrates experts and leading-edge solutions into your organization so you can focus on what really matters.

COMPANY SIZE
500 to 999 employees
INDUSTRY
Computer/IT Services
EMPLOYEE BENEFITS
Paid Sick Days, Employee Referral Program, Employee Events, Retirement / Pension Plans
WEBSITE
https://www.apolisrises.com/