368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$94k – $137k per year
Location
Remote/Hybrid (Somerville, United States)
Seniority
Staff · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Mass General Brigham is a prominent non-profit healthcare system and integrated network of hospitals and physicians originally founded by Brigham and Women's Hospital and Massachusetts General Hospital. Headquartered in Boston, Massachusetts, the organization serves as a major teaching affiliate for Harvard Medical School and conducts extensive biomedical research. Beyond its primary academic medical centers, the vast health network operates numerous community hospitals, specialty facilities, and health insurance plans to provide comprehensive patient care.
Site: Mass General Brigham Incorporated

Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.

Job Summary

Position Summary

The Mass General Brigham Senior Information Security Analyst - Attack Surface Management Function Lead will be responsible for advancing and coordinating the MGB Attack Surface Management capability across vulnerability discovery, penetration testing, attack surface analysis, and attack simulation. This role will help lead the function into a risk-driven, validation-focused capability that identifies meaningful exposure, prioritizes remediation based on exploitability and business impact, and connects findings to detection engineering, threat hunting, threat intelligence, and broader Cyber Defense priorities.

The ideal candidate is a deeply technical security professional with experience in vulnerability management, offensive security, exposure analysis, penetration testing, or adversary simulation. They should be comfortable translating technical findings into actionable risk narratives, guiding engineers through complex analysis, and helping prioritize work based on business risk, asset criticality, threat relevance, and exploitability.

Key Areas of Experience

  • Vulnerability discovery and vulnerability management
  • Attack surface analysis and exposure management
  • Penetration testing and exploit validation
  • Attack simulation, adversary emulation, or breach and attack simulation

Principal Duties and Responsibilities

  • Vulnerability Discovery: Support and mature processes to identify vulnerabilities across infrastructure, applications, cloud environments, endpoints, and externally exposed assets. Ensure findings are enriched with asset context, ownership, severity, exploitability, and business impact to support effective prioritization and remediation.
  • Attack Surface Analysis: Analyze exposed assets, services, technologies, identities, ownership gaps, and environmental risk to identify meaningful exposure. Translate attack surface data into actionable recommendations for risk reduction.
  • Penetration Testing Coordination: Support penetration testing activities, including scoping, methodology, technical validation, reporting, and remediation follow-up. Ensure findings are clearly documented, risk-ranked, and connected to broader Cyber Defense improvement opportunities.
  • Attack Simulation: Coordinate and support attack simulation and adversary emulation activities to validate security controls, response processes, and detection coverage. Map activity to MITRE ATT&CK where appropriate and recommend improvements to preventive, detective, and response capabilities.
  • Remediation Prioritization: Prioritize remediation activity based on exploitability, asset criticality, business context, exposure, and threat relevance. Partner with technology owners to communicate findings clearly and track remediation through appropriate workflows.
  • Detection and Threat Hunting Handoffs: Partner with Security Detections, Threat Intelligence, and Threat Hunting teams to ensure ASM findings inform detection engineering, hunt development, and intelligence-driven security priorities.
  • Program Maturity: Develop and maintain repeatable processes, SOPs, playbooks, reporting standards, and quality expectations for ASM workflows. Identify opportunities to improve consistency, scalability, and operational maturity across the function.
  • Incident Response Support: Support the incident response team by providing insight into potential attack paths, exploitable vulnerabilities, exposed assets, and adversary techniques that may be relevant during a cyber incident.
  • Written Documentation: Create, review, and update documentation related to attack surface management processes, findings, reports, remediation recommendations, playbooks, and security controls.
  • Communication: Provide clear and concise written and verbal communication, including technical reporting, long-form documentation, stakeholder updates, and executive presentations. Translate technical detail into language appropriate for the intended audience.
  • Industry Knowledge: Maintain awareness of emerging vulnerabilities, attacker techniques, offensive security methods, exposure management practices, and technologies that may impact MGB’s security posture.
  • MGB Values: Use Mass General Brigham values to guide decisions, actions, and behaviors, including Patients, Affordability, Accountability & Service Commitment, Decisiveness, Innovation & Thoughtful Risk, Diversity & Inclusion, Integrity & Respect, Learning, Continuous Improvement & Personal Growth, and Teamwork & Collaboration.

• Other duties as assigned.

Qualifications

Education

  • Associate’s degree in a related field of study required, or bachelor’s degree in a related field of study required.
  • Experience may be accepted in lieu of a degree.

Licenses and Credentials

  • Relevant professional certifications preferred or required, such as GCIH, GPEN, CISSP, OSCP, or similar credentials.

Experience

  • 5-7 years of relevant experience required.

Knowledge, Skills, and Abilities

  • Authority in cybersecurity concepts within the role’s domain.
  • Proficient understanding of cybersecurity concepts outside of a specific individual domain.
  • Expertise with the tools and solutions supported by the team.
  • Ability to apply original and innovative thinking to produce new ideas.
  • Strong leadership, communication, and project management skills.
  • Strong decision-making skills, with the ability to weigh the relative costs and benefits of potential actions and identify the most appropriate path forward.

Additional Job Details (if applicable)

Working Model Required

  • Monday-Friday, Eastern business hours.
  • Onsite presence required one day per week.
  • Flexibility required for additional onsite days for meetings or business needs, as planned and scheduled.
  • Remote workdays require a stable, secure, quiet, and compliant workstation using MGB-provided equipment.

Remote Type

Hybrid

Work Location

399 Revolution Drive

Scheduled Weekly Hours

40

Employee Type

Regular

Work Shift

Day (United States of America)

Pay Range

$93,953.60 - $136,739.20/Annual

Grade

7At Mass General Brigham, we believe in recognizing and rewarding the unique value each team member brings to our organization. Our approach to determining base pay is comprehensive, and any offer extended will take into account your skills, relevant experience if applicable, education, certifications and other essential factors. The base pay information provided offers an estimate based on the minimum job qualifications; however, it does not encompass all elements contributing to your total compensation package. In addition to competitive base pay, we offer comprehensive benefits, career advancement opportunities, differentials, premiums and bonuses as applicable and recognition programs designed to celebrate your contributions and support your professional growth. We invite you to apply, and our Talent Acquisition team will provide an overview of your potential compensation and benefits package.

EEO Statement:

0100 Mass General Brigham Incorporated is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religious creed, national origin, sex, age, gender identity, disability, sexual orientation, military service, genetic information, and/or other status protected under law. We will ensure that all individuals with a disability are provided a reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. To ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Veteran’s Readjustment Act of 1974, and Title I of the Americans with Disabilities Act of 1990, applicants who require accommodation in the job application process may contact Human Resources at (857)-282-7642.

Mass General Brigham Competency Framework

At Mass General Brigham, our competency framework defines what effective leadership “looks like” by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused, half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance, make hiring decisions, identify development needs, mobilize employees across our system, and establish a strong talent pipeline.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Somerville
Cybersecurity Manager 4 hours ago
$113k – $227k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Lake Forest • Saint Paul • Chicago
Cybersecurity
CVSS
FedRAMP
GDPR
ISO 27001
MITRE ATT&CK
SOC 2
Apply
$60k – $149k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Ottobrunn • Ulm
Python
AI/ML
Red Teaming
Cybersecurity
MITRE ATT&CK
Apply
Инженер SIEM 7 hours ago
$22k – $54k per year (Estimated) • Remote/Hybrid • Full-Time • Moscow
Bash
Python
Cybersecurity
MITRE ATT&CK
Apply
$17k – $21k per year (Estimated) • Remote/Hybrid • Full-Time • Bucharest
DevOps
Azure
GCP
Incident Management
Splunk
Cybersecurity
Google SecOps
MITRE ATT&CK
Apply
$20k – $44k per year (Estimated) • Remote • Full-Time • 5+ years exp • Minsk
Bash
PowerShell
Python
DevOps
AWS
Azure
Azure DevOps
Bicep
CI/CD
CloudFormation
Datadog
Docker
GCP
GitHub
GitHub Actions
GitLab
GitLab CI
IAM
Jenkins
Kubernetes
Splunk
Terraform
Cybersecurity
Aqua Security
CIS Benchmarks
CWE
Falco
HIPAA
ISO 27001
Kubescape
Kyverno
Least Privilege
Microsoft Sentinel
MITRE ATT&CK
OPA Gatekeeper
OWASP Top 10
PCI DSS
Prisma Cloud
SBOM
SOC 2
Threat Modeling
Trivy
Zero Trust
Open Policy Agent
Apply
Research Data Analyst 8 hours ago
$52k – $101k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • United States
Python
R
R
Bioconductor
Apply
$94k – $137k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Somerville
Apply
$75k – $110k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Somerville
DevOps
AWS
Azure
GCP
Management
ServiceNow
Apply
$90k – $130k per year • Remote/Hybrid • Contractor • 3+ years exp • Somerville • Boston
JavaScript
PHP
TypeScript
PHP
Drupal
Frontend
Angular
Less
React.js
Svelte
Vue.js
Apply
$75k – $110k per year • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Somerville
DevOps
GitLab
Apply
Staff Data Engineer 3 days ago
$148k – $185k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Berkeley • Somerville
Java
Python
Scala
Python
pySpark
Databases
Apache Iceberg
Apache Kafka
ClickHouse
Databricks
Delta Lake
Druid
InfluxDB
Snowflake
TimescaleDB
PostgreSQL
AI/ML
Airflow
Dagster
dbt
Prefect
Spark
Time Series Forecasting
DevOps
AWS
Pulumi
Rest API
Terraform
Amazon Kinesis
IoT
MQTT
OPC UA
Apply
$132k – $209k per year • In office • 6+ years exp • Bachelor's Degree • Somerville
AI/ML
Fine-tuning
LLM
Multimodal AI
NLP
AI Agents
Function Calling
DevOps
AWS
GCP
Cybersecurity
GDPR
Apply
Renewals Specialist 6 days ago
$62k – $123k per year (Estimated) • Remote/Hybrid • 1+ year exp • Somerville
DevOps
GitHub
QA
Swagger
Apply
$94k – $137k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Somerville
Apply
$75k – $110k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Somerville
DevOps
AWS
Azure
GCP
Management
ServiceNow
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.