Jobs Companies Uvcyber Security Analyst, Attack Surface Management

À propos de ce poste Security Analyst, Attack Surface Management chez Uvcyber

Uvcyber · Sur site · Hyderabad

Job Title: Security Analyst, Attack Surface Management

Summary

The Attack Surface Management team owns what happens after a vulnerability is found. Findings arrive from red team pentests, adversary simulations, external bug bounty submissions, and scanning coverage. This role validates them, determines real impact, and drives them to closure with the engineering teams that own the affected assets. Critical findings route to Incident Response. Everything rated High and Medium is this team's responsibility until it is patched or a compensating control is in place and documented.

This is not a patch operations role. Separate teams apply fixes. This role decides what matters, why it matters, and holds the line until it is resolved.

Responsibilities

  • Triage and validate inbound Bugcrowd submissions: reproduce the reported issue, confirm or reject it, deduplicate against known findings, and determine payout-relevant severity.
  • Independently assess impact rather than accepting a submitter's or a scanner's rating. Factor in exploitability, asset exposure, data sensitivity, authentication requirements, and existing controls.
  • Track High and Medium findings from red team engagements and adversary simulations through remediation, including retest and closure verification.
  • Evaluate and document compensating controls where a fix is not immediately viable, and set expiry conditions rather than leaving exceptions open indefinitely.
  • Write remediation guidance that an application or platform engineer can act on without further translation.
  • Escalate Critical findings to Incident Response with the reproduction detail and blast radius assessment they need to act.
  • Partner with application owners and product teams on remediation timelines, and raise risk acceptance decisions to leadership when timelines slip.
  • Maintain visibility into externally exposed assets and flag newly surfaced attack surface for assessment.

Required Qualifications

  • Two or more years in application security, vulnerability management, penetration testing, or bug bounty work.
  • Working proficiency in web application and API penetration testing. You should be able to independently reproduce a submitted finding, escalate it if the submitter undersold it, and prove it is a false positive if it is one.
  • Practical knowledge of OWASP Top 10 and OWASP API Security Top 10, including what remediation actually looks like for each class of issue.
  • Familiarity with MITRE ATT&CK techniques and the ability to connect a finding to how an attacker would chain it.
  • Severity determination beyond a CVSS calculator. You can explain why a High-scoring finding on an isolated internal asset may matter less than a Medium on an internet-facing authentication flow.
  • Hands-on experience with Burp Suite and standard web and API testing tooling.
  • Clear written communication. Much of this role is convincing an engineering team that a finding is real and worth their sprint capacity.

Preferred Qualifications

  • Demonstrated bug bounty track record on Bugcrowd, HackerOne, or Intigriti.
  • Experience triaging submissions from the program side.
  • Cloud security exposure across AWS or Azure, particularly identity and storage misconfigurations.
  • Certifications such as BSCP, OSWA, OSCP, CPTS, or PNPT. A public bug bounty profile carries equal weight.

Scripting in Python for reproduction harnesses and finding automation.

Prêt à postuler chez Uvcyber ?
Postuler chez Uvcyber

Emplois similaires

Dnb
Senior Cyber Security Analyst (R-19638)
Dnb
⚡ Postuler tôt Hyderabad - India Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 2 sem.
Uvcyber
Senior Security Analyst
Uvcyber
⚡ Postuler tôt Hyderabad Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 sem.
Pico
Information Security Analyst
Pico
⚡ Postuler tôt Hyderabad Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 2 mois
Pico
Information Security Analyst
Pico
⚡ Postuler tôt Krakow Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 2 mois
Capgemini
FBS Information Security Analyst
Capgemini
⚡ Postuler tôt Hyderabad, Telangana, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 mois
Scaleway
DevOps Cybersecurity Engineer
Scaleway
⚡ Postuler tôt Paris Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 1 h
MetroStar
Cybersecurity Engineer II (6708)
MetroStar
⚡ Postuler tôt Tysons Corner, VA Sur site $166,000–$202,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 h
MetroStar
Sr. Cybersecurity Engineer II (6708)
MetroStar
⚡ Postuler tôt Herndon, VA Sur site $166,000–$202,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 h
MetroStar
Cybersecurity Engineer II (6708)
MetroStar
⚡ Postuler tôt Washington, DC Sur site $166,000–$202,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Uvcyber

Voir tous les emplois chez Uvcyber →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit