Global Lead, Attack Surface Management
Indexed description
Our 60,000+ associates work across the globe at more than 15 unique businesses within life sciences, diagnostics, and biotechnology.
Are you ready to accelerate your potential and make a real difference? At Danaher, you can build an incredible career at a leading science and technology company, where we’re committed to hiring and developing from within. You’ll thrive in a culture of belonging where you and your unique viewpoint matter.
Learn about the Danaher Business System which makes everything possible.
At Danaher, the Global Lead, Attack Surface Management owns the ASM/EASM/CAASM capability — discovery, attribution, asset ownership, risk prioritization, and cross-functional remediation across internet-facing, internal, cloud, SaaS, subsidiary, and third-party surfaces. Enterprise strategy is set by leadership; the Global Lead shapes and refines the ASM strategy, then owns operationalizing it as part of CTEM. The Global Lead works independently and drives remediation across teams that each own their own assets.
This position reports to the Senior Manager, Exposure Management (CTEM) and is part of the Danaher Information Security (DIS) located in Brazil and will be a remote role.
In This Role, You Will Have The Opportunity To
- Architect the ASM operating model: outside-in discovery, attribution, asset-ownership workflows, and risk prioritization feeding CTEM.
- Engineer/automate discovery correlation and enrichment (APIs, scripting) across EASM/CAASM, DNS, certificate transparency, and CMDB sources.
- Design integration blueprints connecting asset visibility to vulnerability, threat intel, and remediation platforms.
- Design the sustainability & governance model: ownership assignment, remediation SLAs, and external-hygiene control checks.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
- Extensive cybersecurity experience (7-9 years preferably) with a focus on attack surface management, exposure management, or offensive/recon security (GCRF P4 Bachelor's-track minimum; recommended, pending Comp sign-off).
- Experience leading or operating enterprise ASM/EASM/CAASM discovery, attribution, and remediation governance across internet-facing, cloud, and third-party surfaces.
- Hands-on experience with ASM platforms and reconnaissance tooling (such as Cortex Xpanse, Defender EASM, CyCognito, Censys, or Shodan) and internet fundamentals (TCP/IP, DNS, TLS/certificates, domains).
- Experience working independently to drive asset ownership and remediation across infrastructure, cloud, and third-party teams and reporting external risk to stakeholders.
- Experience with digital risk protection or M&A/subsidiary security integration.
- Scripting for API integration and automation (Python preferred).
- CISSP, CISM, OSCP, CRTO, GCIH, GIAC (GOSI/GPEN/GSEC), or a vendor ASM/CAASM certification.
For more information, visit www.danaher.com.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search