Exposure Management - Audit Readiness SME / Analyst

Remote • Posted 1 day ago • Updated 1 day ago
Contract Corp To Corp
Contract W2
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

✨ Finding the perfect fit...

Job Details

Skills

  • Internal Control
  • Collaboration
  • Communication
  • Continuous Improvement
  • Cyber Security
  • Attention To Detail
  • Auditing
  • Security Engineering
  • Security Operations
  • Regulatory Compliance
  • Risk Analysis
  • Risk Assessment
  • Stakeholder Management
  • Mapping
  • NIST 800-53
  • Payment Card Industry
  • Qualys
  • ISACA
  • Vulnerability Scanning
  • System On A Chip
  • Testing
  • Translation
  • ISO 9000
  • ISO/IEC 27001:2005
  • Leadership
  • Management
  • Reporting
  • Bridging
  • CISA
  • CISSP
  • Cadence
  • Dashboard
  • Documentation
  • Vulnerability Management

Summary

Job Title

Exposure Management – Audit Readiness SME / Analyst

Role Summary

The Exposure Management – Audit Readiness SME/Analyst is responsible for ensuring the organization’s exposure management program (vulnerability scanning, attack surface management, and remediation tracking) is audit‑ready, defensible, and aligned with internal controls and regulatory expectations. This role bridges technical security operations with audit, risk, and compliance teams to translate exposure data into clear, evidence‑based narratives for audits and assessments.

Key Responsibilities

Audit & Compliance Readiness

·         Serve as the primary SME for audit readiness related to exposure and vulnerability management.

·         Prepare, review, and validate audit evidence (policies, procedures, scan results, metrics, remediation records).

·         Support internal audits, external audits, regulatory exams, and risk assessments.

Control Mapping & Documentation

·         Map exposure management activities to applicable frameworks (e.g., NIST CSF, NIST 800‑53, ISO 27001, SOC, PCI).

·         Maintain documentation for control design, operational effectiveness, and continuous improvement.

·         Ensure testing frequency, coverage, and remediation practices meet stated control requirements.

Exposure & Risk Analysis

·         Analyze exposure data (vulnerabilities, misconfigurations, exploitability indicators) to support audit inquiries.

·         Validate completeness and accuracy of asset coverage and scanning scope.

·         Translate technical exposure findings into business‑aligned risk statements.

Stakeholder & Cross‑Functional Coordination

·         Act as liaison between security engineering, infrastructure, application teams, and audit/compliance stakeholders.

·         Support audit walkthroughs and provide clear explanations of exposure management processes.

·         Track and manage audit findings related to exposure management through remediation and closure.

Metrics, Reporting & Evidence Management

·         Define and maintain audit‑ready metrics (coverage, scan cadence, remediation SLAs, exceptions).

·         Support dashboards and reporting for leadership, audit committees, and regulators.

·         Ensure evidence repositories are accurate, current, and easily retrievable.

Continuous Improvement

·         Identify control gaps, documentation weaknesses, and audit risks.

·         Recommend remediation actions to improve audit posture and exposure management maturity.

·         Support alignment with Continuous Threat Exposure Management (CTEM) practices.

Required Qualifications

·         5+ years of experience in cybersecurity, vulnerability/exposure management, risk, audit, or compliance.

·         Strong understanding of vulnerability management and exposure concepts (CVSS, exploitability, risk‑based prioritization).

·         Experience supporting internal and/or external audits.

·         Familiarity with security and compliance frameworks (NIST, ISO, SOC, PCI).

·         Strong documentation, communication, and stakeholder management skills.

Preferred Qualifications

·         Experience with exposure or vulnerability management platforms (e.g., Tenable One, Qualys, Rapid7).

·         Experience working with CTEM or attack surface management programs.

·         Prior experience in regulated or large enterprise environments.

·         Certifications such as CISSP, CISA, CRISC, or similar are a plus.

 

Key Competencies

·         Audit and control mindset

·         Strong technical‑to‑business translation

·         Attention to detail and evidence quality

·         Risk‑based analysis and prioritization

·         Cross‑functional collaboration

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10179895
  • Position Id: 8949005
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Contract

Depends on Experience

Remote or Austin, Texas

Today

Easy Apply

Full-time, Part-time, Contract, Third Party

Remote

Today

Easy Apply

Third Party, Contract

Depends on Experience

Remote

Today

Easy Apply

Contract, Third Party

Depends on Experience

Search all similar jobs