Talent.com
Attack Surface Reduction Analyst
Attack Surface Reduction AnalystH&M Group • Bangalore, Karnataka, India
Attack Surface Reduction Analyst

Attack Surface Reduction Analyst

H&M Group • Bangalore, Karnataka, India
19 days ago
Job description

WHAT YOULL DO

We are seeking a skilled and experienced Attack Surface Reduction Analyst with a strong background in penetration testing to join our cybersecurity team. The successful candidate will be responsible for identifying potential security risks and vulnerabilities in our organizations systems applications and networks performing penetration testing and facilitating and managing third-party penetration testing engagements.

WHO YOULL WORK WITH

Attack Surface Reduction team helps and contribute to improve the security posture of H&M by operating within an Agile model. We play a crucial role in proactively identifying and help in mitigating potential security risks and vulnerabilities across H&Ms systems applications and networks with the aim of preventing unauthorized access data breaches and other security incidents.

Key Responsibilities :

  • Conduct comprehensive vulnerability assessments (VA) and penetration tests (PT) on H&Ms systems networks and applications.
  • Utilize industry-standard tools and methodologies to identify potential vulnerabilities and weaknesses in our attack surface.
  • Collaborate with cross-functional teams to prioritize and remediate identified vulnerabilities in a timely manner.
  • Experience in designing implementing and managing vulnerability management processes and workflows.
  • Facilitate and manage penetration testing engagements with third-party vendors.
  • Collaborate with other members of the cybersecurity team to develop and implement strategies to reduce our attack surface.
  • Develop and maintain security policies and procedures for our organizations systems applications and networks.
  • Monitor our organizations systems applications and networks for unauthorized access suspicious activity and other security threats.
  • Stay up to date with the latest trends and developments in the field of cybersecurity specifically related to attack surface reduction techniques.

WHO YOU ARE

We are looking for people with

  • Bachelors degree in computer science information security or a related field.
  • 3-5 years of experience in vulnerability scanning vulnerability management and penetration testing.
  • Solid knowledge of common vulnerabilities and exposures (CVEs) common attack vectors and security best practices.
  • Strong knowledge of security assessment tools vulnerability scanning and penetration testing.
  • Proficient in using industry-standard vulnerability assessment and penetration testing tools (e.g. Kali Distro Qualys Burp Suite etc.).
  • Familiarity with industry frameworks and standards such as NIST OWASP and CIS.
  • Effective communication skills with the ability to clearly convey technical concepts to both technical and non-technical stakeholders.
  • Excellent analytical problem-solving and communication skills.
  • Relevant certifications such as SANS OSCP OSEP CompTIA Security or CREST are a plus.
  • WHY YOULL LOVE WORKING HERE

    At H&M we are proud to be a vibrant and welcoming company. We offer our employees attractive benefits with extensive development opportunities around the globe.

    We offer all our employees at H&M attractive benefits with extensive development opportunities around the globe. All our employees receive a staff discount card usable on all our H&M brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included) COS Weekday Monki H&M HOME & Other Stories ARKET addition to our staff discount all our employees are included in our H&M Incentive Program HIP. You can read more about our H&M Incentive Program here.

    In addition to our global benefits all our local markets offer different competitive perks and benefits. Please note that they may differ between employment types and countries.

    JOIN US

    Our uniqueness comes from a combination of many things our inclusive and collaborative culture our strong values and opportunities for growth. But most of all its our people who make us who we are.

    Take the next step in your career together with us. The journey starts here.

  • We are committed to a recruitment process that is fair equitable and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
  • ADDITIONAL INFORMATION

    This is a full-time position starting in October 2025 .

    Apply by sending in your  CV in English  as soon as possible but no later than the  30th of September 2025 . Due to data policies we only accept applications through the SmartRecruiters or career page

    Remote Work : No

    Employment Type : Full-time

    Key Skills

    ArcGIS,Intelligence Community Experience,GIS,Python,Computer Networking,Data Collection,Intelligence Experience,R,Relational Databases,Analysis Skills,Data Management,Application Development

    Experience : years

    Vacancy : 1

    Create a job alert for this search

    Analyst • Bangalore, Karnataka, India

    Related jobs
    Senior Vulnerability Management Analyst

    Senior Vulnerability Management Analyst

    ITC Infotech • Bengaluru, Republic Of India, IN
    On the portal where vulnerabilities are listed, each vulnerability must be analyzed;.Within each record of each vulnerability, analyze the required fixes and the vendor involved.Contact the vendor ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Disaster Recovery Engineer

    Senior Disaster Recovery Engineer

    Finastra • bangalore district, karnataka, in
    At least 5+ years of relevant IT experience, with 3+ years focused on Disaster Recovery.Proficient with up-to-date DR strategies and methodologies. Knowledge of replication tools (ASR, Zerto, DataGu...Show more
    Last updated: 6 hours ago • Promoted • New!
    Vulnerability Remediation Specialist

    Vulnerability Remediation Specialist

    Infogain • Bengaluru, Republic Of India, IN
    Title : Security Engineer (6+ Years).Use CrowdStrike reports to evaluate all security vulnerabilities on both Windows and Linux systems. Analyze the requirements to remediate the security vulnerabili...Show more
    Last updated: 30+ days ago • Promoted
    Operational Risk Analyst

    Operational Risk Analyst

    Alp Consulting Ltd. • Bengaluru, Republic Of India, IN
    A Business Impact Analyst is responsible for assessing the impact of potential risks, threats, and vulnerabilities to a company's ongoing operations, regulatory compliance, corporate reputation, an...Show more
    Last updated: 4 days ago • Promoted
    Managed Detection and Response Analyst

    Managed Detection and Response Analyst

    Palo Alto Networks • Bengaluru, Republic Of India, IN
    At Palo Alto Networks® everything starts and ends with our mission : .Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and m...Show more
    Last updated: 30+ days ago • Promoted
    Senior Threat Response Analyst

    Senior Threat Response Analyst

    HR Path • Bengaluru, Republic Of India, IN
    HR Path Group, a global leader in HR consulting, helps clients with their HR transformation projects, covering both human and HRIS (Human Resources Information System) aspects.Our 2,500 employees a...Show more
    Last updated: 9 days ago • Promoted
    Tier 2 Endpoint Security Analyst

    Tier 2 Endpoint Security Analyst

    Check Point Software • Bengaluru, Republic Of India, IN
    Troubleshoot and resolve endpoint installation, configuration, connectivity, and performance issues across Windows, macOS, and Linux environments. Perform deep-dive analysis using system logs, trace...Show more
    Last updated: 22 days ago • Promoted
    Vulnerability Management - L3

    Vulnerability Management - L3

    ITC Infotech • Bengaluru, Karnataka, India
    On the portal where vulnerabilities are listed, each vulnerability must be analyzed;.Within each record of each vulnerability, analyze the required fixes and the vendor involved.Contact the vendor ...Show more
    Last updated: 30+ days ago • Promoted
    RevOps Analyst

    RevOps Analyst

    Whatfix • Bengaluru, India
    Whatfix is an AI platform advancing the “userization” of enterprise applications, empowering companies to maximize the ROI of their digital investments. As AI reshapes roles, workflows, and human-ma...Show more
    Last updated: 30+ days ago • Promoted
    Vulnerability Remediation Lead

    Vulnerability Remediation Lead

    ITC Infotech • Bengaluru, Republic Of India, IN
    On the portal where vulnerabilities are listed, each vulnerability must be analyzed;.Within each record of each vulnerability, analyze the required fixes and the vendor involved.Contact the vendor ...Show more
    Last updated: 30+ days ago • Promoted
    Senior DevOps & Database Reliability Engineer – 100% Remote

    Senior DevOps & Database Reliability Engineer – 100% Remote

    Hyly.AI • Bangalore, IN
    Remote
    AI, we’re building the first AI + Data Fabric for the multifamily industry, transforming how clients manage, secure, and scale their marketing and operational data. As the industry moves toward a co...Show more
    Last updated: 14 days ago • Promoted
    Site Reliability Engineer

    Site Reliability Engineer

    Veca Consulting Pvt Ltd • Bengaluru, Karnataka, India
    Role Name : SRE & Devops Engineer(Bigdata).Location : Bangalore(No relocation).Notice Period : 20-30 days(who are currently serving). You will be a member of our AI Platform Team, supporting the next...Show more
    Last updated: 12 days ago • Promoted
    Revops Analyst

    Revops Analyst

    Whatfix • Bengaluru, Republic Of India, IN
    Whatfix is an AI platform advancing the “userization” of enterprise applications, empowering companies to maximize the ROI of their digital investments. As AI reshapes roles, workflows, and human-ma...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Analyst - Vulnerability Management

    Senior Security Analyst - Vulnerability Management

    IH • Bengaluru, Republic Of India, IN
    Qualys / Qualysguard modules (VMDR, Cloud Agent, Container Security), Public Cloud – AWS and Azure, Network Vulnerability Scanning, Scripting (Python, PowerShell).Show more
    Last updated: 1 hour ago • Promoted • New!
    Attack Surface Reduction Senior Analyst

    Attack Surface Reduction Senior Analyst

    Aqilea (formerly Soltia) • Bengaluru, Karnataka, India
    We are a consulting company with a bunch of technology-interested and happy people!.We love technology, we love design and we love quality. Our diversity makes us unique and creates an inclusive and...Show more
    Last updated: 30+ days ago • Promoted
    Cloud Security Lead Analyst

    Cloud Security Lead Analyst

    MUFG • Bengaluru, Republic Of India, IN
    Japan’s premier bank, with a global network spanning in more than 40 markets.Outside of Japan, the bank offers an extensive scope of commercial and investment banking products and services to busin...Show more
    Last updated: 20 days ago • Promoted
    Senior Threat Intelligence Analyst

    Senior Threat Intelligence Analyst

    FICO • Bengaluru, Republic Of India, IN
    FICO (NYSE : FICO) is a leading analytics software company, helping businesses in 90+ countries make better decisions that drive higher levels of growth, profitability and customer satisfaction.The ...Show more
    Last updated: 30+ days ago • Promoted
    Cyber Threat Response Analyst

    Cyber Threat Response Analyst

    Embitel Technologies • Bengaluru, Republic Of India, IN
    We are seeking a highly skilled and detail-oriented Cyber Security Specialist to protect our organization's digital assets and infrastructure from cyber threats. The ideal candidate will have a stro...Show more
    Last updated: 11 days ago • Promoted