Attack Surface Management Engineer (JR229558)

<strong>To heal, to teach, to discover and to advance the health of the communities we serve.<br /></strong><br /> <p>To learn more about the &ldquo;Montefiore Difference&rdquo; &ndash; who we are at Montefiore and all that we have to offer our associates, please click <strong><a href="https://healthymebenefits.com/" target="_blank" title="Montefiore Difference" rel="noopener noreferrer">here</a></strong>.&nbsp;</p>

Elmsford, New York

Montefiore

<h4 class=""><strong>WHY TOP TALENT PICKS MONTEFIORE EINSTEIN&nbsp;<br /><br /></strong>Since its inception in 1884, Montefiore Einstein&rsquo;s mission has been to heal, to teach, to discover and advance the health of the communities we serve.<br /><br />Montefiore Einstein&rsquo;s state-of-the-art facilities include the&nbsp;<span class="">internationally-recognized</span>&nbsp;Children&rsquo;s Hospital at Montefiore Einstein and our Notable Centers of Excellence - Montefiore Einstein Center for Cancer Care, Montefiore Einstein Center for Heart and Vascular Care, Montefiore Einstein Center for Transplantation. Combined with a growing number of locations throughout the Bronx and Westchester County, Montefiore Einstein is the ideal organization to apply and hone your expertise.<br /><br /><span style="text-decoration: underline;"><a href="https://montefiore.wd12.myworkdayjobs.com/en-US/MMC/login" target="_blank" title="Candidate Home" rel="noopener noreferrer">Sign In</a></span>&nbsp;- Candidate Home<br /><span style="text-decoration: underline;"><a href="https://montefiore.wd12.myworkdayjobs.com/en-US/MMC/introduceYourself" target="_blank" title="Introduce Yourself " rel="noopener noreferrer">Introduce Yourself&nbsp;</a></span>-&nbsp;Please let us know about yourself so we can keep in touch about future job openings!<br /><br /><strong><span class="">NURSE&nbsp;RECRUITMENT&nbsp;HOTLINE:</span>&nbsp;<span class="">718-920-6697 (</span><span class="">Monday-Friday: 9am-4pm)&nbsp;&nbsp;</span></strong><br /><br /><strong>Check Out Our Employee&nbsp;<span style="text-decoration: underline;"><a href="https://healthymebenefits.com/" target="_blank" title="Benefits" rel="noopener noreferrer">Benefits</a></span></strong></h4> <h4 class="p1"><span style="text-decoration: underline;"><strong><a href="https://s3.us-east-1.amazonaws.com/vizi.vizirecruiter.com/MontefioreHealthSystem+RecruitingPractices.pdf" target="_blank" title="Safe Online Recruiting" rel="noopener noreferrer">Our Commitment to Safe Online Recruiting</a></strong></span></h4> https://www.montefiore.org/

keywords: position summary,position details,technical,teamwork,review,performance,management,assist,support,reporting,experience,skills,knowledge,preferred,education,proficiency

Full time

$112,000.00-$140,000.00

Overview: <div> <p>Montefiore is ranked among the top hospitals nationally and regionally by U.S. News &amp; World Report. For more than 100 years we have been innovating new treatments, procedures, and approaches to patient care, producing stellar outcomes and raising the bar for academic medical centers in the region and around the world. Our work to improve health outcomes in underserved communities is unparalleled in the United States. Our workforce is among the most diverse in the US: Montefiore associates speak 60+ languages.</p> <p>As a Cybersecurity Engineer&nbsp;in&nbsp;Montefiore Technology, you directly support patient safety, clinical operations, and the protection of sensitive health information. This&nbsp;role&nbsp;provides&nbsp;the opportunity to work deeply with modern security technologies while contributing to our mission-driven organization where cybersecurity is essential to&nbsp;care&nbsp;delivery.&nbsp;</p> </div> <div> <p>The&nbsp;<strong>Attack Surface Management (ASM) Engineer&nbsp;</strong>is a security engineering role responsible for conducting and supporting attack surface discovery, vulnerability management, and exposure reduction activities across a complex healthcare environment. Building upon foundational ASM analyst experience, this role emphasizes hands-on technical execution, operational discipline, and collaboration with IT, Clinical Engineering, Cloud, and Security Operations teams to reduce cyber risk while supporting patient care.&nbsp;</p> </div>
Responsibilities: <ul> <li>Work with architecture and engineering personnel to implement automation and orchestration solutions where appropriate to improve efficiency and reduce manual effort.</li> <li>Collaborate with IT, clinical teams, and other departments to ensure cybersecurity measures are integrated into everyday operations without disrupting patient care.</li> <li>Manage vendor relationships related to security solutions, testing services, and consulting engagements.</li> <li>Maintain security tools and services ensuring continued uptime and efficient execution of scanning activities.</li> <li>Work with DevOps, cloud, and IT infrastructure teams to incorporate secure development practices and vulnerability remediation into their workflows.</li> <li>Perform continuous device and asset discovery across IT, cloud, medical, and IoT/OT environments using approved ASM tooling.</li> <li>Review and validate asset discovery and vulnerability findings to identify unmanaged, unknown, or misclassified assets.</li> <li>Correlate exposure and vulnerability data with CMDBs, internal inventories, and cloud asset repositories to improve accuracy.</li> <li>Support the enterprise vulnerability management lifecycle by tracking findings from identification through remediation.</li> <li>Apply risk-based vulnerability prioritization using exploitability, asset criticality, and business impact.</li> <li>Coordinate with system, application, and device owners to validate their proposed remediation actions and timelines.</li> <li>Review third-party penetration testing results and assist with remediation tracking and validation.</li> <li>Collaborate with SOC and incident response teams to contextualize vulnerabilities during investigations.</li> <li>Develop and maintain technical documentation, SOPs, and workflows related to ASM processes.</li> <li>Contribute to dashboards, KPIs, and reporting that measure attack surface coverage, vulnerability aging, and risk reduction.</li> <li>Monitor vulnerability and threat trends relevant to healthcare and emerging technologies.</li> <li>Assist with automation and orchestration initiatives to improve ASM efficiency under manager guidance.</li> </ul>
Requirements: <div> <ul> <li>Bachelor's&nbsp;degree or&nbsp;equivalent work experience.&nbsp;</li> <li>4&nbsp;-&nbsp;6 years' Cybersecurity or IT experience with progression from vulnerability analysis, exposure management, or ASM analyst functions.&nbsp;&nbsp;</li> <li>4&nbsp;-&nbsp;6 years'&nbsp;prior experience in&nbsp;highly regulated environments.&nbsp;</li> <li>Strong&nbsp;proficiency&nbsp;with asset discovery and attack surface management technologies across on‑prem IT, cloud, and IoMT environments.&nbsp;</li> <li>Strong ability to interpret,&nbsp;validate, and assess findings from attack surface management (ASM) and vulnerability management platforms.&nbsp;</li> <li>Strong understanding of the vulnerability management lifecycle, including remediation processes and governance requirements.&nbsp;</li> <li>Foundational experience correlating data across CMDBs, cloud inventories, and security tools.&nbsp;</li> <li>Ability to communicate technical findings to non-technical stakeholders with guidance.&nbsp;</li> <li>Working knowledge of healthcare cybersecurity frameworks including HIPAA, HITECH, NIST CSF, HITRUST, HICP, and NYSDOH 405.46.&nbsp;</li> <li>Strong analytical skills with attention to detail and data accuracy.&nbsp;</li> <li>Ability to&nbsp;operate&nbsp;effectively within defined processes and escalate appropriately.&nbsp;</li> </ul> <p>&nbsp;</p> <p><strong>Preferred:</strong></p> <ul> <li>Prior experience in healthcare.</li> <li>One of the following certifications required or obtained within 18 months of hire:</li> <ul> <li>CompTIA PenTest+</li> <li>GIAC Security Essentials (GSEC)</li> <li>Tenable Certified Nessus Auditor (TCNA)</li> <li>CREST Registered Vulnerability Specialist (RVS)</li> </ul> </ul> <div>&nbsp;</div> </div>