Talent.com
This job offer is not available in your country.
Attack Surface management

Attack Surface management

ConfidentialIndia, Mumbai
4 hours ago
Job description

The VOC VI & ASM Analyst will be part of a team responsible for monitoring and identifying vulnerabilities as well as proactively assessing their threat . The team also provides

comprehensive feedback and guidance on detected vulnerabilities to assist Security Officers and Application Manager on the remediation part.

This role takes a holistic approach to identifying newly published vulnerabilities and contextualizing them to company environment as well as tracking potential external entry points to systems and data.

The VOC VI & ASM Analyst is responsible for :

Vulnerability Intelligence (VI) :

o Monitor new vulnerabilities and assess their criticality and risk severity based on threat, exploit

availability, ease of exploit, impact, …

o Communicate and publish an assessment on vulnerabilities related to software

o Maintain timely, high-quality vulnerability bulletins, prioritizing issues against the Group's asset

exposure

o Update on a regular basis our software inventory in the scope of Vulnerability Assessment

Service

o Keep the vulnerability database up to date; enrich each CVE and security bulletin with QDS,

EPSS, CVSS metrics, …

Attack Surface Management (ASM) :

o Operate continuous monitoring of external assets via ASM Security tools

o Update on a regular basis the coverage of ASM tools, by adding known domains and IP ranges

o Assess the severity of the findings and confirm their presence (review, challenge, FP assessment,

o Track and report exposure trends; escalate high-risk findings to Blue-Team remediation owners

o Build and use the external footprint to proactively identify new threats and new vulnerabilities

o Leverage ASM tools to proactively identify external assets subject to newly published

vulnerabilities

BlackBox Pentesting :

o Drive proactive follow-up on detected vulnerabilities, engaging system owners and tracking

remediation to closure

o Active follow up with Application managers to onboard new application in the BlackBox

Pentesting service

Vulnerability Management :

o Vulnerability review, recategorization, and false positive identification

o Proactive vulnerability testing and replay

o Pre-analyze and consolidate vulnerability data from various scanning tools

o Prepare concise syntheses of available vulnerabilities

o Offer guidance to the SO and CISO on vulnerabilities

o Collaborate with key stakeholders to develop strategies for vulnerability management

Scripting and automation :

o Automate data extraction and data push from VI and ASM tools to DataLake tools

o Build automation workflows to streamline vulnerability identification, assessment, and reporting

o Collaborate with the offensive and defensive teams to enhance vulnerability assessment and

testing

Bachelor degree in Computer Science, Information Security, EXTC or related field; relevant certifications (e.g., CISSP, CCSP, CompTIA Security+) are a plus

 Proven experience (6+ years) working within the Cybersecurity field, with emphasis on security platform implementation & administration

 Experience on Penetration testing actions (web application, infrastructure, …)

 Experience with security scanning tools

 Experience with VI and ASM tools

 Experience in investigating newly published vulnerabilities and assessing their risks and severity

 Experience with scripting languages (e.g., Python, Bash, Powershell, C#, …) for automation and customization of security processes is a plus

 Experience with Pentester tools (Burp, SQLmap, Metasploit, Kali environment, …)

 Strong technical skills with an interest in open-source intelligence investigations

 Knowledge of NIST CVE database, OWASP Top 10, Microsoft security bulletins

 Excellent writing skills in English and ability to communicate complicate technical challenges in a business language to a range of stakeholders.

Personal Skills

 Has a systematic, disciplined, and analytical approach to problem solving with Thorough leadership skills &

experience

 Excellent ability to think critically under pressure

 Strong communication skills to convey technical concepts clearly to both technical and non-technical

stakeholders

 Willingness to stay updated with evolving cyber threats, technologies, and industry trends

 Capacity to work collaboratively with cross-functional teams, developers, and management to implement robust

security measures

Show more

Show less

Skills Required

Vulnerability Management, Owasp Top 10

Create a job alert for this search

Management • India, Mumbai

Related jobs
  • Promoted
Oracle Cloud Security and Risk Management (RMC) Consultant

Oracle Cloud Security and Risk Management (RMC) Consultant

AtomThane, IN
Job Title : Oracle Cloud Security and Risk Management (RMC) Consultant.We are seeking an experienced Oracle Cloud Security and Risk Management (RMC) Consultant to join our team.The ideal candidate w...Show moreLast updated: 30+ days ago
  • Promoted
Cloud Architect

Cloud Architect

iVedha Inc.Kalyan-Dombivli, IN
Seeking a highly experienced Cloud Architect to design and oversee robust, scalable, and secure.Architect end-to-end cloud solutions (public, private, hybrid) with a focus on reliability, security,...Show moreLast updated: 30+ days ago
  • Promoted
Business Unit Head - Security Awareness

Business Unit Head - Security Awareness

EC-Councilmumbai, maharashtra, in
We operate in 145 countries globally and we are the owner and developer of various world-famous cyber security programs.We are proud to have trained and certified over 400,000 information security ...Show moreLast updated: 14 days ago
  • Promoted
L3 Server Engineer – Major Incident Management

L3 Server Engineer – Major Incident Management

Nextbridge IT SolutionsThane, IN
We are seeking an experienced L3 Infrastructure Engineer to join our IT Operations team with a focus on Major Incident Management (MIM), incident request management, and rapid response for Priority...Show moreLast updated: 7 days ago
  • Promoted
Technical Manager

Technical Manager

Eventus Securitynavi mumbai, maharashtra, in
With a trained team and a client-first approach, we ensure safety, trust, and peace of mind across corporate, residential, and industrial sectors. Job Title : Technical Manager - Cyber Resilience.Eve...Show moreLast updated: 7 days ago
  • Promoted
Cloud Security Engineer

Cloud Security Engineer

AquanowThane, IN
Aquanow, a leading infrastructure and liquidity provider that provides institutional and enterprise application platforms for digital assets, is looking for a Cloud Security Engineer to join our te...Show moreLast updated: 26 days ago
  • Promoted
  • New!
Third Party Risk Management - Cyber Security (Pune, Bangalore, Gurgaon)

Third Party Risk Management - Cyber Security (Pune, Bangalore, Gurgaon)

DigiHelic Solutions Pvt. Ltd.Mumbai, IN
Lead the end-to-end third-party risk assessment process including initial due diligence, onboarding, and periodic reviews. Collaborate and lead discussions with various departments from client’s tea...Show moreLast updated: less than 1 hour ago
  • Promoted
UCCE L3 Engineer

UCCE L3 Engineer

Servion Global SolutionsKalyan-Dombivli, IN
Supporting Experience on Cisco UCCE / UCCX / PCCE solutions & 3rd party Call recording platforms.Basic Cisco ICM / CCMP / CVP / CUIC & troubleshooting. MACD creation knowledge in Cisco UCCE & IPT platform...Show moreLast updated: 17 days ago
  • Promoted
SAP Basis Cloud architect Advisory

SAP Basis Cloud architect Advisory

HCLTechKalyan-Dombivli, IN
CAA (Cloud Architect Advisory).This is SAP Cloud Architect position which is elevated role as per career progression / path for SAP Basis consultant. Architect’s primary role / responsibility is to pl...Show moreLast updated: 30+ days ago
  • Promoted
Cloud Security Architect

Cloud Security Architect

CloudThatthane, maharashtra, in
Strategic role ensuring secure cloud design by reviewing infrastructure, tools, and practices across full cloud lifecycle. Own end-to-end security in project life cycle.Perform security design revie...Show moreLast updated: 25 days ago
  • Promoted
AWS Cloud Engineer

AWS Cloud Engineer

ProgliteThane, IN
Infrastructure & System Administration : .Deploy, manage, and optimize EC2 instances across dev, test, and production environments. Perform system administration and troubleshooting for Linux and Wind...Show moreLast updated: 7 days ago
  • Promoted
  • New!
Engineer

Engineer

Nextbridge IT SolutionsKalyan-Dombivli, IN
We are seeking an experienced subject matter expertise in the Fortinet.This critical role is centered on high-severity incident management, complex security troubleshooting, and architectural impro...Show moreLast updated: less than 1 hour ago
  • Promoted
Network Security Engineer

Network Security Engineer

Integrated Wireless Solutionsmumbai, maharashtra, in
Job Title : Security L2 Engineer.Work Mode : Work from Office (5 Days Working - General Shift).We are seeking a highly skilled and experienced Security L3 Engineer to join our team.This individual wi...Show moreLast updated: 26 days ago
  • Promoted
  • New!
Cloud Architect

Cloud Architect

IntraEdgeKalyan-Dombivli, IN
Senior Cloud Architecture Engineer.The Senior Cloud Architecture Engineer is responsible for designing, building and maintaining the underlying PaaS systems that products and services run on, with ...Show moreLast updated: less than 1 hour ago
  • Promoted
Network Engineer SME

Network Engineer SME

Zensar TechnologiesKalyan-Dombivli, IN
Lead the end-to-end architecture, design, and review of LAN / WAN networks for enterprise-scale deployments.Define and implement telecom infrastructure blueprints, including connectivity models, secu...Show moreLast updated: 17 days ago
  • Promoted
  • New!
Security Consultant (Red Teamer)

Security Consultant (Red Teamer)

ChaleitThane, IN
We're hiring a Specialist Red Teamer to join Chaleit Services.If you have 4–8 years of hands-on offensive security experience and love emulating real adversaries to harden defences, we want to talk...Show moreLast updated: less than 1 hour ago
  • Promoted
  • New!
Tech Engineer for Secure Key Management - Azure (Pune & Hyderabad)

Tech Engineer for Secure Key Management - Azure (Pune & Hyderabad)

DigiHelic Solutions Pvt. Ltd.Thane, IN
Job Title : Tech Engineer for Secure Key Mgmt (Azure).Hands-on experience with Microsoft Azure Security Technologies – specifically Azure KeyVault, Azure Managed HSM, or Dedicated HSM.Strong underst...Show moreLast updated: less than 1 hour ago
  • Promoted
L3 UCCE and Release Management

L3 UCCE and Release Management

Servion Global SolutionsThane, IN
Role : L3 UCCE support and Release Management.Supporting Experience on Cisco UCCE / UCCX / PCCE solutions & 3rd party Call recording platforms. Basic Cisco ICM / CCMP / CVP / CUIC & troubleshooting.MACD cr...Show moreLast updated: 17 days ago