Threat Exposure Management Analyst

Fiserv

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Berkeley Heights, NJAlpharetta, GACoral Springs, FL
Salary
$110,000–$186,000 / yr
Posted
15 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $157k
This role $148k
$101k most similar roles pay here $197k

This role pays less than 58% of similar roles. Most pay $127,850–$187,125 — the shaded band above. At the midpoint, this role pays about $148k versus about $157k for comparable roles.

Based on 239 similar postings.

Employer

About Fiserv

Fiserv is a global leader in financial services technology, providing core banking platforms, payment processing, digital banking, and merchant acquiring solutions to financial institutions and businesses. Industry: Financial Technology & Payments

Fiserv currently has 87 open roles on FindRole.

Listed pay typically runs $115,000–$192,000 across 56 roles with salary data.

Most-posted roles

View all roles at Fiserv

At a glance

TL;DR · Threat Exposure Management Analyst

The Threat Exposure Management Analyst joins the Attack Surface Management team to advance the cybersecurity program from traditional vulnerability management toward a mature exposure management approach. This role involves identifying critical business exposures, validating exploitability through attack-path analysis and breach-and-attack simulation, and driving measurable risk reduction for core services. The analyst will build threat-informed prioritization models using indicators like EPSS, CISA KEV, and MITRE ATT&CK to rank risks based on real-world impact rather than just technical severity. Key responsibilities include mapping exposures to crown-jewel assets, coordinating remediation across infrastructure and security teams, and producing executive reports that translate technical findings into business risk. The role requires expertise in cloud environments, identity platforms, and network security to manage complex attack surfaces while influencing cross-functional stakeholders to prioritize the most critical vulnerabilities for the organization.

What you'll do

  • Analyze how individual exposures chain into viable attack paths toward critical assets.
  • Build and operate threat-informed prioritization models using exploit data and active campaign indicators.
  • Map exposures to crown-jewel assets to ensure remediation priorities reflect business impact.
  • Validate the exploitability of prioritized risks using breach-and-attack simulation and penetration testing findings.
  • Assess whether existing compensating controls effectively reduce risk before mandating remediation.
  • Maintain visibility across external, cloud, SaaS, and identity attack surfaces.
  • Drive remediation actions across infrastructure and security teams by establishing ownership and SLAs.
  • Produce technical and executive reports that translate exposure trends into business-risk terms.

What we're looking for

  • You must possess valid and unrestricted U.S. work authorization.
  • At least 8 years of experience in vulnerability management, attack surface management, exposure management, or offensive security is required.
  • Experience leading security programs with a focus on governance, metrics, and cross-functional stakeholder engagement is required.
  • Ability to assess attack paths, exploitability, and business impact beyond standard CVSS scoring is required.
  • Practical experience incorporating threat intelligence and exploit data like EPSS and CISA KEV into prioritization is required.
  • Proficiency in identifying vulnerabilities across operating systems, networks, cloud environments, identity platforms, and applications is required.
  • Ability to influence cross-functional teams and translate technical exposure into business risk for executive audiences is required.
  • Familiarity with the Gartner CTEM model, MITRE ATT&CK, and various vulnerability scoring standards is required.

More like this

Similar roles

Senior Associate, Threat and Vulnerability

Northern Trust

Chicago, IL 36 days ago $88,900$151,100
Vulnerability Management Threat Intelligence CVSS Zafran Qualys Azure AWS Cloud Security CTEM TTPs cyber security Security Operations Information Technology
3+ yrs exp

Exposure Management Senior Advisor

The Federal Reserve

Richmond, VA +11 7 days ago $136,600$222,000
Exposure Management SaaS CSPM CIEM EASM API Attack Surface Management CTEM Cloud Security Data Pipelines Risk Scoring Information Security Cybersecurity

Staff Vulnerability Management Engineer

SoFi

Seattle, WA +1 43 days ago $144,000$247,500
Vulnerability Management Python Go JavaScript TypeScript Java Kubernetes AWS GCP Azure CI/CD Infrastructure as Code SAST SCA SBOM Tines Wiz Semgrep Snyk Rapid7 Tenable Checkmarx CVSS EPSS CISA KEV AI/ML

Risk Management Analyst

General Dynamics

Fort Bragg, NC 34 days ago $79,220$107,180
Risk Management Threat Analysis Risk Mitigation Intelligence Analysis Program Management Joint Planning
5+ yrs exp

Senior Insider Threat Analyst

Anduril Industries

Reston, VA 74 days ago $166,000$220,000
Insider Threat Digital Forensics Incident Response SIEM EDR DLP Python Go Terraform AWS CDK AWS Data Lake Counterintelligence AI Cybersecurity
5+ yrs exp