Attack Surface Management (ASM)
Forvia, a sustainable mobility technology leader
Your Mission, Roles And Responsibilities
We are seeking a motivated and analytical Cybersecurity Analyst Junior, based in Portugal, to support our global vulnerability management efforts with a focus on attack surface monitoring, threat intelligence analysis, and third‑party incident coordination.
The role reports to the Vulnerability Management Lead in Portugal and requires close collaboration with cross‑functional teams across regions. The ideal candidate will be autonomous, demonstrate initiative, have good communication skills and a strong willingness to learn. While experience with Recorded Future and Palo Alto Cortex is a plus, it is not required.
Main Missions
- Attack Surface Management (ASM)
- Support the identification and reduction of the organization’s external attack surface.
- Track and follow up on vulnerabilities across external‑facing assets; contribute to risk assessment documentation.
- Work closely with first‑line operational teams to ensure remediation actions are initiated and tracked.
- Collaborate with the vulnerability management team in Europe to ensure alignment on strategy and execution.
- Contribute to regular reporting and maintain up‑to‑date asset visibility.
- Cyber Threat Intelligence (CTI) – Third‑Party Risk Focus
- Use Recorded Future to collect and analyze threat intelligence relevant to the organization and its third parties.
- Identify vulnerabilities and threats affecting suppliers and partners to enhance risk assessment.
- Enrich and maintain the third‑party CMDB using intelligence from CTI feeds.
- Monitor emerging attack techniques that may impact the extended ecosystem.
- Support the improvement of third‑party vulnerability management in coordination with our CTI partner.
- Third‑Party Incident Coordination
- Contribute to third‑party incident response by working with the Security Operations Center (SOC) and business stakeholders.
- Help coordinate investigations and remediation activities during third‑party security incidents.
- Maintain active communication with external cybersecurity contacts and internal business owners to strengthen response capabilities.
Your profile and competencies to succeed
Technical Skills
- One year or more experience in IT operations and Cybersecurity.
- Experience with attack surface management tools or CTI platforms (e.g., Recorded Future).
- Familiarity with vulnerability scanning, asset inventory tools, or CMDB systems.
- Certifications such as Security+, CySA+, GCTI, or equivalent.
- Scripting skills (Python, Bash, or PowerShell) for automation or data parsing.
Behavioral Skills
- Bachelor’s degree in Cybersecurity.
- 1–3 years of experience in cybersecurity, ideally with exposure to vulnerability management or threat analysis.
- Strong understanding of cybersecurity fundamentals, including vulnerability and risk management, third‑party risk, and threat landscape.
- Excellent communication and coordination skills in a distributed, international team setting.
- Ability to work independently and demonstrate initiative in a fast‑paced environment.
Compensation and Benefits
- Salary Range: EUR 22 300 – 32 700
- Total compensation will be defined according to the candidate’s skills, professional experience, and competencies.
- Learning environment with extensive training programs.
- Inclusive and diverse workplace culture.
- Commitment to sustainability and net‑zero goals.