Security Analyst, Attack Surface Management

Metmox

Hyderabad

On-site

INR 1,200,000 - 1,800,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Metmox is seeking an Attack Surface Management specialist to validate vulnerability findings sourced from bug bounty submissions, red team exercises, and external scans. You will determine real impact and drive closure with engineering teams responsible for affected assets.

This role requires practical threat analysis, strong written communication, and hands-on use of Burp Suite and API testing tools. A track record in bug bounty and OWASP knowledge is preferred.

Qualifications

  • 2+ years in application security, vulnerability management, penetration testing, or bug bounty work.
  • Proficient in web app and API penetration testing with ability to reproduce and validate findings.

Responsibilities

  • Triage and validate inbound Bugcrowd submissions: reproduce, confirm/reject, deduplicate, determine severity.
  • Assess impact beyond submitter ratings; consider exploitability, asset exposure, data sensitivity, authentication, and controls.
  • Track High and Medium findings from red team engagements through remediation and retest.
  • Document compensating controls when fixes aren’t viable; set expiry conditions for exceptions.
  • Write remediation guidance that engineers can act on without additional translation.
  • Escalate critical findings to Incident Response with detail and scope.
  • Coordinate with owners and product teams on remediation timelines and risk acceptance where needed.
  • Maintain visibility into externally exposed assets and flag new attack surface areas.

Skills

Penetration testing
Bug bounty
Written communication
Threat analysis

Education

Certifications such as BSCP OSWA OSCP CPTS PNPT

Tools

Burp Suite
Postman

Job description

Summary

The Attack Surface Management team owns what happens after a vulnerability is found. Findings arrive from red team pentests, adversary simulations, external bug bounty submissions, and scanning coverage. This role validates them, determines real impact, and drives them to closure with the engineering teams that own the affected assets. Critical findings route to Incident Response. Everything rated High and Medium is this teams responsibility until it is patched or a compensating control is in place and documented.

This is not a patch operations role. Separate teams apply fixes. This role decides what matters, why it matters, and holds the line until it is resolved.

Responsibilities
  • Triage and validate inbound Bugcrowd submissions: reproduce the reported issue, confirm or reject it, deduplicate against known findings, and determine payout-relevant severity.
  • Independently assess impact rather than accepting a submitters or a scanners rating. Factor in exploitability, asset exposure, data sensitivity, authentication requirements, and existing controls.
  • Track High and Medium findings from red team engagements and adversary simulations through remediation, including retest and closure verification.
  • Evaluate and document compensating controls where a fix is not immediately viable, and set expiry conditions rather than leaving exceptions open indefinitely.
  • Write remediation guidance that an application or platform engineer can act on without further translation.
  • Escalate Critical findings to Incident Response with the reproduction detail and blast radius assessment they need to act.
  • Partner with application owners and product teams on remediation timelines, and raise risk acceptance decisions to leadership when timelines slip.
  • Maintain visibility into externally exposed assets and flag newly surfaced attack surface for assessment.
Required Qualifications
  • Two or more years in application security, vulnerability management, penetration testing, or bug bounty work.
  • Working proficiency in web application and API penetration testing. You should be able to independently reproduce a submitted finding, elevate it if the submitter undersold it, and prove it is a false positive if it is one.
  • Practical knowledge of OWASP Top 10 and OWASP API Security Top 10, including what remediation actually looks like for each class of issue.
  • Familiarity with MITRE ATTCK techniques and the ability to connect a finding to how an attacker would chain it.
  • Severity determination beyond a CVSS calculator. You can explain why a High-scoring finding on an isolated internal asset may matter less than a Medium on an internet-facing authentication flow.
  • Hands-on experience with Burp Suite and standard web and API testing tooling.
  • Clear written communication. Much of this role is convincing an engineering team that a finding is real and worth their sprint capacity.
Preferred Qualifications
  • Demonstrated bug bounty track record on Bugcrowd, HackerOne, or Intigriti.
  • Experience triaging submissions from the program side.
  • Cloud security exposure across AWS or Azure, particularly identity and storage misconfigurations.
  • Certifications such as BSCP, OSWA, OSCP, CPTS, or PNPT. A public bug bounty profile carries equal weight.

Scripting in Python for reproduction harnesses and finding automation.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst, Attack Surface Management
Security Analyst, Attack Surface Management

Uvcyber • Hyderabad

On-site
INR 900,000 - 1,500,000
Security Analyst, Attack Surface Management
Security Analyst, Attack Surface Management

UltraViolet Cyber • Hyderabad

On-site
INR 700,000 - 1,200,000
Cyber Analysts - Vulnerability Management and Penetration Testing
Cyber Analysts - Vulnerability Management and Penetration Testing

Tata Power • Navi Mumbai, Mumbai

On-site
INR 800,000 - 1,400,000
Cyber Security Consultant
Cyber Security Consultant

Infosys • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Security Vulnerability Analyst
Security Vulnerability Analyst

Experian Group • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Security Engineer
Security Engineer

AppViewX • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Application Security Engineer
Application Security Engineer

Cyberpwn • Bengaluru

On-site
INR 900,000 - 1,300,000
Security Analyst / Sr. Security Analyst
Security Analyst / Sr. Security Analyst

Nio Stars Technologies LLP • Mumbai

On-site
INR 1,200,000 - 2,400,000