Security Analyst, Attack Surface Management
MiddleOn-site (Hyderabad)Salary undisclosed
Required Skills
PythonAWSAzure
Job Description
Job Title: Security Analyst, Attack Surface Management
Summary
The Attack Surface Management team owns what happens after a vulnerability is found. Findings arrive from red team pentests, adversary simulations, external bug bounty submissions, and scanning coverage. This role validates them, determines real impact, and drives them to closure with the engineering teams that own the affected assets. Critical findings route to Incident Response. Everything rated High and Medium is this team's responsibility until it is patched or a compensating control is in place and documented.
This is not a patch operations role. Separate teams apply fixes. This role decides what matters, why it matters, and holds the line until it is resolved.
Responsibilities
Triage and validate inbound Bugcrowd submissions: reproduce the reported issue, confirm or reject it, deduplicate against known findings, and determine payout-relevant severity.
Independently assess impact rather than accepting a submitter's or a scanner's rating. Factor in exploitability, asset exposure, data sensitivity, authentication requirements, and existing controls.
Track High and Medium findings from red team engagements and adversary simulations through remediation, including retest and closure verification.
Evaluate and document compensating controls where a fix is not immediately viable, and set expiry conditions rather than leaving exceptions open indefinitely.
Write remediation guidance that an application or platform eng
Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.