Job Purpose and Impact
Sr Consultant - Surface Area Management safeguards the organization's Digital footprint both On-Prem/Cloud by leading the continuous improvement of security controls, guardrails, and remediation of the exposures. This role serves as a trusted advisor and technical leader, driving enterprise cloud vulnerability/exposure management strategy, standards, and posture improvement initiatives. With minimal supervision, the Senior Consultant partners with cybersecurity, cloud platform, infrastructure, engineering, risk, and business leaders to reduce cloud risk exposure and improve the exposures and other issues of cloud adoption at scale. professional individual contributor and is recognized as subject matter expert in vulnerability management and exposure reduction strategies.
Key Accountabilities
-Lead enterprise-wide Cloud Vulnerability Management programs across AWS, Azure, GCP, and OCI.
-Design and implement preventive security guardrails using SCPs, Azure Policy, and organization policies to enforce secure-by-default controls.
-Analyze CSPM/CNAPP findings and prioritize remediation based on exposure, business criticality, data sensitivity, and compensating controls.
-Drive remediation accountability, govern security exceptions, and manage risk acceptance processes across platform and application teams.
-Develop automation, auto-remediation capabilities, dashboards, and integrations to improve control coverage, efficiency, and reporting.
-Lead cloud identity and access security initiatives, including privileged access, federation, workload identities, secrets management, and least privilege enforcement.
-Establish risk-based prioritization models incorporating threat intelligence, exploitability, business impact, and compensating controls.
-Coordinate responses to zero-day threats, actively exploited vulnerabilities, and critical CVEs.
-Identify systemic security trends and drive strategic improvements in scanning coverage, asset visibility, attack surface management, and remediation effectiveness.
-Conduct cloud security assessments and architecture reviews, translating findings into prioritized remediation roadmaps.
-Deliver executive-level risk reporting and partner with Incident Response, Threat Intelligence, Security Architecture, and engineering teams.
ESSENTIAL FUNCTIONS
VULNERABILITY MANAGEMENT STRATEGY & GOVERNANCE
Leads the design, implementation, operation, and continuous improvement of enterprise vulnerability management capabilities. Establishes standards, governance processes, performance metrics, and risk management practices to reduce organizational exposure.
EXTERNAL ATTACK SURFACE MANAGEMENT
Provides strategic oversight of the organization's external attack surface, identifying emerging risks, prioritizing remediation efforts, and guiding improvements to overall exposure management practices.
THREAT-INFORMED VULNERABILITY MANAGEMENT
Integrates vulnerability management with threat intelligence, threat hunting, offensive security, and incident response capabilities to improve detection, prioritization, and remediation outcomes.
PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT
Leads cross-functional initiatives that improve scanning coverage, asset visibility, remediation performance, governance processes, and overall program maturity.
EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders, influencing strategic decisions and prioritization of remediation activities.
PREVENTIVE CONTROLS & GUARDRAIL ENGINEERING: Provides strategic and hands-on ownership of preventive cloud controls, ensuring insecure configurations are blocked by default, and guardrail coverage keeps pace with cloud service adoption.
CLOUD POSTURE & MISCONFIGURATION REMEDIATION: Develops and maintains enterprise risk models for cloud posture findings, ensuring remediation efforts focus on the most significant business and cybersecurity risks, and advances automated remediation where appropriate.
CLOUD SECURITY ARCHITECTURE & CONTROL VALIDATION: Provides technical leadership for cloud security architecture reviews, control validation, secure landing zone alignment, workload protection, encryption, network segmentation, key management, and identity-based access controls to ensure cloud environments remain resilient, compliant, and secure by design.
Qualifications
We are a family company providing food, ingredients, agricultural solutions and industrial products that are vital for living. We connect farmers with markets so they can prosper. We connect customers with ingredients so they can make meals people love. And we connect families with daily essentials - from eggs to edible oils, salt to skincare, feed to alternative fuel.
Today, the need to make our food system more sustainable and resilient is urgent. Sitting at the heart of the global supply chain, we have a unique ability, and responsibility, to help. Through innovations, strategic partnerships, and 159 years of experience, we help businesses grow, and communities and people around the world flourish — today, and for generations to come.