SailPoint Logo

SailPoint

Attack Surface Management Team Lead

Posted Yesterday
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in United States
105K-195K Annually
Senior level
Remote or Hybrid
Hiring Remotely in United States
105K-195K Annually
Senior level
The Attack Surface Management Team Lead will drive the strategy for asset discovery, vulnerability management, and risk reduction while mentoring junior security analysts and collaborating across teams.
The summary above was generated by AI

Cybersecurity Attack Surface Management Team Lead

 

SailPoint’s Cybersecurity organization is seeking a Cybersecurity Attack Surface Management Team Lead to strengthen our security posture by reducing our digital exposure. The ASM Lead is a seasoned security professional responsible for defining and executing the strategy to continuously discover, categorize, and prioritize every asset that constitutes our attack surface. You will leverage advanced tooling and threat intelligence to transform raw asset data into actionable risk insights, directly informing our overall security posture and remediation efforts.

 

The ASM Lead will be a critical member of our Threat Exposure Management team, responsible for defining, implementing, and maturing our ASM program. This role requires a blend of technical expertise, strategic thinking, and strong leadership to continuously reduce our organization's external and internal security risks.This person will drive the cultural and technical shift from reactive to proactive, threat-informed risk reduction.

 

Our new Attack Surface Management Team Lead will join a growing and capable threat and vulnerability management team of both emerging and established talent. This potential team member will be comfortable with the 4 I’s at SailPoint (individual, Impact, Innovation, and Integrity) even if they’re new to the concept. They will embrace new challenges and by being their authentic self will be a positive contributor to an already positive work culture and environment.

 

This is a challenging and impactful role where you will have the opportunity to work with a variety of stakeholders, including our fantastic colleagues in IT, DevOps, Product Engineering, Security Architect Engineering, and Cyber Defense Operations. 

 

This role reports directly to the Head of Threat Exposure Management and will be remote.

 

Key Requirements:

  • 5+ years of experience in  Cybersecurity, with at least 2+ years specifically focused on Vulnerability Management, EASM (External Attack Surface Management), or Threat Intelligence.

  • Hands-on experience with commercial and open-source ASM/EASM platforms and methodologies (e.g., CrowdStrike, SecurityScorecard, Shodan, Censys or similar).

  • Expertise of ASM concepts including asset discovery, exposure monitoring, shadow IT detection, and external threat identification

  • Deep understanding of TCP/IP, networking protocols, cloud environments (AWS, Azure, or GCP), and web application architectures.

  • Familiarity with internet-facing systems, cloud infrastructures (IaaS/PaaS/SaaS), domain and certificate management, and network perimeter configurations.

  • Strong ability to translate technical exposure data into meaningful risk insights.

  • Strong analytical and investigative skills, with the ability to turn gaps into prioritized action plans.

  • Proficiency in scripting languages (e.g., Python, PowerShell) for automation and data analysis.

  • Developing and tracking ASM metrics and KPIs.

  • Strategic Vision & Execution - Ability to define and communicate a clear vision and resilience aligned with enterprise goals.

  • Influence & Collaboration – Demonstrable experience building strong partnerships across an organization

  • Risk-Based Decision Making – Experience making informed decisions through balancing business priorities, technical constraints, and risk exposure.

  • Executive Communication – Experience communicating complex technical concepts and ongoing program updates clearly to stakeholders and executive leadership.

  • Certifications like CISSP, OSCP and GIAC are beneficial.

 

Core Responsibilities:

  • Strategy & Program Leadership:

    • Develop and drive the overall strategy for discovering, inventorying, and managing the company's external and internal digital attack surface.

    • Establish and lead the ASM program, defining key metrics, reporting mechanisms, and service level agreements (SLAs) for remediation.

  • Discovery & Inventory:

    • Implement and operate ASM tools (e.g., EASM solutions) to continuously discover and maintain an accurate inventory of all digital assets (IPs, domains, cloud resources, third-party exposures, code repositories, etc.).

    • Identify "Shadow IT" and unknown external-facing assets and integrate them into the security framework.

  • Vulnerability & Risk Management:

    • Collaborate closely with Threat Intelligence, Vulnerability Management, and Penetration Testing teams to prioritize risks based on exploitability and business criticality.

    • Oversee and track the remediation process for identified exposures, working with asset owners across IT and business units.

  • Process Improvement & Automation:

    • Drive the integration of ASM data into existing security operations and risk management processes (e.g., CMDB, SIEM, GRC).

    • Identify opportunities to automate asset discovery, risk assessment, and reporting to enhance program efficiency.

  • Leadership & Mentorship:

    • Provide technical guidance and mentorship to junior security analysts.

    • Present program status, key findings, and strategic recommendations to leadership.

Benefits and Compensation listed vary based on the location of your employment and the nature of your employment with SailPoint.

As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect SailPoint’s differing products, industries, and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary, for US-based employees, will be in this range from (min-mid-max, USD):

$104,800 - $149,700 - $194,600

Base salaries for employees based in other locations are competitive for the employee’s home location.

Benefits Overview

1. Health and wellness coverage: Medical, dental, and vision insurance

2. Disability coverage: Short-term and long-term disability

3. Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)

4. Additional life coverage options: Supplemental life insurance for employees, spouses, and children

5. Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account

6. Financial security: 401(k) Savings and Investment Plan with company matching

7. Time off benefits: Flexible vacation policy

8. Holidays: 8 paid holidays annually

9. Sick leave

10. Parental support: Paid parental leave

11. Employee Assistance Program (EAP) and Care Counselors

12. Voluntary benefits: Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options

13. Health Savings Account (HSA) with employer contribution

SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other category protected by applicable law.  

Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact [email protected] or mail to 11120 Four Points Dr, Suite 100, Austin, TX 78726, to discuss reasonable accommodations.  NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.

Top Skills

AWS
Azure
Censys
Crowdstrike
GCP
Powershell
Python
Securityscorecard
Shodan

Similar Jobs at SailPoint

3 Days Ago
Remote or Hybrid
United States
188K-349K Annually
Senior level
188K-349K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead a team of engineers to define and execute technical strategy for infrastructure scalability and manage platform relations. Promote API-first and microservices approach, driving collaboration with various teams for critical software delivery.
Top Skills: Ai/MlApi DesignAWSCloud-Native ArchitectureDockerEvent-Driven SystemsGraph DatabasesKafkaKubernetesMicroservicesNeo4JSaas PlatformsSqs
3 Days Ago
Remote or Hybrid
Virginia, USA
109K-203K Annually
Senior level
109K-203K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Enterprise Account Executive will drive sales of Agentic Technology solutions, engage with customers, and collaborate with internal teams to meet revenue goals. The role requires experience in cybersecurity, consultative selling, and strong relationship-building skills.
Top Skills: Agent Identity SecurityCloud Data PlatformsCloud TechnologiesCybersecurity TechnologiesData Access SecurityIaasIdentity SecurityMachine Identity Security
4 Days Ago
Remote or Hybrid
2 Locations
120K-223K Annually
Junior
120K-223K Annually
Junior
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Account Executive will sell SailPoint's Identity Security solutions, exceed revenue goals, manage customer relationships, and lead sales strategies while collaborating with various teams.
Top Skills: MicrosoftOktaSalesforce

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account