Job Description – Security Analyst, Attack Surface Management
Role: Security Analyst – Attack Surface Management
Experience: 3–6 Years
Technology: Cybersecurity
Location: Hyderabad
Role Overview
We are looking for a Security Analyst – Attack Surface Management with 3–6 years of experience in cybersecurity operations, vulnerability management, attack surface management, or related security analysis roles.
The candidate will be responsible for identifying, analyzing, and monitoring an organization’s attack surface, assessing exposure and misconfiguration risks, and supporting security teams in reducing vulnerabilities and externally exposed assets across enterprise, hybrid, and cloud environments.
Key Responsibilities
- Monitor and analyze the organization’s internal and external attack surface to identify security exposures and risks.
- Discover, identify, and maintain visibility of internet-facing and enterprise assets.
- Analyze vulnerabilities, misconfigurations, exposed services, and other potential attack vectors.
- Support Attack Surface Management (ASM) and vulnerability management activities.
- Identify risks arising from cloud misconfigurations, identity sprawl, shadow IT, unmanaged assets, and exposed internet-facing services.
- Use security tools such as Rapid7, Microsoft Defender, Claroty, and Prevalent.ai for security monitoring, exposure assessment, asset discovery, and risk analysis.
- Correlate vulnerabilities with exposure, exploitability, and business impact to help prioritize remediation.
- Work with infrastructure, cloud, application, and security teams to investigate and reduce identified exposures.
- Track remediation activities and validate that identified security risks have been appropriately addressed.
- Contribute to security reporting, risk dashboards, and management-level visibility of attack surface risks.
- Support security incident investigations where exposed assets or vulnerabilities contribute to potential threats.
- Identify recurring exposure patterns and recommend improvements to security controls and processes.
- Stay current with emerging attack vectors, vulnerabilities, cloud security risks, and attack surface management practices.
Must-Have Skills
- 3–6 years of experience in cybersecurity operations, vulnerability management, attack surface management, or security analysis.
- Hands-on experience with one or more cybersecurity domains such as:
- Attack Surface Management
- Vulnerability Management
- Security Operations
- Exposure ManagementSecurity Risk AnalysisHands-on experience with Rapid7, Microsoft Defender, Claroty, and/or Prevalent.ai.
- Experience working in enterprise, hybrid, or cloud-enabled environments.
- Strong understanding of security exposures, vulnerabilities, and risk identification.
- Ability to analyze security findings and determine their potential business impact.
- Good understanding of cybersecurity concepts, threat vectors, and security best practices.
- Strong analytical and problem-solving skills.
- Relevant cybersecurity certifications are preferred.
Good-to-Have Skills
- Working knowledge of Attack Surface Management (ASM) concepts, including:
- External exposure discovery
- Asset inventory and asset visibility challenges
- Misconfiguration risk
- Internet-facing asset discovery
- Understanding of common attack surface exposure drivers, including:
- Cloud misconfigurations
- Identity sprawl
- Shadow IT
- Unmanaged assets
- Exposed internet-facing services
- Familiarity with vulnerability management principles and vulnerability prioritization.
- Understanding of the relationship between vulnerabilities, exposure, exploitability, and business risk.
- Awareness of how attack surface risks can contribute to:
- Ransomware
- Data breaches
- Business disruption
- Unauthorized access
- Understanding of how exposure reduction contributes to:
- Cyber resilience
- Security risk reduction
- Cyber insurance posture
- Regulatory and compliance expectations
Preferred Certifications
Relevant cybersecurity certifications such as Security+, CEH, CySA+, GSEC, CISSP, or equivalent will be an advantage.
Ideal Candidate Profile
The ideal candidate is a cybersecurity professional with strong exposure to Attack Surface Management and Vulnerability Management, capable of identifying security exposures across enterprise and cloud environments and translating technical findings into actionable remediation priorities.
The candidate should be comfortable working with security tools, analyzing exposure and vulnerability data, collaborating with cross-functional teams, and contributing to the organization's overall cyber resilience and risk reduction strategy.