
Attack Surface Reduction Analyst
2 weeks ago
WHAT YOU'LL DO
We are seeking a skilled and experienced Attack Surface Reduction Analyst with a strong background in penetration testing to join our cybersecurity team. The successful candidate will be responsible for identifying potential security risks and vulnerabilities in our organization's systems, applications, and networks, performing penetration testing, and facilitating and managing third-party penetration testing engagements.
WHO YOU'LL WORK WITH
Attack Surface Reduction team helps and contribute to improve the security posture of H&M by operating within an Agile model. We play a crucial role in proactively identifying and help in mitigating potential security risks and vulnerabilities across H&M's systems, applications, and networks, with the aim of preventing unauthorized access, data breaches, and other security incidents.
Key Responsibilities:
- Conduct comprehensive vulnerability assessments (VA) and penetration tests (PT) on H&M's systems, networks, and applications.
- Utilize industry-standard tools and methodologies to identify potential vulnerabilities and weaknesses in our attack surface.
- Collaborate with cross-functional teams to prioritize and remediate identified vulnerabilities in a timely manner.
- Experience in designing, implementing, and managing vulnerability management processes and workflows.
- Facilitate and manage penetration testing engagements with third-party vendors.
- Collaborate with other members of the cybersecurity team to develop and implement strategies to reduce our attack surface.
- Develop and maintain security policies and procedures for our organization's systems, applications, and networks.
- Monitor our organization's systems, applications, and networks for unauthorized access, suspicious activity, and other security threats.
- Stay up to date with the latest trends and developments in the field of cybersecurity, specifically related to attack surface reduction techniques.
WHO YOU ARE
We are looking for people with…
- Bachelor's degree in computer science, information security, or a related field.
- 3-5 years of experience in vulnerability scanning, vulnerability management, and penetration testing.
- Solid knowledge of common vulnerabilities and exposures (CVEs), common attack vectors, and security best practices.
- Strong knowledge of security assessment tools, vulnerability scanning, and penetration testing.
- Proficient in using industry-standard vulnerability assessment and penetration testing tools (e.g., Kali Distro, Qualys, Burp Suite, etc.).
- Familiarity with industry frameworks and standards, such as NIST, OWASP, and CIS.
- Effective communication skills, with the ability to clearly convey technical concepts to both technical and non-technical stakeholders.
- Excellent analytical, problem-solving, and communication skills.
- Relevant certifications, such as SANS, OSCP, OSEP, CompTIA Security+ or CREST are a plus.
WHY YOU'LL LOVE WORKING HERE
At H&M, we are proud to be a vibrant and welcoming company. We offer our employees attractive benefits with extensive development opportunities around the globe.
We offer all our employees at H&M attractive benefits with extensive development opportunities around the globe. All our employees receive a staff discount card, usable on all our H&M brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET, Afound. In addition to our staff discount, all our employees are included in our H&M Incentive Program – HIP. You can read more about our H&M Incentive Program here.
In addition to our global benefits, all our local markets offer different competitive perks and benefits. Please note that they may differ between employment types and countries.
JOIN US
Our uniqueness comes from a combination of many things – our inclusive and collaborative culture, our strong values, and opportunities for growth. But most of all, it's our people who make us who we are.
Take the next step in your career together with us. The journey starts here.
*We are committed to a recruitment process that is fair, equitable, and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
ADDITIONAL INFORMATION
This is a full-time position, starting in October 2025.
Apply by sending in your CV in English as soon as possible, but no later than the 30th of September 2025. Due to data policies, we only accept applications through the SmartRecruiters or career page
-
Attack Surface Reduction Analyst
7 days ago
Bengaluru, Karnataka, India H&M Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob DescriptionWHAT YOU'LL DOWe are seeking a skilled and experiencedAttack Surface Reduction Analystwith a strong background in penetration testing to join our cybersecurity team. The successful candidate will be responsible for identifying potential security risks and vulnerabilities in our organization's systems, applications, and networks, performing...
-
Attack Surface Reduction Senior Analyst
2 weeks ago
Bengaluru, Karnataka, India Aqilea (formerly Soltia) Full time ₹ 15,00,000 - ₹ 25,00,000 per yearCompany Description We are a consulting company with a bunch of technology-interested and happy people We love technology, we love design and we love quality. Our diversity makes us unique and creates an inclusive and welcoming workplace where each individual is highly valued. With us, each individual is her/himself and respects others for who they are and...
-
Sr Red Team Security Analyst
2 weeks ago
Bengaluru, Karnataka, India FireCompass Technologies Private Limited. Full time ₹ 18,00,000 - ₹ 26,00,000 per yearPosition: Sr Security Analyst At FireCompass, we are building a team that wants to make a difference globally: team players, thinkers, hackers, builders, and hustlers who challenge the status quo and who want to change the world. We believe in creating something that is challenging and exciting and that will have a tremendous impact on our customers and the...
-
Senior Information Security Consultant
7 days ago
Bengaluru, Karnataka, India RedHunt Labs Full time ₹ 15,00,000 - ₹ 25,00,000 per yearCompany DescriptionRedHunt Labs is a cybersecurity company focused on Attack Surface Management (ASM) and Penetration Testing. We help mid to large enterprises across the UK, US, India, and SE Asia discover unknown assets, monitor exposure, and validate risk. Our CTEM platform unifies ASM with vendor and subsidiary risk, Shadow SaaS discovery, risk rating,...
-
Principal Analyst
1 week ago
Bengaluru, Karnataka, India Optiv Full time ₹ 12,00,000 - ₹ 36,00,000 per yearThe Principal Analyst will lead advanced threat detection and analysis efforts by leveraging enterprise-scale data sources, audit logs, and monitoring tools. This role involves deep-dive investigations into suspicious activity, identifying hidden threats, and proactively hunting for adversaries across customer environments. The Principal Analyst will work...
-
Product Security Analyst
5 days ago
Bengaluru, Karnataka, India GE Healthcare Private Limited Full time ₹ 20,00,000 - ₹ 25,00,000 per yearSr Product Security Analyst Job Description SummaryWe are looking for an Sr Product Security Analyst, with a focus on Penetration testing and Python coding. In this role you will work in a team to identify, risk rate, communicate and track product vulnerabilities and be a part of the Cyber Security Lab team. GE Healthcare is a leading global...
-
Principal Analyst
2 weeks ago
Bengaluru, Karnataka, India Optiv Full time US$ 90,000 - US$ 1,20,000 per yearThe Principal Analyst will provide deep-level analysis for client investigations utilizing customer-provided data sources, audit, and monitoring tools at both the government and enterprise levels. The Principal Analyst will work closely with our Technology Engineers, Architects, and Threat Analysts to service customers.How you'll make an impactOperate...
-
Product Manager
4 weeks ago
Bengaluru, Karnataka, India SYD Full timeThe client's Attack Surface Monitoring (ASM) productis used by enterprises globally to identify, monitor, and secure their external attack surface. It enables organisations to discover shadow assets, misconfigurations, leaked credentials, and other exposuresbefore adversaries do.The Client is now scaling the product further and are looking for a Product...
-
Intern - Cyber Security Analyst
1 week ago
Bengaluru, Karnataka, India CloudSEK Full time ₹ 4,50,000 - ₹ 12,00,000 per yearWHO ARE WE?We are a bunch of super enthusiastic, passionate, and highly driven people, working to achieve a common goal We believe that work and the workplace should be joyful and always buzzing with energyCloudSEK, one of India's most trusted Cyber security product companies, is on a mission to build the world's fastest and most reliable AI technology that...
-
Sr Product Security Analyst
3 days ago
Bengaluru, Karnataka, India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryWe are looking for an Sr Product Security Analyst, with a focus on Penetration testing and Python coding. In this role you will work in a team to identify, risk rate, communicate and track product vulnerabilities and be a part of the Cyber Security Lab team. GE Healthcare is a leading global medical technology and digital solutions...