Lead Attack Surface Management Engineer

2 weeks ago


Allen, United States Experian Full time
Company Description

Experian is the world’s leading global information services company. During life’s big moments – from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers – we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control and access financial services, businesses to make smarter decisions and thrive, lenders to lend more responsibly, and organizations to prevent identity fraud and crime.

We have 20,000 people operating across 44 countries and every day we’re investing in new technologies, talented people, and innovation to help all our clients maximize every opportunity.

Job Description

The Lead Attack Surface Management Engineer - External is responsible for all activities related to the execution and management of the External Attack Surface Management Program, with the goal to ensure comprehensive visibility and actionability of Experian’s external attack surface, exposures, and vulnerabilities, thus minimizing Experian’s risk potential. This role acts as a subject matter expert for the team, and owns the systems and tools for the group.

Responsibilities:

  • Owns and executes External Attack Surface Management processes and procedures to continuously monitor and improve visibility of the attack surface in order to detect anomalies faster and reduce incidences or potential of cyber-attacks.
  • Manages the EASM platform and service provider to deliver consistent and reliable scanning of Experian’s complete external-facing digital footprint.
  • Is responsible for managing and maintaining integrations between the EASM platform and Experian services.
  • Lead contributor EASM expertise daily to the Cyber Fusion Center to ensure information, discoveries, and actions are well communicated and understood.
  • Performs verification/validation testing for vulnerabilities in external-facing web sites, web applications, and services; demonstrates exploitation steps and verify remediation/fixes.
  • Oversees and owns comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniques.
  • Engage with IT and geographically dispersed business stakeholders to ensure they fully understand their Attack Surface and helps them identify prioritization of vulnerabilities.
  • Develops vulnerability KPIs/metrics to demonstrate coverage and remediation effectiveness.
  • Execute daily operations of the External Attack Surface Management program, including the interpretation of scanning results.
  • Plays key role in assisting with the identification of internal and external risks based on scanning results, including attribution of ownership.
  • Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.
Qualifications
  • Four-year college diploma or university degree in computer science or computer engineering, and/or 4 additional years' equivalent work experience.

  • 3+ years of experience managing security tools, preferably for large organization.

  • 5+ in information security vulnerability management role.

  • 8+ total years in security and/or technology engineering or implementation roles.

  • Certification that could be helpful but not required: CISSP, Security+, CEH, OSCP, GIAC certifications.

  • Familiarity with common web vulnerabilities including: XSS, XXE, SQL Injection, Deserialization Attacks, Path Traversal Attacks, Remote Execution Flaws, and Authentication Flaws.

  • Understanding of common web application frameworks and web-based APIs.

  • Experience with one or more scripting languages such as Bash, Python, Perl, PowerShell, etc.

  • Working knowledge of networking standards and protocols: IPv4 IPv6, TCP/IP, DNS, HTTPS, TLS, BGP, Firewalls and NAT, SMTP, VPN, ICMP, SSH, IPSec, etc.

  • Demonstrable knowledge of architecture, engineering, and operations of one or more vulnerability management tools, such as Wiz, Qualys, Rapid7, and ServiceNow.

  • Demonstrable understanding of the application one or more of the following frameworks and how they are applied to identifying and rating risk: OWASP, SANS, NIST, CIS, and MITRE ATT&CK.

  • Knowledge of major cloud platforms (AWS, Azure, or GCP).

  • Knowledge of systems hardening and other risk mitigation factors on multiple technologies and operating systems (Window, Linux, Mac, routers, switches, Kubernetes).

  • A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies.

  • Applied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management and security and controls.

  • Excellent interpersonal skills and strong verbal and written communication. Able to communicate ideas in both technical and user-friendly language.

  • Strong organizational skills with proven ability to manage multiple high visibility issues simultaneously.

  • Proactive attitude, seeking for improvement opportunities which can positively impact the security posture and the business.

  • Willing to travel globally as required

Additional Information

All your information will be kept confidential according to EEO guidelines.

Experian is proud to be an Equal Opportunity and Affirmative Action employer. Our goal is to create a thriving, inclusive and diverse team where people love their work and love working together. We believe that diversity, equity and inclusion is essential to our purpose of creating a better tomorrow. We value the uniqueness of every individual and want you to bring your whole, authentic self to work. For us, this is The Power of YOU and and it reflects what we believe.  See our DEI work in action

Please contact us at JobPostingInquiry@experian.com to request the salary range of this position (please include the exact Job Title as it reads above in your email). In addition to a competitive base salary and variable pay opportunity, Experian offers a comprehensive benefits package including health, life and disability insurance, generous paid time off including 12 company paid holidays and parental and family care leave, an employee stock purchase plan and a 401(k) plan with a company match.

Experian Careers - Creating a better tomorrow together

Find out what its like to work for Experian by clicking here

Our compensation reflects the cost of labor across several U.S. geographic markets. The base pay range for this position is listed above.  Within this range, individual pay is determined by work location and additional factors such as job-related skills, experience and education.  This position is also eligible for a variable pay opportunity and a comprehensive benefits package which includes health, life and disability insurance, generous paid time off including paid parental and family care leave, an employee stock purchase plan and a 401(k) plan with a company match.

Experian is proud to be an Equal Opportunity and Affirmative Action employer. We’re passionate about unlocking the power of data to transform lives and create opportunities for consumers, businesses, and society. For more than 125 years, we’ve helped people and economies flourish – and we’re not done.

We take our people’s agenda very seriously. We focus on what truly matters; diversity and inclusion, work/life balance, flexible working, development, collaboration, wellness, reward & recognition, volunteering, making an impact... the list goes on. See our DEI work in action

The power of YOU. We are building a culture where everyone is comfortable bringing their whole self to work. A place where we not only respect our differences and values but celebrate them in a positive and supportive environment.

Find out what is like to work for Experian and discover the Unexpected



  • Allen, United States Experian Full time

    Company Description Experian is the world’s leading global information services company. During life’s big moments – from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers – we empower consumers and our clients to manage their data with confidence. We help individuals to take financial...


  • Allen, United States Experian Full time

    Job DescriptionAs a Site Reliability Engineering Manager, you will lead a global team of talented SREs in the development, deployment, and continuous improvement of our Cyber Threat Detection Pipeline. You will leverage cutting-edge technologies such as Splunk Enterprise Security, Exabeam Advanced Analytics (UEBA), Security Data Lakes (e.g., Data Bricks or...


  • Allen, United States Experian Full time

    Company Description Experian is the world's leading global information services company. During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control and...


  • Allen, United States Experian Full time

    Company Description Experian is the world’s leading global information services company. During life’s big moments – from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers – we empower consumers and our clients to manage their data with confidence. We help individuals to take financial...

  • Lead Data Scientist

    2 weeks ago


    Allen, United States London Stock Exchange Full time

    Join our team to redefine the landscape of financial services through the lens of Risk Intelligence Innovation! We're looking for a Data Scientist who is ready to dive into the dynamic fields of digital identity, and fraud. You will be crucial in shaping the future of these areas. We are searching for a candidate who is not only passionate about risk...


  • Allen, Texas, United States Experian Full time

    Job Description As a Site Reliability Engineering Manager, you will lead a global team of talented SREs in the development, deployment, and continuous improvement of our Cyber Threat Detection Pipeline. You will leverage cutting-edge technologies such as Splunk Enterprise Security, Exabeam Advanced Analytics (UEBA), Security Data Lakes (e.g., Data Bricks or...

  • Assistant Team Lead

    2 weeks ago


    Allen, United States Goodwill of Dallas Full time

    Partner with the Manager to mentor, coach, motivate and supervise Warehouse and Collection employees. Lead by example to ensure that all procedures and best practices are consistently followed. Comply with Agency policies and Donated Goods Retail sta Store Manager, Assistant Store Manager, Team Lead, Assistant, Lead, Manager


  • Allen, United States Kuraray America , Inc. Full time

    Company Description About us, but we’ll be brief Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for . In addition, for the last five years...

  • Operations Manager

    1 week ago


    Allen, United States CY9 Full time

    Role and Responsibilities:Delivery & Execution: Responsible for the successful execution of Telecommunications Network Planning, Design, Field operations and Software Solutions projects across USEnsuring quality, on time delivery of the projects with minimum hand holding from the customerAnalyzing the daily project report and foreseeing the risks if any and...

  • Operations Manager

    1 week ago


    Allen, United States CY9 Full time

    Role and Responsibilities:Delivery & Execution: Responsible for the successful execution of Telecommunications Network Planning, Design, Field operations and Software Solutions projects across USEnsuring quality, on time delivery of the projects with minimum hand holding from the customerAnalyzing the daily project report and foreseeing the risks if any and...

  • Operations Manager

    1 week ago


    Allen, United States CY9 Full time

    Role and Responsibilities:Delivery & Execution: Responsible for the successful execution of Telecommunications Network Planning, Design, Field operations and Software Solutions projects across USEnsuring quality, on time delivery of the projects with minimum hand holding from the customerAnalyzing the daily project report and foreseeing the risks if any and...

  • Sales Lead

    4 weeks ago


    Allen, United States Paper Source Full time

    Job Summary: , As a Sales Lead (SL), you model great selling behaviors - you love selling our products and make the customer experience exceptional by sharing your knowledge with your team and your customers. Your desire to lead the team and manage the store supports the achievement of sales goals, efficiencies and operational excellence. As a leader, you...


  • Allen, TX, United States London Stock Exchange Group Full time

    Join our team to redefine the landscape of financial services through the lens of Risk Intelligence Innovation. We're looking for a Machine Learning Engineer who is ready to dive into the dynamic fields of digital identity, and fraud. You will be crucial in shaping the future of these areas. We are searching for a candidate who is not only passionate about...


  • Allen, United States Octopi Brewing Co. Full time

    Description Job Summary: The Process and Automation Engineer is integral to the Octopi team’s engineering function, delivering a comprehensive range of engineering services aligned with strategic direction and operational needs. This role focuses on implementing efficient ways of working, closely integrated with the brewery's automation and control...


  • Allen Park, United States Kyyba Full time

    Job Details: Must Have Skills: • Good Knowledge in AUTOSAR project and experience in project involving AUTOSAR based functional safety • Good Understanding in ASPICE Process and implementation experience • Demonstrated skills in C, C+, C++ and assembly language and experience with scripting languages Nice to have skills Detailed Job Description: Scope...


  • Allen Park, United States Kyyba Full time

    Job Details: Must Have Skills: • Good Knowledge in AUTOSAR project and experience in project involving AUTOSAR based functional safety • Good Understanding in ASPICE Process and implementation experience • Demonstrated skills in C, C+, C++ and assembly language and experience with scripting languages Nice to have skills Detailed Job Description: Scope...


  • Allen, United States Ramboll Group AS Full time

    Waterfront and Dams Senior Project Engineer We invite you to bring your energy, experience, and professionalism into play as you contribute to innovative and high-quality design solutions. To succeed in this role, you must have structural engineering experience in dams, hydraulic structures, and waterfront resiliency structures for ports and harbors. Are you...


  • Allen Park, United States Optimal CAE Full time

    Position Description: We create lifetime value for our customers by delivering a software development environment that is purposeful and differentiated with simplicity and ingenuity to generate sustainable returns. We equip the enterprise to derive value from all forms of data to generate sustainable savings through automation and team integration. In the...


  • Allen Park, United States Optimal CAE Full time

    Position Description: We create lifetime value for our customers by delivering a software development environment that is purposeful and differentiated with simplicity and ingenuity to generate sustainable returns. We equip the enterprise to derive value from all forms of data to generate sustainable savings through automation and team integration. In the...

  • Project Engineer

    4 weeks ago


    Glen Allen, United States GAI Consultants Full time

    GAI Consultants, Inc. is seeking a Project Engineer to work with the Power Generation Business Sector on primarily renewable energy projects and when needed other regional projects. GAI Consultants, Inc. offers its employees, upon approval by supervisors, the ability to work remotely or in a hybrid setting, and this position is eligible for a sign-on bonus....