Security Analyst Consultant - Attack Surface Management at Kalles Group
Seattle, WA
$110,000–$140,000from the description
Jul 25, 2026
Seattle, WA
Jul 26, 2026
What this job asks for AI summary
A consulting role focused on building and maturing an enterprise Attack Surface Management program for a client based in Seattle. Day-to-day work spans vulnerability discovery and prioritization, external reconnaissance, OSINT, threat intelligence analysis, and automation development across cloud, network, and application environments. The role suits an experienced security professional comfortable with both hands-on technical execution and cross-functional collaboration to drive remediation and influence security architecture.
Senior level · 6+ years · Seattle-Tacoma-Bellevue, WA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 75 people in the Seattle-Tacoma-Bellevue, WA area plausibly meet what this posting asks for (information security analysts). range 30–110
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $165,338 (middle half $132,613–$190,632). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is on-site at a client location in Seattle, WA; Kalles Group is a consultancy placing the candidate at a client site.
AWS, Azure, and GCP are all listed together as required multi-cloud experience; they are captured as separate required skills since the JD expects familiarity across all three, not just one.
Python and PowerShell are listed together as scripting/automation proficiency under required qualifications; they are captured as alternatives since either satisfies the scripting requirement.
CISSP, OSCE, and GREM appear under Preferred Qualifications as optional certifications; CISSP is listed as the primary with OSCE and GREM as alternatives.
AI/automation applied to security operations appears under Preferred Qualifications.
Threat modeling appears under Preferred Qualifications alongside purple teaming and adversary simulation; threat modeling is captured as the representative preferred skill for that cluster.
Cloud-native security platforms and exposure management tooling are mentioned under Preferred Qualifications but name no specific product, so they are omitted per the no-generic-concepts rule.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Attack Surface Management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.