Regeneron logo

Attack Surface & Vulnerability Analyst

Regeneron
On-site
Sleepy Hollow, NY
IT

Role Summary

Attack Surface & Vulnerability Management (ASVM) Analysts identify, assign, and validate remediation of compute-environment vulnerabilities and misconfigurations across on-prem, hybrid, and multi-tenant cloud environments. The role supports Regeneron’s global Science to Medicine objectives by strengthening the cybersecurity defense posture and visibility. You will focus on attack surface management, vulnerability identification, security control coverage, and enabling remediation through ASVM tooling and ITSM platforms.

Responsibilities

  • Manage cybersecurity vulnerabilities and risks across Regeneron, including identifying and supporting application and system owners to manage risks and remediate vulnerabilities.
  • Conduct vulnerability and security compliance assessments of scans of servers, websites, workstations, serverless technology, network devices, cloud infrastructure, and other assets using various vulnerability management platforms and tools.
  • Create/edit/analyze enterprise cybersecurity policies and configurations to evaluate compliance with regulations and enterprise policies and standards.
  • Collection, reporting, and metrics generation for multiple ASVM datasets, including patching efficiency, identifying system misconfigurations, and security hygiene assessments.
  • Support security compliance assessments of systems and multi-tenant cloud services, leveraging industry best practices, to include CIS hardening guidelines.
  • Analysis and monitoring of cybersecurity feeds, threat intelligence, and open-source intelligence on trending vulnerabilities and exploits.
  • Partner with IT service providers to operate, maintain, and enhance ASVM platforms, including native Operating System, cloud security, and data aggregation platforms.

Qualifications

  • Required: Knowledge, proven ability, and skills in defense-in-depth security control coverage and vulnerability assessment, prioritization, assignment, validation, and tracking.
  • Required: ASVM/ASM focused Cybersecurity tool familiarity (e.g., CAASM (Cyber Asset Attack Surface Management), EASM (External Attack Surface Management), RBVM (Risk Based Vulnerability Management), CNAPP (Cloud Native Application Protection Platform), EDR (Endpoint Detection and Response), etc.
  • Required: Familiarity with CIS Security Controls, MITRE ATT&CK Framework
  • Required: Working knowledge of multi-tenant cloud environments (AWS, Azure, GCP), vulnerability mitigation techniques, and system hardening.
  • Preferred: Experience and working knowledge of multi-faceted attack surface management and aggregation tools used by ASVM to include Wiz, Censys, SafeBreach, Axonius, Seemplicity
  • Preferred: Experience gained through a complex organization and managed security providers and vendors.
  • Preferred: Excellent problem-solving skills and attention to detail.
  • Preferred: Proven experience in customer service, communication, and relationship building.
  • Preferred: Ability to work independently and as part of a team.

Skills

  • Proven threat and vulnerability assessment skills or knowledge gained through experience or academia.
  • Ability to understand threat modeling and apply technical, administrative, and security control risk mitigation.
  • Organized, reliable, detail oriented.
  • Proven or conceptual abilities to navigate levels through thought equity.