Attack Surface Management Analyst
Attack Surface Management (ASM) Analysts deliver our managed Polus Attack Surface Management service to our clients on a continuous basis to help them reduce risks to their internet-facing assets. This involves validating vulnerabilities, performing manual discovery of their attack surface and helping our clients interpret prioritised findings. Our aim is to become trusted advisors to our clients.
You will help our clients to build cyber resilience, enhance their understanding of the threat landscape and become better prepared to face dynamic and evolving security risks. This will involve being on the front foot of new and emerging threats, and ensuring our clients receive quick feedback as to whether they may be affected and actions they can take.
- Main Duties and Responsibilities
The main responsibilities of this role will include working closely with the ASM practice lead and Customer Success Managers to ensure that a high value service is delivered to clients. This will include:
- Technical testing; vulnerability scanning, attack surface discovery, manual exploit validation, light-touch pentesting and Open-Source Intelligence (OSINT) gathering
- Client Engagement; translating client challenges into solutions that fit S-RM’s ASM service offerings and value proposition, understanding and supporting the proposal process and ensuring delivery timelines are understood inline with project resourcing requirements
- Reporting; Delivering findings in a range of formats, including via the Polus ASM platform, via written report and also through Quarterly Service Reviews
You will also be required to keep abreast of threat intelligence developments, and work closely with S-RM’s Threat Intelligence and Incident Response teams to integrate key data points into our service.
Support to other teams will be required where ASM is used as a value-add to assessment-based engagements in our Risk & Resilience practice, and also where ASM is used to support incident investigation with our Incident Response practice.
You will be required to work closely with the other managed service teams (Managed Detection and Response and Cyber Threat Intelligence) to ensure that managed service delivery is unified across all three offerings. Through this, you will also be given the opportunity to support and shape the development of the service, by working with the ASM practice lead, managed service teams and technical development teams to identify opportunities for innovation and improvement.
- Who are we looking for?
We are looking for individuals keen to keep their finger on the pulse when it comes to the latest threats and vulnerabilities, with good client-facing skills needed to provide long term support to the organisations we work with. We’re not looking for prior Attack Surface Management experience (although bonus points if you do), but we’re looking for individuals who may fall into the following profiles with regards to experience:
- Pentesters with a minimum of 1 year experience (including carrying out external pentests) looking to specialise in threat led approaches
- Cyber Security Analysts with experience running vulnerability scans and triaging issues, looking to move into managed service delivery with an offensive security focus
- Threat Intelligence Analysts with good knowledge of offensive security concepts and familiarity with running security tooling, keen to develop their technical skills
Candidates must have permission to work in the UK by the start of their employment
OUR BENEFITS
We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, this includes but is not exhaustive of:
Our benefits
We offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, this includes but is not exhaustive of:
- 25 days holiday per year in addition to bank holidays (+1 day for every year of service up to a maximum of 30 days);
- Hybrid working and flexible working hours;
- Matching pension contribution up to 7% and financial education;
- Fertility treatment leave – 5 days of leave per cycle of treatment per year;
- Maternity leave – 26 weeks of full pay followed by 13 weeks of half pay;
- Paternity leave – 6 weeks of full pay.
- Private dental and medical insurance (taxable benefit) for you and your family;
- Virtual GP for you and your family members that live in the same household;
- Various gym discounts for you and your partner;
The role will be based in our London office. However, we have flexible working arrangements available.
THE APPLICATION PROCESS
We want to get to know you, and for you to get to know us, to see if we’d be a good fit. We are responsive and respectful of people’s time throughout our hiring process.
A typical application process includes:
- Initial screening of your application by our recruiting team.
- Interview to assess your baseline technical skills.
- An interview to discuss your previous experience, broader competencies, and suitability for the role.
To apply for this role, please send a cover letter and CV to: Job Application for Attack Surface Management Analyst at S-RM
Create a Job Alert
Interested in building your career at S-RM? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field