Specialist, Attack Surface Management
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Systems Engineer
Job Classification
Technology - Information Security
Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career – all while growing your skills and advancing your profession at one of the world’s leading financial services institutions.
YourTeam & Role
As a Specialist, Cyber Security Operations
- Vulnerability Management on the Attack Surface Management Team, you will partner with other security professionals across the Information Security Office, the Chief Technology Office, and other groups in Prudential to drive Prudential’s risk reduction efforts across the global enterprise.
You will support implementation and operational best practices, while contributing to or owning deliverables and project work streams around end user device security posture. You will be directly responsible for the design, development, and implementation of a comprehensive program to manage the attack surface across our endpoint fleet. You will also perform triage of issues related to technology configuration, software weaknesses, build/deployment, and process challenges.
You will work on significant and unique issues where analysis of situations or data requires an evaluation of intangible variables and may impact future concepts, products or technologies to ensure security of our products and customers! In addition to applied experience, you will bring excellent problem solving, communication and teamwork skills, along with agile ways of working, strong business insight, an inclusive leadership attitude and a continuous learning focus to all that you do.
is What You Can Expect on a Typical Day
- Design, implement, and socialize a robust endpoint vulnerability management program, unified with existing vulnerability management standards, tools, and operations.
- Collaborate with cross-functional teams to gain a deep and contextualized understanding of Prudential’s endpoint fleet, as well as supporting infrastructure and device management tooling.
- Research and ensure alignment of Prudential’s endpoint security monitoring with applicable industry and regulatory standards.
- Assess existing vulnerability landscape and patch management architectures and processes. Provide technical security recommendations and drive sustainable change across the enterprise.
- Establish clear roles & responsibilities across various teams to support operational workflows & processes (patching, remediation, exception management, etc.).
- Execute and enhance our Emergent Vulnerability Response playbook to identify, analyze, and mitigate rapidly evolving vulnerability threats commonly associated with end user devices.
- Validate asset management integration between CMDB, device management tooling, and vulnerability management inventory.
- Support integration of vulnerability management tooling and centralized orchestration and reporting
- Triage, prioritize, and provide technical guidance to partner teams to drive remediation and validate mitigating controls of findings.
- Partner with leadership to set direction for the future of the Attack Surface Management program, while ensuring an accurate understanding and in-depth knowledge of daily operations to provide recommendations to team objectives.
- Bachelor of Computer Science/Engineering or formal experience in related fields
- Specialized expertise with device management tools (UEM, MDM, etc.)
- 3+ years of demonstrated experience vulnerability assessment, risk prioritization, and threat correlation
- Experience building and maturing endpoint security posture management
- Familiarity with vulnerability and security scanning tools, as well as common vulnerability data sources and frameworks (CVE, CVSS, EPSS, CWE)
- Knowledge of industry security standards and frameworks (NYDFS, CIS, NIST CSF), especially as applicable to endpoint security hardening
- Experience improving vulnerability management platforms, processes, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).