· Own the triage, analysis, and remediation coordination of externally exposed vulnerabilities, misconfigurations, and threat findings identified through attack surface management platforms, vulnerability scanning, automated testing, and AI‑driven discovery.
· Drive risk‑based prioritization by correlating exposure data with threat intelligence, attacker activity, exploitability, and business impact.
· Act as a central coordination point across threat intelligence, CSIRT, vulnerability management, cloud security, application, and infrastructure teams to accelerate remediation of internet‑facing risk.
· Partner directly with remediation owners to define remediation approaches, track execution, escalate material risk, and ensure closure aligned to enterprise SLAs and risk tolerance.
· Analyze internal and external cyber threat intelligence to identify active, emerging, or likely‑to‑be‑exploited threats relevant to the organization’s public attack surface.
· Assess adversary tactics, techniques, and indicators to support threat‑informed decision‑making and incident response readiness.
· Enable continuous, global threat operations by supporting handoffs, documentation, and coordination across regions and service providers.
· Ensure threat management practices, tooling usage, and remediation workflows align with enterprise security standards, policies, and governance requirements.
· Provide audit‑ready evidence, analysis, and subject‑matter expertise to support regulatory, internal, and third‑party assessments related to threat and exposure management.
· Maintain strong working relationships with IT, cloud, application, risk, governance, and third‑party teams responsible for managing external risk.
· Contribute to the continuous improvement of attack surface and threat management processes, incorporating new tooling, AI‑driven discovery capabilities, and evolving attacker techniques.
· Define, track, and analyze KPIs and KRIs to support leadership visibility, operational oversight, and risk‑based decision‑making.
· Contribute threat intelligence insights to enterprise risk assessments and executive‑level reporting.
· Review application and infrastructure changes for external exposure and security risk implications.
· Produce clear, actionable security reporting and communicate risk findings effectively to technical and non‑technical stakeholders.