Cyber Threat Exposure Management Analyst

Version1

Bengaluru

On-site

INR 1,500,000 - 2,200,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Version1 is seeking a Cyber Threat Exposure Analyst in Bengaluru to lead end-to-end vulnerability lifecycle management across an expanding attack surface. You’ll enrich exposure views using threat intelligence and KPIs, coordinating with platform and engineering teams to remediate CSPM findings and align with ISO 27001 and CTEM practices.

You will own reporting dashboards, communicate risk to senior stakeholders, and support audits while embedding secure development practices within the SDLC.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field
  • 3+ years' experience in cyber security with hands-on exposure to vulnerability management, attack surface management, and/or cloud security
  • Certifications: CompTIA CySA+, CEH, OSCP, CISSP
  • Working knowledge of NIST CSF, ISO 27001, MITRE ATT&CK, and CTEM principles
  • Strong written and verbal communication skills; able to translate technical risk for non-technical stakeholders

Responsibilities

  • Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation.
  • Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths.
  • Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF.
  • Break down complex vulnerability backlogs into prioritised, actionable components and drive them to closure with minimal supervision.
  • Monitor cloud misconfigurations, identity risk, and posture drift across AWS, Azure, and OCI.
  • Partner with cloud platform teams to remediate CSPM findings and reduce recurring misconfiguration classes.
  • Operate the Scope, Discover, Prioritise, Validate, and Mobilise phases of CTEM programme.
  • Consolidate exposure data into a single view for stakeholders; track exposure reduction metrics against KPIs.
  • Embed security requirements and threat modelling into the Secure SDLC; work with engineering teams to reduce vulnerability at source.
  • Translate external test results into prioritised remediation guidance for internal teams.
  • Produce dashboards and reports translating exposure data into business risk language for senior stakeholders.
  • Support audit and certification cycles (ISO 27001, Cyber Essentials Plus, SOC 1) with evidence of exposure management practice.
  • Adapt communication style to audience; explain technical risk clearly to non-technical colleagues and business stakeholders.
  • Meet team commitments and deadlines; support colleagues and adapt to changing priorities

Skills

Cyber security
Vulnerability management
Attack surface management
Cloud security

Education

Bachelor's degree in Computer Science, Information Security, or related field
Certifications: CompTIA CySA+, CEH, OSCP, CISSP

Tools

EASM/CAASM tools
Threat intelligence platforms
Defender XDR
Zscaler
Tanium

Job description

We are seeking a Cyber Threat Exposure Analyst to support our exposure management programme across the estate. The role spans vulnerability management, attack surface management, cloud security posture, and secure development practice. Working as a fully contributing team member, you will own end-to-end vulnerability lifecycle activity, maintain prioritised exposure views, and communicate risk clearly to internal stakeholders. You operate with limited supervision, take clear ownership of your assignments, and consistently deliver to a high standard of quality.

Key Responsibilities
  • Attack Surface Management (ASM / EASM)

    Maintain a continuous inventory of Internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, and third-party-hosted assets.

    Operate EASM/CAASM tooling to surface unowned or unmanaged assets and route them to the correct owner.

    Enrich attack surface findings with threat intelligence, active exploitation trends, and KEV data to support prioritisation.

    Proactively identify gaps in asset coverage and bring forward improvement ideas without waiting to be directed.

  • Vulnerability Management

    Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation.

    Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths.

    Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF.

    Break down complex vulnerability backlogs into prioritised, actionable components and drive them to closure with minimal supervision.

  • Cloud Security Posture Management (CSPM)

    Monitor cloud misconfigurations, identity risk, and posture drift across AWS, Azure, and OCI.

    Partner with cloud platform teams to remediate CSPM findings and reduce recurring misconfiguration classes.

    Extend CSPM coverage as new cloud services, apps, and workloads are onboarded.

    Build and maintain strong working relationships with platform and engineering teams; negotiate remediation timelines and handle pushback constructively.

  • CTEM / Exposure Management

    Operate the Scope, Discover, Prioritise, Validate, and Mobilise phases of the CTEM programme.

    Consolidate attack surface, vulnerability, and posture data into a single exposure view for stakeholders.

    Track and report exposure reduction metrics against agreed KPIs, maintaining accurate and well-organised records across all workstreams.

  • Secure SDLC

    Embed security requirements, threat modelling, and secure code review checkpoints into the SDLC.

    Work with engineering teams to reduce vulnerability injection at source rather than relying only on downstream remediation.

    Maintain secure-by-design standards and guidance for development teams.

  • Pentest & Purple Team Support

    Support the commission and management of third-party penetration testing and purple team engagements.

    Review scope, rules of engagement, and quality of third-party findings before acceptance.

    Translate external test results into prioritised, actionable remediation guidance for internal teams.

  • Reporting & Stakeholder Communication

    Produce dashboards and reports translating technical exposure data into business risk language for senior stakeholders.

    Present exposure trends, remediation progress, and residual risk to management and audit/compliance functions.

    Support audit and certification cycles (ISO 27001, Cyber Essentials Plus, SOC 1, client MSP audits) with evidence of exposure management practice.

    Adapt communication style to the audience; explain technical risk clearly to non-technical colleagues and business stakeholders.

  • Ways of Working

    Meet all team commitments and deadlines; support colleagues encountering blockers and contribute to a collaborative team environment.

    Seek out and act on feedback; treat problems as learning opportunities and continuously update skills and knowledge.

    Adapt readily to changing priorities, new tooling, and evolving threat landscapes without disruption to delivery quality.

  • Live and demonstrate Version 1 Core Values in everyday work, acting as a visible example for more junior colleagues.
Qualifications and Experience
  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
  • 3+ years' experience in cyber security with hands-on exposure to vulnerability management, attack surface management, and/or cloud security.
  • Relevant certifications: CompTIA CySA+, CEH, OSCP, CISSP, or equivalent.
  • Working knowledge of NIST CSF, ISO 27001, MITRE ATT&CK, and CTEM principles.
  • Strong written and verbal communication skills; able to translate technical risk for non-technical stakeholders.
Beneficial Skills
  • Hands-on experience with EASM/CAASM, CSPM, or exposure management platforms.
  • Familiarity with AI-augmented vulnerability triage or detection tooling.
  • Experience with Defender XDR, Defender CSPM, Zscaler, Tanium, or equivalent platforms.
  • Familiarity with Identity Security Posture Management (ISPM) and attack path mapping.
  • Exposure to regulator
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Exposure Management Analyst
Cyber Threat Exposure Management Analyst

Version 1 • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Product Manager - Exposure Management
Product Manager - Exposure Management

Prevalent AI • Ernakulam

On-site
INR 1,500,000 - 2,300,000
Threat Vulnerability Manager
Threat Vulnerability Manager

Trekrecruit India. • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • India

On-site
INR 1,200,000 - 2,400,000
Cyber Security SME - Tenable
Cyber Security SME - Tenable

In2IT • Gautam Buddha Nagar

On-site
INR 4,000,000 - 6,000,000
Senior Cybersecurity Analyst - Threat Exposure Management
Senior Cybersecurity Analyst - Threat Exposure Management

Maersk Line India Pvt Ltd • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Security Vulnerability Analyst
Security Vulnerability Analyst

Experian Group • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Information Security Analyst - Exposure Management
Information Security Analyst - Exposure Management

MathWorks • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Security Engineer / Cybersecurity Specialist
Security Engineer / Cybersecurity Specialist

Codvo.ai • India

On-site
INR 1,200,000 - 2,000,000
Cyber Manager - Threat Exposure Management
Cyber Manager - Threat Exposure Management

Damco Spain SL • India

On-site
INR 1,500,000 - 2,000,000
Diverse and inclusive workplace
Opportunities for professional development