New opportunity
Cybersecurity Engineer – External Attack Surface Management
About the company
We are a young and fast-growing recruiting company with five years of experience working across Latin America and the United States. We partner closely with teams and founders to help them build strong, high-impact teams through recruitment, outsourcing, and team-building services.
Our culture is built on effective communication, trust, and transparency. We believe great work happens when people feel heard, supported, and empowered to grow. Today, our team is made up of more than 80 professionals working across different projects throughout the region, collaborating remotely and learning from each other every day.
About the role
At Staffy, we’re seeking a Cybersecurity Engineer – External Attack Surface Management to own the discovery, validation, monitoring, and reduction of the client’s internet-facing attack surface.
The client’s external footprint continuously evolves through new mining sites, energy infrastructure, corporate acquisitions, and cloud services. This role will identify and monitor internet-facing assets across the organization, including domains, subdomains, cloud assets, exposed services, third-party integrations, and infrastructure inherited through acquisitions.
The ideal candidate combines attack surface management, external reconnaissance, cloud security, and offensive security experience with a strong remediation mindset. This is not a role focused solely on identifying vulnerabilities—the engineer is expected to validate findings, prioritize real business risk, and drive exposures through to remediation.
Responsibilities
- Deploy and operate an External Attack Surface Management (EASM) platform such as Palo Alto Cortex Xpanse, Microsoft Defender EASM, CyCognito, Censys, or equivalent
- Build and continuously maintain a comprehensive inventory of internet-facing assets across corporate domains, mining sites, cloud environments, subsidiaries, and acquired entities
- Discover and investigate shadow IT, orphaned infrastructure, expired certificates, exposed management interfaces, misconfigured cloud resources, and other external exposures
- Monitor for domain and subdomain takeover risks, typosquatting, and brand impersonation targeting the organization and its investor-facing identity
- Establish and operate a continuous Threat Exposure Management / CTEM process covering discovery, prioritization, validation, and remediation
- Support external attack surface discovery during M&A activities and new site deployments, ensuring newly acquired or provisioned assets are incorporated into the security program
- Integrate EASM findings with vulnerability management and ticketing platforms to enable closed-loop remediation tracking
- Support external penetration testing scoping and validate remediation of previously identified exposures
- Correlate attack surface findings with threat intelligence to prioritize exposures that are more likely to be targeted by active adversaries
- Validate material findings before escalation by confirming asset ownership, exposure, business context, and—where safe and authorized—exploitability
- Develop repeatable validation methodologies that provide asset owners with confirmed findings and actionable evidence rather than raw scanner output
- Prioritize exposures using both technical and business context, including data sensitivity, asset criticality, network position, and proximity to critical systems
- Recommend concrete remediation paths for confirmed findings, such as decommissioning, patching, reconfiguration, proxy/VPN protection, or compensating network controls
- Coordinate risk acceptance processes when immediate remediation is not feasible, ensuring ownership, expiration dates, and compensating controls are clearly documented and tracked
- Maintain an escalation process for high-likelihood compromise risks, including actively exploited vulnerabilities affecting internet-facing assets
- Re-validate remediated findings through rescanning or manual verification before closure
- Maintain a complete and defensible audit trail covering discovery, validation evidence, risk rationale, remediation decisions, and closure verification
- Report external exposure trends and critical findings to cybersecurity leadership and relevant stakeholders
Requirements
- 4+ years of cybersecurity engineering experience with hands-on experience in attack surface management, external reconnaissance, offensive security, or related areas
- Direct experience with at least one EASM or external attack surface discovery platform, such as Microsoft Defender EASM, Palo Alto Cortex Xpanse, Shodan Enterprise, CyCognito, Tenable, Qualys, Censys, or equivalent
- Strong working knowledge of DNS, certificate infrastructure, cloud networking (AWS/Azure), and common web application exposure patterns
- Experience analyzing large asset discovery datasets, distinguishing genuine security risks from tool noise, and prioritizing findings effectively
- Familiarity with attacker reconnaissance techniques including OSINT, passive DNS, certificate transparency logs, and external enumeration
- Python scripting skills for API integrations, automation, and discovery-to-ticket workflows
- Demonstrated practical use of AI/LLM tools such as Claude, ChatGPT, GitHub Copilot, or equivalent to accelerate scripting, automation, documentation, analysis, and exposure triage
- Ability to critically evaluate AI-generated output and validate its accuracy before implementation
Nice to have
- Background in offensive security, red teaming, or penetration testing
- Experience supporting external attack surface discovery during M&A due diligence or post-acquisition integration
- Familiarity with Cloud Security Posture Management (CSPM) platforms as a complement to EASM
- Experience working in energy, critical infrastructure, financial services, or other highly regulated environments
- OSCP, GPEN, CEH, or equivalent offensive security certification
Benefits
- People First culture
- Referral Program
- Free access to streaming platforms
- Free access to Spotify Premium
- GYM discount
- Travel discount
- E-Learning discount
- Birthday-day gift
- Points Program