Attack Surface & Vulnerability Analyst

Regeneron
Sleepy Hollow, NY

Attack Surface & Vulnerability Management (ASVM) Analysts support Regeneron's ASVM capability to identify, assign, and validate remediation of compute environment vulnerabilities and misconfigurations. This encompasses Regeneron’s on-prem, hybrid, and multi-tenant cloud environments. This position supports and enables Regeneron’s, global (US (United States), EU (European Union), APAC) Science to Medicine business objectives through enriching the cybersecurity defense posture.

ASVM Analysts focus on cybersecurity attack surface management, vulnerability identification, security control and visibility gap coverage, facilitate priority-based patching, validate remediation effectiveness, and support the tooling enabling the discovery mechanisms. Operational requirements include leveraging ASVM and information technology service management (ITSM) platforms to provide visibility, quantification, and accountability for remediation efficacy. This includes the utilization of reporting, executive summaries, and real-time dashboards.

As an Analyst, a typical day may include:

  • Manage cybersecurity vulnerabilities and risks across Regeneron including identifying and supporting application and system owners to manage risks and remediate vulnerabilities.
  • Conduct vulnerability and security compliance assessments of scans of servers, websites, workstations, serverless technology, network devices, cloud infrastructure, and other assets using various vulnerability management platforms and tools.
  • Create/edit/analyze enterprise cybersecurity policies and configurations to evaluate compliance with regulations and enterprise policies and standards.
  • Collection, reporting, and metrics generation for multiple cyber ASVM datasets. This includes patching efficiency, identifying system misconfigurations, and security hygiene assessments.
  • Support the process of Security Compliance assessments of systems and multi-tenant cloud services, leveraging industry best practices, to include, Center for Internet Security (CIS) hardening guidelines
  • Analysis and monitoring of cybersecurity feeds, cyber threat intelligence, and open-source intelligence on trending vulnerabilities and exploits.
  • Partner with IT service providers to operate, maintain, and enhance ASVM platforms. This includes native Operating System, cloud security, and data aggregation platforms

To be considered for this role, you must meet the following:

  • Knowledge, proven ability, and skills in defense-in-depth security control coverage and vulnerability assessment, prioritization, assignment, validation, and tracking.
  • ASVM/ASM focused Cybersecurity tool familiarity E.g., CAASM (Cyber Asset Attack Surface Management), EASM (External Attack Surface Management), RBVM (Risk Based Vulnerability Management), CNAPP (Cloud Native Application Protection Platform), EDR (Endpoint Detection and Response), etc.
  • Familiarity with CIS Security Controls, MITRE ATT&CK Framework
  • Working knowledge of multi-tenant cloud environments (AWS, Azure, GCP), vulnerability mitigation techniques, and system hardening.

Collaboration

  • Collaborate and partner with cross-departmental peers (technical and non-technical) to report, synthesize, and prioritize vulnerabilities and threats based on contextual assets and relationship data.

Innovation

  • Leverage industry and compute environment data to assess current and alternative technical solutions and processes for continuous enhancement and issue resolution.

Skills/Tools

  • Proven threat and vulnerability assessment skills or knowledge gained through experience or academia.
  • Ability to understand threat modeling and apply technical, administrative, and security control risk mitigation.
  • Organized, reliable, detail oriented.
  • Proven or conceptual abilities to navigate levels through thought equity.

Preferred:

  • Experience and working knowledge of multi-faceted attack surface management and aggregation tools used by ASVM to include Wiz, Censys, SafeBreach, Axonius, Seemplicity
  • Experience gained through a complex organization and managed security providers and vendors.
  • Excellent problem-solving skills and attention to detail.
  • Proven experience in customer service, communication, and relationship building.
  • Ability to work independently and as part of a team.

Does this sound like you? Apply now to take your first step towards living the Regeneron Way! We have an inclusive culture that provides comprehensive benefits, which vary by location. In the U.S., benefits may include health and wellness programs (including medical, dental, vision, life, and disability insurance), fitness centers, 401(k) company match, family support benefits, equity awards, annual bonuses, paid time off, and paid leaves (e.g., military and parental leave) for eligible employees at all levels! For additional information about Regeneron benefits in the US, please visit For other countries’ specific benefits, please speak to your recruiter.
Please be advised that at Regeneron, we believe we are most successful and work best when we are together. For that reason, many of Regeneron’s roles are required to be performed on-site. Please speak with your recruiter and hiring manager for more information about Regeneron’s on-site policy and expectations for your role and your location.

Regeneron is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion or belief (or lack thereof), sex, nationality, national or ethnic origin, civil status, age, citizenship status, membership of the Traveler community, sexual orientation, disability, genetic information, familial status, marital or registered civil partnership status, pregnancy or parental status, gender identity, gender reassignment, military or veteran status, or any other protected characteristic in accordance with applicable laws and regulations. The Company will also provide reasonable accommodation to the known disabilities or chronic illnesses of an otherwise qualified applicant for employment, unless the accommodation would impose undue hardship on the operation of the Company's business.

For roles in which the hired candidate will be working in the U.S., the salary ranges provided are shown in accordance with U.S. law and apply to U.S.-based positions. For roles which will be based in Japan and/or Canada, the salary ranges are shown in accordance with the applicable local law and currency. If you are outside the U.S, Japan or Canada, please speak with your recruiter about salaries and benefits in your location.

Please note that certain background checks will form part of the recruitment process. Background checks will be conducted in accordance with the law of the country where the position is based, including the type of background checks conducted. The purpose of carrying out such checks is for Regeneron to verify certain information regarding a candidate prior to the commencement of employment such as identity, right to work, educational qualifications etc.

Salary Range (annually)

$80,300.00 - $131,100.00
Posted 2026-02-18

Recommended Jobs

Senior Software Engineer - City Environmental Quality Review

City Of New York
New York, NY

Job Description THIS POSITION IS TEMPORARILY FUNDED THROUGH DECEMBER 2027 WITH THE POSSIBILITY OF FURTHER EXTENSION. THE AGENCY The Department of City Planning (DCP) plans for the strategi…

View Details
Posted 2026-02-10

Payer Engagement Account Director (Market Access) #4538

GRAIL
Albany, NY

Our mission is to detect cancer early, when it can be cured. We are working to change the trajectory of cancer mortality and bring stakeholders together to adopt innovative, safe, and effective tech…

View Details
Posted 2026-02-09

Physical Therapist

Able Health Care Service
Hempstead, NY

As a home care agency, Able Health Care Service is dedicated in providing top quality care to all of our clients. Currently, we are looking for individuals who are compassionate and caring to be apar…

View Details
Posted 2026-02-13

Housekeeper

GreatAuPair LLC
Ithaca, NY

Get hired for Jer's housekeeper Job in Ithaca, NY. Live and Work as Housekeeper in Vacation Home. Find housekeeper care work in Ithaca.

View Details
Posted 2025-11-09

Design Studio Manager of Accessories and Licensing

PVH
New York, NY

Be part of an iconic story. At Calvin Klein, we believe in fostering an inclusive and collaborative culture by celebrating different perspectives, backgrounds and beliefs to truly connect with o…

View Details
Posted 2025-12-29

Maintenance Mechanic - Multiple shifts available (CPP Syracuse)

CPP- Syracuse
Chittenango, NY

Maintenance Mechanic - Multiple shifts available If you would love to be part of a company that is poised for substantial growth with opportunities for advancement, then working for CPP and its su…

View Details
Posted 2025-12-25

Athletic Trainer - Sports Medicine

Geneva, NY

Athletic Trainer – Full-Time | Direct Hire | Geneva, NY Competitive Pay | Excellent Benefits | New Grads Welcome Are you passionate about helping athletes stay strong, recover quickly, and perf…

View Details
Posted 2026-02-18

EEG Technologist - ETECHTV

NavitsPartners
Syracuse, NY

Job Title: EEG Technologist Location: Syracuse, NY 13210 Duration: 13 Weeks (High possibility of extension) Schedule: 7:00 AM – 3:30 PM | Every Other Weekend Guaranteed …

View Details
Posted 2026-02-15

Rad / CT Tech Multi-Modality

Palm Careers
Buffalo, NY

Radiologic Technologist / CT Technologist (Multi-Modality) Western New York State (Buffalo, Niagara, Rochester Region) | Community Hospital Perm preferred | Traveler or Temp-to-Perm considered …

View Details
Posted 2026-01-28

Audiologist

AlphaX
Elmont, NY

We are seeking a licensed Audiologist to join a patient-centered hearing healthcare practice in Elmont, NY . This role focuses on delivering thorough hearing evaluations, fitting and programming he…

View Details
Posted 2026-02-18