HHiring Reality
← Uvcyber

Security Analyst, Attack Surface Management

Uvcyber
Location
Hyderabad
Posted
17 days ago
Department
Dedicated Defense
What they actually want (must-haves)
  • Two or more years in application security, vulnerability management, penetration testing, or bug bounty work.
  • Working proficiency in web application and API penetration testing.
  • Practical knowledge of OWASP Top 10 and OWASP API Security Top 10.
  • Familiarity with MITRE ATT&CK techniques.
  • Severity determination beyond a CVSS calculator.
  • Hands-on experience with Burp Suite and standard web and API testing tooling.
Nice to have
  • Demonstrated bug bounty track record on Bugcrowd, HackerOne, or Intigriti.
  • Experience triaging submissions from the program side.
  • Cloud security exposure across AWS or Azure.
  • Certifications such as BSCP, OSWA, OSCP, CPTS, or PNPT.
  • Scripting in Python for reproduction harnesses and finding automation.
What the job really is

The Security Analyst in Attack Surface Management will focus on validating vulnerabilities identified through various sources, including red team tests and bug bounty submissions. The role involves assessing the impact of these vulnerabilities, tracking their remediation, and collaborating with engineering teams to ensure timely resolution. Additionally, the analyst will document findings and provide clear remediation guidance while maintaining visibility into the organization's attack surface.

Things to weigh
  • This role is not focused on applying patches, which may limit hands-on technical remediation experience.
  • The position requires strong communication skills to convince engineering teams of the validity and importance of findings.
  • No specific benefits or compensation details are provided in the posting.
Job score2.6/5
Benefits1/5
Freshness4/5
Career value4/5
Role clarity4/5
Pay transparency0/5

Applying to Uvcyber?

See how your résumé matches this role — and tailor it from what actually gets interviews.