Skip to content

Open nowPosted 12 hours agoWe saw it 53 min after it went up

Threat Mitigation Lead - Network and Systems Attack Surface

Jobgether4,394 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowThreat Mitigation Lead - Network and Systems Attack SurfaceJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 12 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Mitigation Lead - Network and Systems Attack Surface based in the United States.

This role leads strategic and technical efforts to reduce cybersecurity risk across a complex technology environment. You’ll translate vulnerability, exposure, and threat intelligence into focused remediation campaigns with clear owners, priorities, and timelines. The position combines hands-on security expertise with cross-functional leadership across cyber defense, infrastructure, applications, and security engineering teams. You’ll help automate and improve remediation workflows while ensuring mitigation requirements are properly implemented and validated. As a technical anchor for the threat surface management function, you’ll mentor analysts and strengthen the team’s capabilities. The role offers an opportunity to influence enterprise security strategy while working with emerging threats, vulnerabilities, and adversary techniques. Success requires strong technical judgment, communication skills, and the ability to drive meaningful outcomes without relying on direct authority.

Accountabilities

  • Lead vulnerability, exposure, and threat mitigation campaigns from intake through closure, establishing clear priorities, ownership, targets, and timelines.
  • Analyze threat intelligence and exposure data to identify and prioritize risks using factors such as CVSS, EPSS, KEV, active exploitation intelligence, and adversary TTPs.
  • Develop and implement solutions that accelerate remediation, including automation for triage, deduplication, ownership identification, and stakeholder notification.
  • Track remediation progress, remove blockers, escalate stalled or high-severity items, and maintain accountability through to completion.
  • Capture root causes, technical recommendations, and lessons learned and translate them into sustainable improvements for security and remediation processes.
  • Support application, platform, and infrastructure teams in interpreting mitigation requirements and developing practical security plans.
  • Validate security controls and mitigation evidence within GRC systems, ensuring records are complete, accurate, and ready for closure.
  • Serve as a technical subject matter expert for the threat surface management analyst community, leading technical investigations into vulnerabilities, threat intelligence, and adversary behavior.
  • Identify capability gaps, mentor analysts, and develop strategies that expand the threat surface management team's effectiveness.
  • Build strong working relationships with cyber defense, identity and access management, security architecture and engineering, platform, and other cybersecurity teams.
  • Advise cybersecurity leadership and business stakeholders by translating technical risk and remediation information into clear, actionable decisions.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related discipline.
  • At least 5 years of experience in threat surface management, vulnerability management, cyber defense, or a closely related cybersecurity discipline.
  • At least 3 years of experience scoping and driving remediation or mitigation campaigns to completion across teams without direct management authority.
  • At least 3 years of experience working with threat intelligence and exposure data and applying it to risk prioritization.
  • Strong knowledge of vulnerability and threat prioritization frameworks and signals, including CVSS, EPSS, KEV, adversary TTPs, and active exploitation reporting.
  • Hands-on experience with security control technologies such as vulnerability scanning and prioritization platforms, endpoint detection and response (EDR), and security information and event management (SIEM) systems.
  • Demonstrated technical leadership experience, including mentoring analysts, leading technical deep dives, and developing team capabilities without formal authority.
  • Experience automating remediation workflows, particularly processes involving triage, deduplication, ownership identification, or stakeholder notification.
  • Experience collaborating with cyber defense, security operations, or threat intelligence functions.
  • Experience in a regulated environment with formal control validation, compliance, and audit requirements is advantageous.
  • Relevant certifications such as CISSP, OSCP, GIAC Enterprise Vulnerability Assessor (GEVA), or equivalent are preferred.
  • Excellent communication skills, with the ability to explain complex technical threats and remediation requirements to both technical and business audiences.
  • Strong analytical, problem-solving, risk-management, and attention-to-detail skills.
  • Base salary range of $129,000–$253,000, depending on education, experience, skills, and geographic location.
  • Eligibility for a company incentive bonus based partly on organizational and individual performance.
  • 401(k) retirement savings plan.
  • Pension benefits.
  • Vacation and other paid leave benefits.
  • Medical, dental, vision, and prescription drug coverage for eligible employees.
  • Flexible benefits, including healthcare and/or dependent-care options.
  • Life insurance and death benefits.
  • Employee assistance programs and wellness/fitness benefits.
  • Employee clubs, activities, and employee resource groups.
  • Workplace accommodation support for qualified applicants with disabilities.
  • Full-time employment with the opportunity to work on enterprise-scale cybersecurity initiatives and emerging threat challenges.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.