Senior Attack Surface Management Analyst

Manager

Senior Attack Surface Management Analyst

Apply Now

- $0.00

  • Date posted
    September 11, 2026
  • Expiration date
    December 11, 2026
  • Application ends
    December 11, 2026

As a Senior ASM Analyst, you will be a critical technical partner to our ASM Team Lead and broader security and engineering teams. You will navigate complex technical challenges, ensuring our risk recommendations are concise, data-driven, and focused on automation. The ideal candidate has a deep offensive security mindset, excels at dissecting complex cloud infrastructures, and is passionate about automating asset discovery. This role is fully remote and reports to the Head of Vulnerability Management.

Key Responsibilities:

Continuous Discovery and Programmatic Asset Attribution

  • Execute and scale continuous discovery processes to map and maintain a real-time, comprehensive inventory of all external-facing and internal digital assets, including domains, IPs, APIs, complex cloud resources (AWS, Azure, GCP), SaaS applications, and Shadow IT.
  • Develop and implement robust asset attribution models, writing scripts to query asset databases and integrate disparate inventories (CMDB, cloud accounts) into a unified, reliable “single source of truth”.

Exposure Analysis, Threat Intelligence, and Prioritization:

  • Proactively identify security exposures like misconfigured cloud storage, exposed administrative portals, outdated systems, and vulnerabilities (including emerging zero-days) across our entire attack surface.
  • Contribute to intelligence-led prioritization efforts by combining vulnerability severity (beyond CVSS), real-world exploit availability (drawing from CISA KEV and other threat intel sources), business criticality, data sensitivity, mapped attack paths, and active threat intelligence to determine “what matters most” and “what to fix first” while uncovering root causes.

Security Validation and Remediation Orchestration:

  • Orchestrate Breach and Attack Simulation (BAS) and Autonomous Pentesting exercises, safely simulating real-world attacks (mapped to MITRE ATT&CK) to validate the efficacy of existing security controls (SIEM, EDR, Firewalls) and prove vulnerability exploitability.
  • Collaborate with Engineering, DevOps, and IT teams to define remediation SLAs, build automated ticketing workflows, and verify fixes through continuous monitoring and programmatic re-scanning.
  • Support continuous Purple Teaming initiatives, partnering closely with offensive (Red Team) and defensive (SOC/Blue Team) functions to translate attack surface findings into resilient detection rules.
  • Are you interested in this position?

     

    Apply by clicking on the “Apply Now” button below!

     

    #AlbionarcJobs#FintechJobs

    #AsiaJobs#MiddleEastCareers

    #TechTalent#FintechRecruitment

    #FinanceOpportunities#

Apply Now

- $0.00

Select your currency