Attack Surface Management Engineer

3 weeks ago


Hyderabad, India Experian Full time
Job Description

DescriptionThe Attack Surface Management engineer is responsible for activities related to Attack Surface Management, with the goal to ensure comprehensive visibility of Experian’s attack surface and vulnerabilities.Reporting RelationshipReports to the Director Attack Surface MgmtFunctionsFollows Attack Surface Mgmt processes to continuously monitor and improve visibility of the attack surface in order to detect anomalies faster and reduce incidences of cyber-attacksPerform verification/validation testing for vulnerabilities in external-facing web sites, web applications, and services; demonstrate exploitation steps and verify remediation/fixesGenerate comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniquesEngage with business stakeholders to ensure they fully understand their Attack Surface, and helps them identify prioritization of vulnerabilitiesDevelops vulnerability KPIs/metrics to demonstrate coverage and remediation effectivenessExecute daily operations of the Attack Surface Mgmt program, including the interpretation of scanning resultsAsist in the identification of internal and external risks based on scanning resultsAssist in the attribution of findings to appropriate business ownerIdentify improvements to scan coverageCoordinate with IT and geographically dispersed business units vulnerability remediation and mitigation strategiesAssist in the documentation and standardization of process and procedures related to Attack Surface MgmtAggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.Responsibilities/RequirementsFamiliarity with common web vulnerabilities including: XSS, XXE, SQL Injection, Deserialization Attacks, Path Traversal Attacks, Remote Execution Flaws, and Authentication FlawsUnderstanding of common web application frameworks and web-based APIsExperience with one or more scripting languages such as Bash, Python, Perl, PowerShell, etc.In-depth knowledge of architecture, engineering, and operations of one or more vulnerability management tools, such as Wiz, Qualys, Rapid7 and ServiceNow.Solid understanding of the application of the following frameworks and how they are applied to identifying and rating risk: OWASP, SANS, NIST, CIS, and MITRE ATT&CK.Ability to provide creative solutions to complex problemsAbility to clearly communicate risk of vulnerabilities to all levels within an organization.Knowledge of major cloud platforms (AWS, Azure, or GCP).Knowledge of systems hardening and other risk mitigation factors on multiple technologies and operating systems (Window, Linux, Mac, routers, switches, Kubernetes).Certification that could be helpful but not required: CISSP, Security+, CEH, GIAC certifications.Ability to manage, organize, analyze, and present substantial amounts of dataExperience selecting and deploying productPosition RequirementsFormal Education & CertificationFour-year college diploma or university degree in computer science or computer engineering, and/or 3 years equivalent work experience.

Qualifications

Position RequirementsFormal Education & CertificationFour-year college diploma or university degree in computer science or computer engineering, and/or equivalent work experience.Knowledge & Experienceexperience in information security vulnerability management roleExperience with large scale and complex environmentsA broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategiesApplied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management and security and controlsExcellent interpersonal skills and strong verbal and written communicationAn ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood and actionable mannerStrong organizational skills with proven ability to manage multiple high visibility issues simultaneouslyProactive attitude, seeking for improvement opportunities which can positively impact the security posture and the businessPersonal AttributesExcellent oral and interpersonal communication skillsOutstanding writing and documentation skillsAble to communicate ideas in both technical and user-friendly languageHighly self-motivated and directed, with keen attention to detailAble to prioritize and execute tasks in a high-pressure environmentExperience working in a team-oriented, collaborative environmentWilling to travel globally as required

Additional Information

Experian Careers - Creating a better tomorrow togetherFind out what its like to work for Experian by clicking here

  • Hyderabad, India Experian Full time

    Job Description Description The Attack Surface Management engineer is responsible for activities related to Attack Surface Management, with the goal to ensure comprehensive visibility of Experian’s attack surface and vulnerabilities. Reporting Relationship Reports to the Director Attack Surface Mgmt Functions Follows Attack Surface Mgmt...


  • hyderabad, India Experian Full time

    Job Description Description The Attack Surface Management engineer is responsible for activities related to Attack Surface Management, with the goal to ensure comprehensive visibility of Experian’s attack surface and vulnerabilities. Reporting Relationship Reports to the Director Attack Surface Mgmt Functions Follows Attack Surface...

  • Engineer I

    2 days ago


    Hyderabad, India TechnipFMC Full time

    Engineer I (Surface)Location:Hyderabad, INEmployment type: Employee Place of work: Office Offshore/Onshore: OnshoreTechnipFMC is committed to driving real change in the energy industry. Our ambition is to build a sustainable future through relentless innovation and global collaboration – and we want you to be part of it. You’ll be joining a culture that...

  • Engineer I

    4 days ago


    Hyderabad, India TechnipFMC Full time

    Engineer I (Surface) Location: Hyderabad, IN Employment type: Employee Place of work: Office Offshore/Onshore: Onshore TechnipFMC is committed to driving real change in the energy industry. Our ambition is to build a sustainable future through relentless innovation and global collaboration – and we want you to be part of it. You’ll be joining a...

  • Engineer I

    3 days ago


    hyderabad, India TechnipFMC Full time

    Engineer I (Surface) Location: Hyderabad, IN Employment type: Employee Place of work: Office Offshore/Onshore: Onshore TechnipFMC is committed to driving real change in the energy industry. Our ambition is to build a sustainable future through relentless innovation and global collaboration – and we want you to be part of it. You’ll be joining a...

  • Data Science Engineer

    3 weeks ago


    Hyderabad, India Microsoft Full time

    OverviewOverview:Are you a data enthusiast with a knack for engineering and analytics? Do you find joy in influencing product development through each stage of its lifecycle using data-driven insights? If you have a penchant for designing, measuring, understanding, and visualizing real-world user data to derive insights that drive business metrics, we are...

  • Lead Engineer

    2 days ago


    Hyderabad, India Orica Full time

    About OricaAt Orica, it’s the power of our people that leads change and shapes our futures. Every day, all around the world, our people help mobilise vital resources essential to progress. Established in 1874, we have grown to become the world leader in mining and civil blasting with a diverse of team of more than 13,000 across the world.It’s an exciting...

  • Data Science Engineer

    3 weeks ago


    Hyderabad, India Microsoft Full time

    Overview Overview: Are you a data enthusiast with a knack for engineering and analytics? Do you find joy in influencing product development through each stage of its lifecycle using data-driven insights? If you have a penchant for designing, measuring, understanding, and visualizing real-world user data to derive insights that drive business...


  • Hyderabad, India Microsoft Full time

    Overview Are you passionate about building cool devices and technologies? The Surface Team focuses on building devices that fully express the Windows vision along with innovation in the Sensors space. A fundamental part of our strategy is having desirable and powerful devices that enable the experiences people want and elicit their excitement. Creating...


  • Hyderabad, India Microsoft Full time

    Overview:Are you a data enthusiast with a knack for engineering and analytics? Do you find joy in influencing product development through each stage of its lifecycle using data-driven insights? If you have a penchant for designing, measuring, understanding, and visualizing real-world user data to derive insights that drive business metrics, we are eager to...

  • Data Science Engineer

    3 weeks ago


    hyderabad, India Microsoft Full time

    Overview Overview: Are you a data enthusiast with a knack for engineering and analytics? Do you find joy in influencing product development through each stage of its lifecycle using data-driven insights? If you have a penchant for designing, measuring, understanding, and visualizing real-world user data to derive insights that drive business...


  • Hyderabad, India Nubes Opus Full time

    Job Title - Google Chronicle SIEM Engineer Location - Hyderabad, Telangana **Job Description**: NUBESOPUS LLC is hiring a Google Chronicle SIEM Engineer Job type : Full time role and remote Joining : Immediately or one month **Requirements**: - Bachelor of engineering or Science in computers, information systems, information security, Math, decision...


  • Hyderabad, India Microsoft Full time

    Overview : Are you a data enthusiast with a knack for engineering and analytics? Do you find joy in influencing product development through each stage of its lifecycle using data-driven insights? If you have a penchant for designing, measuring, understanding, and visualizing real-world user data to derive insights that drive business metrics, we are...


  • hyderabad, India Microsoft Full time

    Overview : Are you a data enthusiast with a knack for engineering and analytics? Do you find joy in influencing product development through each stage of its lifecycle using data-driven insights? If you have a penchant for designing, measuring, understanding, and visualizing real-world user data to derive insights that drive business metrics, we are...


  • Hyderabad, India ADCI HYD 13 SEZ Full time

    Analytical and communication skills, and have a passion for using data to drive business decisions. You are analytical and creative, and you don’t quit until you solve the problem. You attack complex business questions with data and curiosity, diving below the surface to identify the root cause and the “so what” rather than just superficial trends. You...

  • Lead Engineer

    4 weeks ago


    Hyderabad, India Orica Full time

    About Orica At Orica, it’s the power of our people that leads change and shapes our futures. Every day, all around the world, our people help mobilise vital resources essential to progress. Established in 1874, we have grown to become the world leader in mining and civil blasting with a diverse of team of more than 13,000 across the world.  ...


  • Hyderabad, India Genpact Full time

    Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients. Powered by our purpose – the relentless pursuit of a world that works better for people –...


  • hyderabad, India Genpact Full time

    Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients. Powered by our purpose – the relentless pursuit of a world that works better for people –...


  • Hyderabad, India Microsoft Full time

    Overview About Microsoft shopping Microsoft Shopping enables customers to shop with confidence, convenience and with savings, anywhere. Providing solutions that delight online shoppers and also enable retailers to realize maximum revenues is a significant opportunity for Bing, Azure and Microsoft overall. This global team has built best in class...

  • Senior Engineer

    2 days ago


    Hyderabad, India TechnipFMC Full time

    Senior Engineer - Product ImprovementLocation:Hyderabad, INEmployment type: Employee Place of work: Office Offshore/Onshore: OnshoreTechnipFMC is committed to driving real change in the energy industry. Our ambition is to build a sustainable future through relentless innovation and global collaboration – and we want you to be part of it. You’ll be...