Role overview
About this role
A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work with leading companies across industries, helping them shape their hybrid cloud and AI journeys. With support from our strategic partners, robust IBM technology, and Red Hat, you’ll have the tools to drive meaningful change and accelerate client impact. At IBM Consulting, curiosity fuels success. You’ll be encouraged to challenge the norm, explore new ideas, and create innovative solutions that deliver real results. Our culture of growth and empathy focuses on your long-term career development while valuing your unique skills and experiences. The Security Specialist – Exposure Management is responsible for identifying, assessing, prioritizing, and reducing cybersecurity exposures across the organization's technology environment. This role focuses on vulnerability management, attack surface management, security risk analysis, and remediation coordination to ensure critical security weaknesses are addressed in a timely manner. The specialist works closely with infrastructure, application, cloud, and security teams to strengthen the organization's security posture and reduce the risk of cyber threats. Perform continuous identification, assessment, and prioritization of security vulnerabilities across on-premises, cloud, and hybrid environments. Manage the end-to-end vulnerability management lifecycle, including discovery, analysis, remediation tracking, and validation. Conduct attack surface management activities to identify exposed assets, misconfigurations, and potential entry points for attackers. Analyze vulnerability scan results and correlate findings with threat intelligence and business risk. Prioritize remediation efforts based on severity, exploitability, asset criticality, and business impact. Collaborate with infrastructure, network, cloud, and application teams to drive remediation of identified security exposures. Monitor emerging threats, vulnerabilities, and industry security trends that may impact organizational assets. Validate remediation activities through rescanning, testing, and security assessments. Develop and maintain exposure management dashboards, metrics, and executive reports. Support risk assessments and provide recommendations for reducing organizational cyber risk. Assist with security audits, compliance requirements, and regulatory assessments related to vulnerability management. Leverage security tools such as Vulnerability Management platforms, EDR, SIEM, Attack Surface Management, and Threat Intelligence solutions. Define and improve exposure management processes, standards, and operational procedures. Participate in incident response activities when vulnerabilities or exposures contribute to security incidents. Provide guidance and security recommendations to stakeholders regarding remediation strategies and security best practices. Experience in Cybersecurity, Vulnerability Management, Exposure Management, or Security Operations. Strong knowledge of vulnerability assessment methodologies and risk-based prioritization. Experience with vulnerability scanning tools such as Tenable, Qualys, Rapid7, or similar platforms. Understanding of attack surface management and exposure assessment concepts. Knowledge of operating systems, networks, cloud platforms (AWS, Azure, GCP), and security architectures. Familiarity with SIEM, EDR/XDR, threat intelligence, and security monitoring technologies. Ability to interpret CVEs, CVSS scores, security advisories, and threat intelligence reports. Strong analytical, problem-solving, and communication skills. Experience working with cross-functional technical teams to drive remediation activities..Preferred Qualifications Experience with Exposure Management platforms (Tenable One, Microsoft Defender EASM, Cortex Xpanse, etc.). Knowledge of cloud security and container security. Familiarity with security frameworks such as NIST CSF, CIS Controls, ISO 27001, and MITRE ATT&CK. Security certifications such as CISSP, CISM, GSEC, CEH, Security+, or equivalent. Experience with automation and scripting (Python, PowerShell, Bash) for security operations • Vulnerability Scanning Tools: Exposure to additional vulnerability scanning and management tools beyond Tenable, Qualys, Nexpose Rapid 7, Ivanti Neurons, and Cisco Kenna, is beneficial for this role. • Advanced Threat Analysis: Experience working with advanced threat analysis and risk assessment methodologies can be an asset in identifying emerging risks and opportunities. • Cloud Security Knowledge: Familiarity with cloud security principles and exposure management best practices can be advantageous in enhancing the organization's security posture.