Stand out for this role — generate a tailored resume and cover letter in about a minute.
Metmox is seeking an Attack Surface Management specialist to validate vulnerability findings sourced from bug bounty submissions, red team exercises, and external scans. You will determine real impact and drive closure with engineering teams responsible for affected assets.
This role requires practical threat analysis, strong written communication, and hands-on use of Burp Suite and API testing tools. A track record in bug bounty and OWASP knowledge is preferred.
The Attack Surface Management team owns what happens after a vulnerability is found. Findings arrive from red team pentests, adversary simulations, external bug bounty submissions, and scanning coverage. This role validates them, determines real impact, and drives them to closure with the engineering teams that own the affected assets. Critical findings route to Incident Response. Everything rated High and Medium is this teams responsibility until it is patched or a compensating control is in place and documented.
This is not a patch operations role. Separate teams apply fixes. This role decides what matters, why it matters, and holds the line until it is resolved.
Scripting in Python for reproduction harnesses and finding automation.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.