Attack Surface Reduction Analyst

3 weeks ago


Bengaluru, India H&M Full time
Job Description

Attack Surface Reduction team contributes to improve the security posture of H&M by operating within an Agile model. We play a crucial role in proactively identifying and help in mitigating potential security risks and vulnerabilities across H&M's systems, applications, and networks, with the aim of preventing unauthorized access, data breaches, and other security incidents.  

We are seeking a skilled and experienced Attack Surface Reduction Analyst with a strong background in penetration testing to join our cybersecurity team. The successful candidate will be responsible for identifying potential security risks and vulnerabilities in our organization's systems, applications, and networks, performing penetration testing, and facilitating and managing third-party penetration testing engagements. 

  1. Conduct comprehensive vulnerability assessments(VA) and penetration tests (PT) on H&M's systems, networks, and applications. 

  2. Utilize industry-standard tools and methodologies to identify potential vulnerabilities and weaknesses in our attack surface. 

  3. Collaborate with cross-functional teams to prioritize and remediate identified vulnerabilities in a timely manner. 

  4. Experience in designing, implementing, and managing vulnerability management processes and workflows. 

  5. Facilitate and manage penetration testing engagements with third-party vendors. 

  6. Collaborate with other members of the cybersecurity team to develop and implement strategies to reduce our attack surface. 

  7. Develop and maintain security policies and procedures for our organization's systems, applications, and networks. 

  8. Monitor our organization's systems, applications, and networks for unauthorized access, suspicious activity, and other security threats. 

  9. Stay up-to-date with the latest trends and developments in the field of cybersecurity, specifically related to attack surface reduction techniques. 


Qualifications

  1. Bachelor's degree in computer science, information security, or a related field. 

  2. 8-10 years of experience in vulnerability scanning, vulnerability management, and penetration testing. 

  3. Solid knowledge of common vulnerabilities and exposures (CVEs), common attack vectors, and security best practices. 

  4. Strong knowledge of security assessment tools, vulnerability scanning, and penetration testing. 

  5. Proficient in using industry-standard vulnerability assessment and penetration testing tools (e.g., Kali Distro, Qualys, Burp Suite, etc.). 

  6. Familiarity with industry frameworks and standards, such as NIST, OWASP, and CIS. 

  7. Effective communication skills, with the ability to clearly convey technical concepts to both technical and non-technical stakeholders. 

  8. Excellent analytical, problem-solving, and communication skills. 

  9. Relevant certifications, such as SANS, OSCP, OSEP, CompTIA Security+ or CREST are a plus. 



Additional Information

Inclusion & Diversity 
At H&M Group, we’re determined to create and maintain inclusive, diverse, and equitable workplaces throughout our organization. Our teams should consist of a variety of people who share and combine their knowledge, experience, and ideas. Having a diverse workforce leads to a positive impact on how we address challenges, on what we perceive possible, and on how we choose to relate to our colleagues and customers all over the world. Hence all diversity dimensions are taken into consideration in our recruitment process.

We strive to have a fair and equal process and therefore kindly ask you not to attach a cover letter to your application as it often contains information that can easily trigger unintentional biases.

Benefits
We offer all our employees at H&M Group attractive benefits with extensive development opportunities around the globe. All our employees receive a staff discount card, usable on all our H&M Group brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET, Afound. In addition to our staff discount, all our employees are included in our H&M Incentive Program – HIP. You can read more about our H&M Incentive Program here. 

In addition to our global benefits, all our local markets offer different competitive perks and benefits. Please note that they may differ between employment types and countries. 



  • Bengaluru, India CYFIRMA Full time

    CYFIRMAis the fastest-growing cybersecurity start-up, delivering a near real-time view of external cyber threats and risks. We are an external threat landscape management platform company. We combine cyber intelligence with attack surface discovery and digital risk protection to deliver an early warning, personalized, contextual, outside-in, and...


  • Greater Bengaluru Area, India CYFIRMA Full time

    CYFIRMA  is the fastest-growing cybersecurity start-up, delivering a near real-time view of external cyber threats and risks. We are an external threat landscape management platform company. We combine cyber intelligence with attack surface discovery and digital risk protection to deliver an early warning, personalized, contextual, outside-in, and...


  • Greater Bengaluru Area, India CYFIRMA Full time

    CYFIRMA is the fastest-growing cybersecurity start-up, delivering a near real-time view of external cyber threats and risks. We are an external threat landscape management platform company. We combine cyber intelligence with attack surface discovery and digital risk protection to deliver an early warning, personalized, contextual, outside-in, and...


  • Bengaluru, India Barracuda Full time

    Job ID: 25-275Come Join Our Passionate Team! At Barracuda, we make the world a safer place. We believe every business deserves access to cloud-enabled, enterprise-grade security solutions that are easy to buy, deploy, and use. We protect email, networks, data and applications with innovative solutions that grow and adapt with our customers’ journey. More...


  • Bengaluru, India Insight Global Full time

    Shifts:Wednesday to Sunday or Saturday to Wednesday:7 AM – 3 PM UK time(11:30 AM – 7:30 PM IST) converts to2 AM – 10 AM EST .Friday to Monday:6 AM – 4 PM UK time(10:30 AM – 8:30 PM IST) converts to1 AM – 11 AM EST .Must Haves:Requires 7+ Years of experience. At least 3-4 years SOC.Experience with Microsoft Sentinel or Crowd strike EDR/XDR...

  • Cyber Security Analyst

    3 months ago


    Bengaluru, India Wipro Full time

    Role Purpose The purpose of this role is to analyse, identify, rectify & recommend specific improvement measures that help in the security posture of the organization by protecting the sensitive information Do Ensuring customer centricity by providing apt cybersecurity Monitoring and safeguarding the log sources and security access Planning for disaster...


  • Bengaluru, India Insight Global Full time

    Insight Global is looking for a Senior SOC Analyst for one of our major retail apparel clients based out of North America. They will be joining a SOC team to support their 24X7 operations out of their India Tech Hub in Bengaluru. This would be a long termcontract role with potential for full time conversionsitting3 days on site in their Bengaluru office.The...

  • Senior SOC Analyst

    3 months ago


    Bengaluru, India AXA Group Full time

    Senior SOC Analyst (Level 3) Bangalore/Gurgaon, India AXA XL has an exciting opportunity for an experienced L3 Senior SOC analyst to join the Security Operations team, supporting security incident investigations across the organisation’s global infrastructure and responding to escalations from the Level 1 and 2 SOC teams. The successful candidate will...

  • SOC L3

    4 months ago


    Bengaluru, Karnataka, India True Talents Consulting Pvt Ltd Full time

    **Want to be a part of our team?** Provides technical support to field engineers, technicians, and product support personnel who are diagnosing, troubleshooting, repairing, and debugging complex electro/mechanical equipment, computer systems, complex software, or networked and/or wireless systems. Responds to situations where first-line product support has...

  • Ethical Hacker

    4 months ago


    Bengaluru, India ExamRoom.AI Full time

    **Reports To: Penetration Engineer** **Position **Overview**: ExamRoom.AI is seeking a highly skilled and motivated Ethical Hacker to join our team. As an Ethical Hacker, you will play a crucial role in identifying vulnerabilities, assessing risks, and implementing robust security measures to protect our organization's digital assets. You will be...


  • Bengaluru, India LTIMindtree Full time

    Skill: Defender EDR, SCCM Experience: 12-16 Years Shift Timing: Second Shift Location: Mumbai / Pune / Chennai / Hyderabad / Bangalore / Kolkata / Delhi / Coimbatore Job Description: Drive implementation if required innovation and continuous improvement for Healthineers security for endpoints Provide technical leadership as we design and deploy secure...


  • Bengaluru, India LTIMindtree Full time

    Skill: Defender EDR, SCCMExperience: 12-16 YearsShift Timing: Second ShiftLocation: Mumbai / Pune / Chennai / Hyderabad / Bangalore / Kolkata / Delhi / Coimbatore Job Description:Drive implementation if required innovation and continuous improvement for Healthineers security for endpointsProvide technical leadership as we design and deploy secure...


  • Bengaluru, India LTIMindtree Full time

    Skill: Defender EDR, SCCMExperience: 12-16 YearsShift Timing: Second ShiftLocation: Mumbai / Pune / Chennai / Hyderabad / Bangalore / Kolkata / Delhi / Coimbatore Job Description:Drive implementation if required innovation and continuous improvement for Healthineers security for endpointsProvide technical leadership as we design and deploy secure...


  • Bengaluru, India Insight Global Full time

    Insight Global is looking for a Senior SOC Analyst for one of our major retail apparel clients based out of North America. They will be joining a SOC team to support their 24X7 operations out of their India Tech Hub in Bengaluru. This would be a long term contract role with potential for full time conversion sitting 3 days on site in their Bengaluru office....


  • Bengaluru, India Insight Global Full time

    Insight Global is looking for a Senior SOC Analyst for one of our major retail apparel clients based out of North America. They will be joining a SOC team to support their 24X7 operations out of their India Tech Hub in Bengaluru. This would be a long term contract role with potential for full time conversion sitting 3 days on site in their Bengaluru office....


  • Bengaluru, India Insight Global Full time

    Insight Global is looking for a Senior SOC Analyst for one of our major retail apparel clients based out of North America. They will be joining a SOC team to support their 24X7 operations out of their India Tech Hub in Bengaluru. This would be a long term contract role with potential for full time conversion sitting 3 days on site in their Bengaluru office....


  • Bengaluru, India ADCI - Karnataka Full time

    Amazon’s Account Integrity team within the Customer Trust and Partner Support organization is looking for a passionate, results-oriented Business Analyst to leverage data to deliver projects with huge strategic impact. This team designs and builds high performance software systems using machine learning that identify and prevent fraudulent activity and...


  • Bengaluru, India KPMG India Full time

    About KPMG in India KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in...

  • Senior Product Manager

    3 months ago


    Bengaluru, India CloudSEK Full time

    WHO ARE WE?We are a bunch of super enthusiastic, passionate, and highly driven people, working to achieve a common goal! We believe that work and the workplace should be joyful and always buzzing with energy!CloudSEK,one of India’s most trusted Cyber security product companies, is on a mission to build the world’s fastest and most reliable AI technology...


  • Bengaluru, India CloudSEK Full time

    WHO ARE WE?Founded in 2015, and headquartered at Singapore, we are proud to say that we’ve grown at a frenetic pace and have been able to achieve some accolades along the way, including:Launch of our first product in 2016.Earning our pre-series A funding in 2018.Receiving multiple awards including the prestigious Excellence Award for being the Security...