Last year our HCA Healthcare colleagues invested over 156,000 hours volunteering in our communities. As a(an) Consulting Security Vulnerability Engineer with HCA Healthcare you can be a part of an organization that is devoted to giving back!
Job Summary and Qualifications
Why HCA Healthcare?
- Competitive Fortune 100, industry matched salaries and yearly merit increases.
- Department with industry leading security technologies and high tech “SOC” center.
- HCA offers an extensive professional development and educational reimbursement program for continuing education.
Summary
The Consulting Security Exposure Engineer serves as the technical lead for Enterprise Exposure Prioritization within HCA Healthcare's Attack Surface Management (ASM) program. Reporting to the Manager, Attack Surface Management Governance & Architecture, this role is responsible for transforming security findings into prioritized, actionable exposure intelligence that enables informed risk decisions and accelerates enterprise risk reduction.
Operating within a Continuous Threat Exposure Management (CTEM) framework, this position develops and maintains enterprise exposure prioritization methodologies by integrating vulnerability data, attack surface intelligence, threat intelligence, adversarial validation, business criticality, asset ownership, and control effectiveness. The role ensures that exposures are consistently evaluated, attributed, prioritized, and routed to the appropriate remediation, governance, vendor management, or risk acceptance workflows.
The Consulting Security Exposure Engineer partners closely with Threat Intelligence Services, Red Team, Enterprise Security Architecture, Infrastructure Operations, Cloud Security, Product Security, Identity Security, Cyber Physical Security, and Enterprise Vulnerability Remediation teams to continuously improve HCA Healthcare's ability to identify the exposures that matter most to patient care, operational resilience, regulatory obligations, and enterprise trust.
- Lead implementation and continuous improvement of the enterprise Exposure Prioritization program across all attack surface domains.
- Develop and maintain enterprise exposure prioritization methodologies incorporating business criticality, exploitability, threat intelligence, adversarial validation, asset context, ownership, and control effectiveness.
- Correlate findings from vulnerability management, cloud security, application security, cyber-physical systems, external attack surface management, identity security, and other security domains into unified exposure assessments.
- Develop and maintain exposure scoring models that accurately reflect enterprise risk and support executive decision-making.
- Partner with Threat Intelligence Services to integrate active threat campaigns, exploit intelligence, and adversary tradecraft into exposure prioritization.
- Partner with Red Team to incorporate adversarial exposure validation and attack path testing into prioritization decisions.
- Attribute exposures to business applications, enterprise assets, and accountable owners to support effective remediation routing.
- Support implementation of enterprise exposure routing models that direct findings to remediation teams, vendors, governance processes, or formal risk acceptance workflows.
- Develop dashboards, analytics, and reporting that measure exposure prioritization effectiveness, routing accuracy, ownership attribution, exposure aging, and overall attack surface risk.
- Collaborate with Enterprise Vulnerability Remediation, Infrastructure Operations, Cloud Engineering, Product Security, and business stakeholders to improve remediation prioritization and reduce exposure dwell time.
- Identify opportunities to automate exposure correlation, prioritization, enrichment, routing, and reporting through security orchestration and workflow automation.
- Provide technical leadership and mentorship regarding exposure management methodologies, threat-informed prioritization, attack surface analysis, and emerging exposure management technologies.
- Support development of executive metrics and outcome-driven reporting that demonstrate measurable reduction in enterprise cyber exposure.
Skills
- Effective self-management skills
- Effective time management skills
- Effective organizational skills
- Effective written and oral communication skill
- Effective analytical skills
- Effective decision making in crisis scenarios
- Effective project management skills
- Strong understanding of cybersecurity risk assessment and exposure prioritization methodologies.
- Demonstrated ability to correlate multiple security data sources into meaningful, business-focused exposure assessments.
- Proficient with SQL, ADX, GCP. and scripting (Python).
- Experience integrating threat intelligence and adversarial validation into operational security decision-making.
- Strong understanding of attack paths, exploitability, asset criticality, and compensating controls.
- Ability to communicate complex technical risk in clear business terms to technical and executive audiences.
- Experience designing dashboards, KPIs, and outcome-driven security metrics.
- Strong analytical, organizational, and problem-solving skills.
- Experience working across multiple technical and operational teams to establish ownership, accountability, and coordinated remediation.
- Experience supporting enterprise-scale security transformation initiatives.
What qualifications you will need:
- Bachelor's Degree preferred
- Seven or more years of relevant work experience
Other/Special Qualifications
Certifications (preferred, not required):
- CISSP (Certified Information Systems Security Professional)
- GCTI (GIAC Cyber Threat Intelligence)
- GCIA / GCIH
- CCSP (Certified Cloud Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- GIAC or SANS certifications related to Exposure Management, Threat Intelligence, Cloud Security, or Security Engineering
Preferred areas of experience:
- Attack Surface Management (ASM)
- Continuous Threat Exposure Management (CTEM)
- Exposure Assessment Platforms (EAP)
- Threat-Informed Defense methodologies
- Threat Intelligence integration
- Vulnerability and Exposure Management
- Risk-based prioritization methodologies
- Security Architecture
- Cloud Security (CNAPP, CSPM, CIEM, CWPP)
- Application Security and DevSecOps
- Identity Security
- Cyber Physical Systems Security
- Security automation and orchestration
- Data analytics and security reporting
- Enterprise CMDB and asset attribution
Benefits
HCA Healthcare, offers a total rewards package that supports the health, life, career and retirement of our colleagues. The available plans and programs include:
- Comprehensive benefits for medical, prescription drug, dental, vision, behavioral health and telemedicine services
- Wellbeing support, including free counseling and referral services
- Time away from work programs for paid time off, paid family leave, long- and short-term disability coverage and leaves of absence
- Savings and retirement resources, including a 401(k) Plan with a 100% match on 3% to 9% of pay (based on years of service), Employee Stock Purchase Plan, flexible spending accounts, preferred banking partnerships, retirement readiness tools, rollover support and financial wellbeing counseling
- Education support through tuition assistance, student loan assistance, certification support, dependent scholarships and a partnership with Galen College of Nursing
- Additional benefits for fertility and family building, adoption assistance, life insurance, supplemental health protection plans, auto and home insurance, legal counseling, identity theft protection and consumer discounts
Learn more about Employee Benefits
Note: Eligibility for benefits may vary by location.
HCA Healthcare has been recognized as one of the World's Most Ethical Companies® by the Ethisphere Institute more than ten times. In recent years, HCA Healthcare spent an estimated $3.7 billion in cost for the delivery of charitable care, uninsured discounts, and other uncompensated expenses.
"There is so much good to do in the world and so many different ways to do it."- Dr. Thomas Frist, Sr.
HCA Healthcare Co-Founder
Be a part of an organization that invests in you! We are reviewing applications for our Consulting Security Vulnerability Engineer opening. Qualified candidates will be contacted for interviews. Submit your application and help us raise the bar in patient care!
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.