Menu

Continuous Threat Exposure Management Lead

We’re recruiting for the position of Continuous Threat Exposure Management Lead. The purpose of this position will be to lead the establishment, operation and continuous improvement of the company’s Continuous Threat Exposure Management capability. The role is accountable for providing a unified, risk-based view of cyber exposure across critical business services, infrastructure, telecommunications platforms, cloud environments, applications, APIs, identities, data, AI systems and approved third parties. The role will drive the complete exposure lifecycle, from discovery and prioritisation through remediation, validation, exception management and executive reporting, with success measured by verified risk reduction rather than vulnerability volumes. (12 month contract role based in Johannesburg).

Duties and Responsibilities:

  • Defining and maintaining the exposure-management strategy, operating model, roadmap, governance framework, standards and performance measures
  • Establishing continuous discovery and reconciliation of assets and exposures against authoritative inventories
  • Integrating and correlating findings from vulnerability management, attack-surface management, cloud, identity, application-security testing, penetration testing, threat intelligence, incidents, audits and control-assurance activities
  • Prioritising exposures using business criticality, customer impact, internet exposure, reachability, attack paths, privilege, known exploitation, threat intelligence, CVSS, CISA KEV and EPSS rather than technical severity alone
  • Maintaining a single governed exposure backlog with accountable owners, required actions, target dates, dependencies, exceptions, evidence and audit trails
  • Co-ordinating remediation across infrastructure, network, cloud, application, identity, supplier, business and market teams
  • Leading urgent escalation and co-ordinated response for actively exploited vulnerabilities, credible zero-days, exposed privileged paths and critical control failures
  • Establishing independent, evidence-based validation of remediation and ensuring exposures are reopened where validation fails or evidence is insufficient
  • Governing time-bound risk acceptances, compensating controls and escalation of overdue exposures, ownership gaps and remediation blockers
  • Providing operational and executive reporting on exposure coverage, critical attack paths, ageing, remediation performance, exceptions, recurring issues and verified risk reduction
  • Managing exposure-management tooling, integrations, data quality, automation and supporting service-provider performance
  • Converting recurring exposure themes into systemic control improvements, architecture changes, security testing, supplier actions or problem-management initiatives
  • Measuring coverage of priority business services and critical technology assets
  • Measuring reduction in critical attack paths and known-exploited exposures
  • Measuring remediation performance against approved targets
  • Measuring reduction in overdue, recurring and reopened exposures
  • Measuring the percentage of material exposures with accountable owners
  • Measuring the quality and timeliness of risk acceptances
  • Measuring successful independent validation of exposure closure
  • Demonstrating and sustaining a reduction in residual cyber risk

Minimum Requirements:

  • Relevant degree or equivalent experience in cybersecurity, technology, engineering or risk management
  • Significant experience leading vulnerability management, exposure management, cyber-risk reduction, security testing or a related enterprise security capability
  • Strong knowledge of infrastructure, cloud, identity, application, API, network and telecommunications security
  • Experience coordinating remediation across complex technology and business environments
  • Strong understanding of attack-path analysis, threat-informed prioritisation, security assurance and exception governance
  • Experience managing executive reporting, governance forums, senior stakeholders and service providers
  • Relevant certification such as CISSP, CISM, CRISC, CCSP, OSCP or GIAC is advantageous
  • Knowledge of NIST CSF 2.0, MITRE ATT&CK, CISA KEV and FIRST EPSS is advantageous

    Have you worked with APMC before?