Sr Consultant - Surface Area Management safeguards the organization's Digital footprint both On-Prem/Cloud by leading the continuous improvement of security controls, guardrails, and remediation of the exposures. This role serves as a trusted advisor and technical leader, driving enterprise cloud vulnerability/exposure management strategy, standards, and posture improvement initiatives. With minimal supervision, the Senior Consultant partners with cybersecurity, cloud platform, infrastructure, engineering, risk, and business leaders to reduce cloud risk exposure and improve the exposures and other issues of cloud adoption at scale. professional individual contributor and is recognized as subject matter expert in vulnerability management and exposure reduction strategies.
Key Accountabilities
-Lead enterprise-wide Cloud Vulnerability Management programs across AWS, Azure, GCP, and OCI.
-Design and implement preventive security guardrails using SCPs, Azure Policy, and organization policies to enforce secure-by-default controls.
-Analyze CSPM/CNAPP findings and prioritize remediation based on exposure, business criticality, data sensitivity, and compensating controls.
-Drive remediation accountability, govern security exceptions, and manage risk acceptance processes across platform and application teams.
-Develop automation, auto-remediation capabilities, dashboards, and integrations to improve control coverage, efficiency, and reporting.
-Lead cloud identity and access security initiatives, including privileged access, federation, workload identities, secrets management, and least privilege enforcement.
-Establish risk-based prioritization models incorporating threat intelligence, exploitability, business impact, and compensating controls.
-Coordinate responses to zero-day threats, actively exploited vulnerabilities, and critical CVEs.
-Identify systemic security trends and drive strategic improvements in scanning coverage, asset visibility, attack surface management, and remediation effectiveness.
-Conduct cloud security assessments and architecture reviews, translating findings into prioritized remediation roadmaps.
-Deliver executive-level risk reporting and partner with Incident Response, Threat Intelligence, Security Architecture, and engineering teams.
ESSENTIAL FUNCTIONS
VULNERABILITY MANAGEMENT STRATEGY & GOVERNANCE
Leads the design, implementation, operation, and continuous improvement of enterprise vulnerability management capabilities. Establishes standards, governance processes, performance metrics, and risk management practices to reduce organizational exposure.
EXTERNAL ATTACK SURFACE MANAGEMENT
Provides strategic oversight of the organization's external attack surface, identifying emerging risks, prioritizing remediation efforts, and guiding improvements to overall exposure management practices.
THREAT-INFORMED VULNERABILITY MANAGEMENT
Integrates vulnerability management with threat intelligence, threat hunting, offensive security, and incident response capabilities to improve detection, prioritization, and remediation outcomes.
PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT
Leads cross-functional initiatives that improve scanning coverage, asset visibility, remediation performance, governance processes, and overall program maturity.
EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders, influencing strategic decisions and prioritization of remediation activities.
PREVENTIVE CONTROLS & GUARDRAIL ENGINEERING: Provides strategic and hands-on ownership of preventive cloud controls, ensuring insecure configurations are blocked by default, and guardrail coverage keeps pace with cloud service adoption.
CLOUD POSTURE & MISCONFIGURATION REMEDIATION: Develops and maintains enterprise risk models for cloud posture findings, ensuring remediation efforts focus on the most significant business and cybersecurity risks, and advances automated remediation where appropriate.
CLOUD SECURITY ARCHITECTURE & CONTROL VALIDATION: Provides technical leadership for cloud security architecture reviews, control validation, secure landing zone alignment, workload protection, encryption, network segmentation, key management, and identity-based access controls to ensure cloud environments remain resilient, compliant, and secure by design.
Qualifications
- Bachelor's degree in computer science, Cybersecurity, Information Security, Information Systems, or a related technical field, or equivalent practical experience.
- 6+ years of cybersecurity experience, including 4+ years focused on cloud security engineering, cybersecurity, vulnerability management, attack surface management, or exposure management experience.
- Hands-on experience securing enterprise -scale vulnerability management in at least one of AWS, Microsoft Azure, Google Cloud, or Oracle Cloud Infrastructure, with working knowledge of a second.
- Proven experience designing and operating preventive cloud guardrails - AWS service control policies, Azure Policy, Google organization policies, or equivalent policy-as-code enforcement - not detection and reporting alone.
- Strong expertise in cloud security architecture and cloud-native security controls across IaaS, PaaS, and SaaS, including network security, data protection, and key management such as Azure Key Vault or AWS KMS.
- Deep expertise in cloud identity and access management, including least-privilege role design, federation and workload identity, privileged access management, conditional access, and Zero Trust principles.
- Hands-on experience operating a CSPM or CNAPP platform at enterprise scale - Wiz, Microsoft Defender for Cloud, Prisma Cloud, AWS Security Hub, or equivalent - including onboarding, policy tuning, finding triage, and remediation ownership routing.
- Hands-on experience with infrastructure as code security and policy enforcement using Terraform, Bicep, ARM templates, or CloudFormation, and integrating security controls into CI/CD pipelines and DevSecOps practices.Proven experience conducting cloud security assessments, posture reviews, threat modeling, architecture reviews, and security control validation, and translating findings into prioritized remediation roadmaps.
- Strong knowledge of cloud security frameworks and standards including CSA Cloud Controls Matrix, CIS Benchmarks, NIST, ISO 27001, and cloud provider Well-Architected security principles.
- Experience driving remediation accountability across platform and application teams, governing security exceptions and risk acceptances, and communicating cloud risk to senior leaders and executive audiences.
Preferred Certifications
- Cloud-specific certifications strongly preferred: CCSP, CCSK, AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect Expert (SC-100), or Google Professional Cloud Security Engineer.
- CISSP or an equivalent broad security certification is preferred.
Skills Required
- Minimum 5 years relevant cybersecurity, vulnerability management, exposure management experience (typically 7+ years)
- Experience performing advanced analysis with Tenable, Qualys, Rapid7, Wiz, or cloud-native security platforms
- Deep expertise in CVSS, EPSS, MITRE ATT&CK, threat modeling, and cyber risk management frameworks
- Experience with AWS, Azure, GCP, OCI, containers, and remediation across on-premises and cloud environments
- Experience leading enterprise-scale vulnerability management, exposure management, or cyber risk reduction initiatives
- Demonstrated experience influencing senior leaders and driving cross-functional remediation efforts
- Designing and implementing dashboards, automation, and integrations for vulnerability program efficiency
- Relevant industry certifications (CISSP, GSEC, GIAC, Security+, CySA+, AWS Security, Azure Security Engineer or equivalent)
Cargill Compensation & Benefits Highlights
-
Healthcare Strength — Health coverage is described as comprehensive, including medical, dental, vision, mental health/EAP resources, wellness programs, and partner services like Bright Horizons and Milk Stork on the official benefits hub. Feedback suggests these offerings provide robust support for both physical and psychological well-being.
-
Retirement Support — Retirement programs feature immediate 401(k) eligibility with a competitive company match, plus an ESOP component and Vanguard administration, with some materials also noting an employer-funded retirement account. Feedback suggests the multi-layered savings design and clear match mechanics are notable strengths.
-
Leave & Time Off Breadth — PTO tiers start at 15 days and scale up to 30 days with tenure, alongside defined holidays and floating personal days. Paid family leave for bonding and caregiving further rounds out a well-structured time-off program.
Cargill Insights
What We Do
We are a family company providing food, ingredients, agricultural solutions and industrial products to nourish the world in a safe, responsible and sustainable way. We connect farmers with markets so they can prosper. We connect customers with ingredients so they can make meals people love. And we connect families with daily essentials— from eggs to edible oils, salt to skincare, feed to flooring. By providing customers with products that are vital for living, we help businesses grow, communities prosper and consumers live well in their daily lives.
Why Work With Us
The decision to join Cargill can open the door to a world of possibility. As part of our Digital, Technology & Data team, you’ll get to be part of a large and diverse group full of unique perspectives united by a common, higher purpose while building a rewarding career full of opportunity, growth and the satisfaction of knowing your work matters.
Gallery
Cargill Teams
Cargill Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.



.jpg)












.jpg)











