412,158open jobs
14,541companies
72,770added this week
Browse all
Salary
$15k – $37k per year (Estimated)
Location
In office (Hyderabad)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Ultraviolet Cyber is an enterprise cybersecurity company that provides unified, automated security operations and threat management solutions. The firm offers managed detection and response (MDR), threat intelligence, and security automation services designed to help organizations streamline their security operations centers (SOCs). By synthesizing telemetry across diverse IT environments, it enables enterprises to detect, investigate, and neutralize complex cyber threats in real time.

Job Title: Security Analyst, Attack Surface Management

Summary

The Attack Surface Management team owns what happens after a vulnerability is found. Findings arrive from red team pentests, adversary simulations, external bug bounty submissions, and scanning coverage. This role validates them, determines real impact, and drives them to closure with the engineering teams that own the affected assets. Critical findings route to Incident Response. Everything rated High and Medium is this team's responsibility until it is patched or a compensating control is in place and documented.

This is not a patch operations role. Separate teams apply fixes. This role decides what matters, why it matters, and holds the line until it is resolved.

Responsibilities

  • Triage and validate inbound Bugcrowd submissions: reproduce the reported issue, confirm or reject it, deduplicate against known findings, and determine payout-relevant severity.
  • Independently assess impact rather than accepting a submitter's or a scanner's rating. Factor in exploitability, asset exposure, data sensitivity, authentication requirements, and existing controls.
  • Track High and Medium findings from red team engagements and adversary simulations through remediation, including retest and closure verification.
  • Evaluate and document compensating controls where a fix is not immediately viable, and set expiry conditions rather than leaving exceptions open indefinitely.
  • Write remediation guidance that an application or platform engineer can act on without further translation.
  • Escalate Critical findings to Incident Response with the reproduction detail and blast radius assessment they need to act.
  • Partner with application owners and product teams on remediation timelines, and raise risk acceptance decisions to leadership when timelines slip.
  • Maintain visibility into externally exposed assets and flag newly surfaced attack surface for assessment.

Required Qualifications

  • Two or more years in application security, vulnerability management, penetration testing, or bug bounty work.
  • Working proficiency in web application and API penetration testing. You should be able to independently reproduce a submitted finding, escalate it if the submitter undersold it, and prove it is a false positive if it is one.
  • Practical knowledge of OWASP Top 10 and OWASP API Security Top 10, including what remediation actually looks like for each class of issue.
  • Familiarity with MITRE ATT&CK techniques and the ability to connect a finding to how an attacker would chain it.
  • Severity determination beyond a CVSS calculator. You can explain why a High-scoring finding on an isolated internal asset may matter less than a Medium on an internet-facing authentication flow.
  • Hands-on experience with Burp Suite and standard web and API testing tooling.
  • Clear written communication. Much of this role is convincing an engineering team that a finding is real and worth their sprint capacity.

Preferred Qualifications

  • Demonstrated bug bounty track record on Bugcrowd, HackerOne, or Intigriti.
  • Experience triaging submissions from the program side.
  • Cloud security exposure across AWS or Azure, particularly identity and storage misconfigurations.
  • Certifications such as BSCP, OSWA, OSCP, CPTS, or PNPT. A public bug bounty profile carries equal weight.

Scripting in Python for reproduction harnesses and finding automation.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
412,158 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
$28k – $69k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chennai
Python
PowerShell
AI/ML
Red Teaming
DevOps
Splunk
Terraform
Ansible
GCP
Helm
Azure DevOps
GitHub Actions
CloudFormation
Prometheus
Pulumi
GitLab CI
Azure
Jenkins
AWS
Docker
Kubernetes
Grafana
Service Mesh
GitHub
GitLab
Cybersecurity
Snyk
OWASP ZAP
Prisma Cloud
HashiCorp Vault
Checkmarx
OWASP Top 10
Zero Trust
Threat Modeling
Sysdig Secure
Cryptography
Vault
Apply
$114k – $282k per year (Estimated) • In office • Full-Time • 5+ years exp • Master's Degree • Tel Aviv
Python
AI/ML
LangChain
AI Agents
PyTorch
LLM
RAG
Hugging Face
Agentforce
Agentic Workflows
Cybersecurity
OWASP Top 10
Apply
$16k – $40k per year (Estimated) • Remote/Hybrid • 4+ years exp • Bachelor's Degree • Hyderabad
Python
PowerShell
AI/ML
AI Agents
DevOps
Splunk
GCP
Azure
AWS
Cybersecurity
Microsoft Sentinel
MITRE ATT&CK
IBM QRadar
Apply
$105k – $231k per year • Remote • Full-Time • 12+ years exp
AI/ML
Red Teaming
DevOps
Azure
AWS
Apply
In office • Full-Time • Riyadh
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
IBM QRadar
Apply
$100k – $110k per year • Remote • 4+ years exp
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Apply
$23k – $51k per year (Estimated) • In office • Full-Time • 8+ years exp • Hyderabad
Python
PowerShell
YARA
DevOps
Splunk
GCP
Azure
AWS
Vector
IAM
Cybersecurity
Wireshark
Crowdstrike
Volatility
Microsoft Sentinel
Autopsy
Ghidra
YARA
SentinelOne
Microsoft Defender
Cortex XDR
MITRE ATT&CK
IBM QRadar
FTK
EnCase
Apply
$101k – $197k per year (Estimated) • Remote/Hybrid • 8+ years exp • Bachelor's Degree • Washington
Python
SQL
AI/ML
Airflow
Prefect
DevOps
Terraform
GCP
GitHub Actions
CloudFormation
Azure
CI/CD
Jenkins
AWS
Self-Healing
GitHub
GitLab
Analytics
ETL/ELT
Apply
$160k – $210k per year • Remote/Hybrid • 12+ years exp • Bachelor's Degree
DevOps
Splunk
Cybersecurity
Qualys Cloud Platform
Zero Trust
Apply
$90k – $130k per year • In office • 4+ years exp • Herndon
Python
PowerShell
DevOps
Splunk
Ansible
Azure
AWS
Apply
Remote/Hybrid • 8+ years exp • Bachelor's Degree • Hyderabad
AI/ML
AI Agents
DevOps
AWS
Kubernetes
Amazon EKS
Cybersecurity
ISO 27001
SOC 2
CVSS
Apply
Remote/Hybrid • 5+ years exp • Hyderabad
Python
Go
JavaScript
TypeScript
C#
AI/ML
AI Agents
LLM
DevOps
Terraform
GCP
Helm
GitHub Actions
CloudFormation
Azure
CI/CD
Jenkins
AWS
Kubernetes
GitHub
IAM
Cybersecurity
Trivy
Checkmarx
Checkov
OWASP Top 10
Threat Modeling
Veracode
Apply
Remote • 8+ years exp • Bachelor's Degree • Hyderabad
Python
Java
PowerShell
AI/ML
MLFlow
AI Agents
EU AI Act
NIST AI RMF
DevOps
GCP
Azure
AWS
Cybersecurity
SOC 2
GDPR
Threat Modeling
Apply
Remote • 8+ years exp • Hyderabad
JavaScript
TypeScript
AI/ML
AI Agents
Frontend
Angular
Angular Material
Mobile
Material Design
Design
Figma
Apply
Remote/Hybrid • 8+ years exp • Bachelor's Degree • Hyderabad
JavaScript
TypeScript
C#
C#
ASP.NET Core
AI/ML
AI Agents
Frontend
Webpack
RxJS
Angular
esbuild
NgRx
DevOps
CI/CD
QA
Cypress
Playwright
Jest
Apply
See all jobs
This is one of many
412,158 more open roles from verified company boards, updated every day.