Attack Surface Analyst

3 weeks ago


London, Greater London, United Kingdom Vallum Associates Full time

Vallum Associates is seeking an experienced Attack Surface Analyst to help us strengthen our cybersecurity posture and protect our digital assets. As an Attack Surface Analyst, you will play a crucial role in identifying, assessing, and mitigating potential threats to our organization's attack surface.

This role requires a deep understanding of cybersecurity principles, hands-on experience with ASM tools, and the ability to communicate complex security concepts to both technical and non-technical stakeholders.

Key Responsibilities:

  • Attack Surface Analysis and Assessment
  • Regularly assess the organization's attack surface, encompassing network, cloud, and application assets.
  • Employ ASM tools (e.g., RiskIQ, Expanse, CyCognito) and threat intelligence to identify internet-facing assets and evaluate their susceptibility to potential threats.
  • Conduct continuous asset discovery to identify shadow IT, misconfigured services, and third-party risks.
  • Document all exposed assets to maintain an accurate inventory of the digital footprint across the organization.
  • Risk Evaluation and Mitigation
  • Evaluate the security posture of identified assets and prioritize risks based on potential impact and likelihood of exploitation.
  • Collaborate with IT, DevOps, and Security Operations teams to address high-risk exposures through configuration changes, access controls, or network segmentation.
  • Offer recommendations for securing exposed assets, reducing the attack surface, and mitigating identified vulnerabilities.
  • Ensure asset owners are informed of ASM findings and provide actionable guidance for risk mitigation.
  • Monitoring and Threat Intelligence Integration
  • Continuously monitor the attack surface for changes and newly discovered assets.
  • Integrate threat intelligence to identify and assess the relevance of emerging threats to the organization's digital assets.
  • Stay current on new attack techniques, tools, and threat actor activities that could impact the organization's attack surface.
  • Establish alerting and response protocols for identified high-risk exposures.
  • Reporting and Communication
  • Develop and deliver clear, actionable reports on attack surface findings, risk assessments, and remediation progress.
  • Effectively communicate risks and recommendations to technical and non-technical stakeholders, including executive leadership.
  • Create metrics and dashboards to provide visibility into the organization's attack surface and ASM program effectiveness.
  • Security Program Development and Continuous Improvement
  • Assist in developing and enhancing the Attack Surface Management program, including establishing standards for asset discovery and risk management.
  • Develop processes and workflows to automate attack surface discovery, monitoring, and assessment.
  • Provide training and awareness sessions to teams on reducing the attack surface and mitigating risks.
  • Identify opportunities to enhance security policies and procedures based on ASM findings and emerging best practices.

Estimated Salary: $120,000 - $180,000 per year.

Location: Remote or on-site at Vallum Associates' headquarters.

Required Qualifications:

  • Education: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field. Equivalent experience may be considered.
  • Experience:
  • Minimum of [3-5] years of experience in cybersecurity, with a focus on Attack Surface Management, Threat Intelligence, Vulnerability Management, or related fields.
  • Hands-on experience with ASM tools (e.g., RiskIQ, Expanse, CyCognito) and asset discovery methodologies.
  • Familiarity with vulnerability management processes and tools, along with an understanding of network and cloud security principles.
  • Experience working in large-scale enterprise environments, including cloud (AWS, Azure, GCP) and hybrid infrastructures.
  • Certifications (preferred): CISSP, CISM, OSCP, CEH, CompTIA CySA+, or relevant security certifications.


  • London, Greater London, United Kingdom Vallum Associates Full time

    Job OverviewWe are seeking a highly skilled Attack Surface Management Specialist to join our team at Vallum Associates. As a key member of our cybersecurity department, you will play a crucial role in identifying and mitigating potential threats to our digital assets.With a strong background in Attack Surface Management, Threat Intelligence, and...


  • London, Greater London, United Kingdom Vallum Associates Full time

    Job Title: Attack Surface Management LeadVallum Associates is seeking an experienced Cybersecurity Threat Intelligence Specialist to lead efforts in identifying, monitoring, and reducing the organization's digital attack surface. The ideal candidate will have a strong understanding of cybersecurity principles and extensive experience with Attack Surface...


  • London, Greater London, United Kingdom Vallum Associates Full time

    At Vallum Associates, we are seeking a skilled Attack Surface Management Specialist to lead our efforts in identifying and reducing the organization's digital attack surface. This role requires a strong understanding of cybersecurity principles, extensive experience with Attack Surface Management (ASM) tools, and the ability to assess and communicate...


  • London, Greater London, United Kingdom Vallum Associates Full time

    At Vallum Associates, we are seeking a seasoned Attack Surface Management expert to lead our efforts in identifying, monitoring, and reducing the organization's digital attack surface. With a strong understanding of cybersecurity principles and extensive experience with ASM tools, you will assess the exposure of assets, evaluate potential vulnerabilities,...


  • London, Greater London, United Kingdom Vallum Associates Full time

    Vallum Associates is seeking a highly skilled Digital Attack Surface Security Specialist to lead our efforts in identifying, monitoring, and reducing the organization's digital attack surface. With a strong focus on cybersecurity principles and extensive experience with Attack Surface Management (ASM) tools, you will assess the exposure of assets, evaluate...


  • London, Greater London, United Kingdom Iceberg Full time

    We are an equal opportunities employer and welcome applications from all qualified candidates. If you are a motivated and experienced Senior External Attack Surface Management Analyst looking for a new challenge, please apply now.Job Description:As a Senior External Attack Surface Management Analyst, you will be responsible for maintaining and monitoring the...


  • London, Greater London, United Kingdom Iceberg Full time

    **Job Title:** Senior External Attack Surface Management Analyst**Location:** Preston or Frimley (Hybrid and flexible working options available)Iceberg is seeking a skilled Senior External Attack Surface Management Analyst to protect its critical assets by identifying and mitigating perimeter risks. The selected candidate will maintain and monitor the global...


  • London, Greater London, United Kingdom Vallum Associates Full time

    Vallum Associates is committed to delivering exceptional results for our clients, and we are seeking a talented Cybersecurity Risk Analyst to join our team. In this role, you will play a critical part in assessing the organization's digital attack surface, evaluating potential vulnerabilities, and implementing risk mitigation strategies.To be successful in...


  • London, Greater London, United Kingdom Worldpay Full time

    Insider Threat Prevention AnalystEstimated Salary: $100,000 - $160,000 per yearAs an Insider Threat Prevention Analyst at Worldpay, you will play a critical role in identifying and mitigating internal security risks posed by employees, contractors, and partners. Your primary focus will be on developing and implementing effective strategies to prevent insider...


  • London, Greater London, United Kingdom Vallum Associates Full time

    Job Summary:Vallum Associates is seeking an experienced Cybersecurity Threat Intelligence Specialist to lead our Attack Surface Management program. The ideal candidate will have a strong background in cybersecurity and experience with Attack Surface Management tools, as well as excellent communication and interpersonal skills.You will be responsible for...


  • London, Greater London, United Kingdom Vallum Associates Full time

    Vallum Associates seeks a seasoned Cybersecurity Risk Management Expert to bolster our defenses and ensure the integrity of our digital presence. In this pivotal role, you will leverage your expertise in Attack Surface Management to mitigate potential threats and protect our organization's assets.This position demands a profound understanding of...


  • London, Greater London, United Kingdom Iceberg Full time

    **Job Overview:** We are looking for a highly skilled Senior External Attack Surface Management Analyst to join our team at Iceberg. As a key member of our security team, you will play a vital role in protecting our organization's assets from external threats.The successful candidate will have extensive experience in external risk management, including...

  • IT Security Analyst

    3 weeks ago


    London, Greater London, United Kingdom Strativ Group Full time

    IT Security AnalystWe are seeking an experienced IT Security Analyst to join our team at Strativ Group. In this role, you will have the opportunity to work on a wide range of engagements across industries, analyzing and mitigating potential security risks.As an IT Security Analyst, your primary responsibility will be to identify and exploit vulnerabilities...


  • London, Greater London, United Kingdom Police Digital Services Full time

    We are seeking a highly skilled Cyber Threat Intelligence Analyst to join Police Digital Service. This mid-tier role is ideal for those with experience in cyber threat intelligence or associated fields.Key ResponsibilitiesDevelop awareness for the policing community of the cyber risks to critical services by continually assessing the threat landscape and...


  • London, Greater London, United Kingdom Vallum Associates Full time

    Key ResponsibilitiesAttack Surface Analysis and AssessmentConduct regular assessments of our digital assets, identifying potential vulnerabilities and exposure to threats.Utilize ASM tools and threat intelligence to evaluate the security posture of identified assets and prioritize risks based on potential impact and likelihood of exploitation.Develop and...


  • London, Greater London, United Kingdom Vallum Associates Full time

    About the RoleThe successful candidate will have a minimum of [3-5] years of experience in cybersecurity, with a focus on Attack Surface Management, Threat Intelligence, or related fields. You will be an expert in ASM tools (e.g., RiskIQ, Expanse, CyCognito) and asset discovery methodologies, with a solid understanding of network and cloud security...


  • London, Greater London, United Kingdom Capgemini Full time

    Are you looking for a challenging role as a Digital Threat Analyst at Capgemini?We are seeking an experienced Penetration Tester to join our team in Bristol, Birmingham, or London. As a digital threat analyst, you will be responsible for identifying vulnerabilities in clients' IT systems, applications, and networks through rigorous testing.This will involve...


  • London, Greater London, United Kingdom Nielseniq Full time

    Information Security Director RoleNIQ, the world's leading consumer intelligence company, is seeking an experienced Information Security Director to lead the development and implementation of our cybersecurity engineering solutions.We require a seasoned professional with expertise in managing diverse teams and driving business growth. The successful...


  • London, Greater London, United Kingdom McDonald's Full time

    **Job Overview:** Security Information AnalystWe are seeking a talented Security Information Analyst to join our team at McDonald's. As a key member of our SOC, you will be responsible for monitoring external data sources to stay informed about cyber defense threat conditions.**Annual Salary Range:** $80,000 - $105,000 per yearThe ideal candidate will...


  • London, Greater London, United Kingdom Vallum Associates Full time

    Job Description:Vallum Associates is a leading provider of cybersecurity solutions, and we are seeking a highly skilled Digital Asset Risk Reduction Expert to join our team. As a key member of our cybersecurity team, you will play a critical role in identifying, assessing, and mitigating risks associated with our digital assets.Your primary responsibility...