Director, Attack Surface & Infrastructure Vulnerability Management
Role details
Job location
Tech stack
Job description
Define and lead the longterm enterprise strategy for attack surface and infrastructure vulnerability management
- Drive modernization of Product Security capabilities including automated risk scoring, AIenabled security, riskbased vulnerability management, and targeted offensive security
- Own the full vulnerability lifecycle across cloud, infrastructure, endpoints, identities, and platforms
- Build prioritization models that reflect real risk using exploitability, exposure, asset criticality, and business impact
- Lead continuous discovery and reduction of internal and external attack surface across all production environments
- Partner closely with Engineering, Product, Cloud Platform, IT, Security Operations, Risk, Compliance, and Legal to drive durable risk reduction
- Establish and oversee targeted offensive security initiatives that validate realworld exploitability and influence architecture and investment decisions
- Define ASVM tool strategy, integrations, automation, and trusted data pipelines across the security ecosystem
- Translate complex technical risk into clear, executivelevel insights that inform business decisions
- Build, lead, and develop a highperforming team with clear ownership, accountability, and growth paths
- Define KPIs and deliver regular executive updates on risk posture, trends, and program effectiveness
Requirements
- 10+ years of experience in cybersecurity, with strong depth in vulnerability management, attack surface management, or infrastructure security
- Experience leading enterprisescale security programs with broad organizational impact
- Strong understanding of cloud platforms, modern infrastructure, identity systems, and application security
- Handson experience with riskbased vulnerability management and exposure prioritization beyond CVSS
- Experience designing or overseeing offensive security efforts such as penetration testing or adversary simulation
Leadership and Influence
- Proven people leader with experience hiring, coaching, and developing highperforming teams
- Ability to influence senior leaders and align crossfunctional partners without relying on authority alone
- Comfort making strategic tradeoffs and owning outcomes that matter at an executive level
Ways of Working
- Outcomefocused mindset with a bias toward measurable risk reduction
- Strong judgment, curiosity, and ability to operate effectively in complex environments
- Passion for building scalable, durable security capabilities that stand the test of growth
Benefits & conditions
- Reports to the VP, Head of Product Security
- Fully remote role
- Peopleleader position
#LI-Remote
This is a remote position. Salary Range $167,000.00 To $221,000.00 / year Benefits & Perks
The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives and restricted stock units as part of the total compensation package, in addition to a full range of benefits including:
- Medical, dental, and vision
- HSA contribution and match
- Dependent care FSA match
- Uncapped paid time off
- Paid parental leave
- 401(k) match
- Personal and healthcare financial literacy programs
- Ongoing education& tuition assistance
- Gym and fitness reimbursement
- Wellness program incentives
Onboarding & Travel
This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity's immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations.
This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.
HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process. Why work with HealthEquity
Why work for HealthEquity