Verified current Job

Threat Mitigation Lead - Network and Systems Attack Surface

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Mitigation Lead - Network and Systems Attac

Job Remote Full source details
Jobgether Source published Oct 2, 2026 Verified 3 hours ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Mitigation Lead - Network and Systems Attac

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Threat Mitigation Lead - Network and Systems Attack Surface based in the United States. This role leads strategic and technical efforts to reduce cybersecurity risk across a complex technology environment. You’ll translate vulnerability, exposure, and threat intelligence into focused remediation campaigns with clear owners, priorities, and timelines. The position combines hands-on security expertise with cross-functional leadership across cyber defense, infrastructure, applications, and security engineering teams. You’ll help automate and improve remediation workflows while ensuring mitigation requirements are properly implemented and validated. As a technical anchor for the threat surface management function, you’ll mentor analysts and strengthen the team’s capabilities. The role offers an opportunity to influence enterprise security strategy while working with emerging threats, vulnerabilities, and adversary techniques. Success requires strong technical judgment, communication skills, and the ability to drive meaningful outcomes without relying on direct authority.

Lead vulnerability, exposure, and threat mitigation campaigns from intake through closure, establishing clear priorities, ownership, targets, and timelines. Analyze threat intelligence and exposure data to identify and prioritize risks using factors such as CVSS, EPSS, KEV, active exploitation intelligence, and adversary TTPs. Develop and implement solutions that accelerate remediation, including automation for triage, deduplication, ownership identification, and stakeholder notification. Track remediation progress, remove blockers, escalate stalled or high-severity items, and maintain accountability through to completion. Capture root causes, technical recommendations, and lessons learned and translate them into sustainable improvements for security and remediation processes. Support application, platform, and infrastructure teams in interpreting mitigation requirements and developing practical security plans. Validate security controls and mitigation evidence within GRC systems, ensuring records are complete, accurate, and ready for closure. Serve as a technical subject matter expert for the threat surface management analyst community, leading technical investigations into vulnerabilities, threat intelligence, and adversary behavior. Identify capability gaps, mentor analysts, and develop strategies that expand the threat surface management team's effectiveness. Build strong working relationships with cyber defense, identity and access management, security architecture and engineering, platform, and other cybersecurity teams. Advise cybersecurity leadership and business stakeholders by translating technical risk and remediation information into clear, actionable decisions. Requirements Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related discipline. At least 5 years of experience in threat surface management, vulnerability management, cyber defense, or a closely related cybersecurity discipline. At least 3 years of experience scoping and driving remediation or mitigation campaigns to completion across teams without direct management authority. At least 3 years of experience working with threat intelligence and exposure data and applying it to risk prioritization. Strong knowledge of vulnerability and threat prioritization frameworks and signals, including CVSS, EPSS, KEV, adversary TTPs, and active exploitation reporting. Hands-on experience with security control technologies such as vulnerability scanning and prioritization platforms, endpoint detection and response (EDR), and security information and event management (SIEM) systems. Demonstrated technical leadership experience, including mentoring analysts, leading technical deep dives, and developing team capabilities without formal authority. Experience automating remediation workflows, particularly processes involving triage, deduplication, ownership identification, or stakeholder notification. Experience collaborating with cyber defense, security operations, or threat intelligence functions. Experience in a regulated environment with formal control validation, compliance, and audit requirements is advantageous. Relevant certifications such as CISSP, OSCP, GIAC Enterprise Vulnerability Assessor (GEVA), or equivalent are preferred. Excellent communication skills, with the ability to explain complex technical threats and remediation requirements to both technical and business audiences. Strong analytical, problem-solving, risk-management, and attention-to-detail skills. Benefits Base salary range of $129,000–$253,000 , depending on education, experience, skills, and geographic location. Eligibility for a company incentive bonus based partly on organizational and individual performance. 401(k) retirement savings plan. Pension benefits. Vacation and other paid leave benefits. Medical, dental, vision, and prescription drug coverage for eligible employees. Flexible benefits, including healthcare and/or dependent-care options. Life insurance and death benefits. Employee assistance programs and wellness/fitness benefits. Employee clubs, activities, and employee resource groups. Workplace accommodation support for qualified applicants with disabilities. Full-time employment with the opportunity to work on enterprise-scale cybersecurity initiatives and emerging threat challenges.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books