Attack Surface Management Engineer

5 months ago


Hyderabad, India Experian Full time

Job Description

Description

The Attack Surface Management engineer is responsible for activities related to Attack Surface Management, with the goal to ensure comprehensive visibility of Experian’s attack surface and vulnerabilities.

Reporting Relationship

Reports to the Director Attack Surface Mgmt

Functions

Follows Attack Surface Mgmt processes to continuously monitor and improve visibility of the attack surface in order to detect anomalies faster and reduce incidences of cyber-attacks Perform verification/validation testing for vulnerabilities in external-facing web sites, web applications, and services; demonstrate exploitation steps and verify remediation/fixes Generate comprehensive reports, including detailed findings, exploitation procedures, and mitigation techniques Engage with business stakeholders to ensure they fully understand their Attack Surface, and helps them identify prioritization of vulnerabilities Develops vulnerability KPIs/metrics to demonstrate coverage and remediation effectiveness Execute daily operations of the Attack Surface Mgmt program, including the interpretation of scanning results Asist in the identification of internal and external risks based on scanning results Assist in the attribution of findings to appropriate business owner Identify improvements to scan coverage Coordinate with IT and geographically dispersed business units vulnerability remediation and mitigation strategies Assist in the documentation and standardization of process and procedures related to Attack Surface Mgmt Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.

Responsibilities/Requirements

Familiarity with common web vulnerabilities including: XSS, XXE, SQL Injection, Deserialization Attacks, Path Traversal Attacks, Remote Execution Flaws, and Authentication Flaws Understanding of common web application frameworks and web-based APIs Experience with one or more scripting languages such as Bash, Python, Perl, PowerShell, etc. In-depth knowledge of architecture, engineering, and operations of one or more vulnerability management tools, such as Wiz, Qualys, Rapid7 and ServiceNow. Solid understanding of the application of the following frameworks and how they are applied to identifying and rating risk: OWASP, SANS, NIST, CIS, and MITRE ATT&CK. Ability to provide creative solutions to complex problems Ability to clearly communicate risk of vulnerabilities to all levels within an organization. Knowledge of major cloud platforms (AWS, Azure, or GCP). Knowledge of systems hardening and other risk mitigation factors on multiple technologies and operating systems (Window, Linux, Mac, routers, switches, Kubernetes). Certification that could be helpful but not required: CISSP, Security+, CEH, GIAC certifications. Ability to manage, organize, analyze, and present substantial amounts of data Experience selecting and deploying product

Position Requirements

Formal Education & Certification

Four-year college diploma or university degree in computer science or computer engineering, and/or 3 years equivalent work experience.

Qualifications

Position Requirements

Formal Education & Certification

Four-year college diploma or university degree in computer science or computer engineering, and/or equivalent work experience.

Knowledge & Experience

 experience in information security vulnerability management role Experience with large scale and complex environments  A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies Applied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management and security and controls Excellent interpersonal skills and strong verbal and written communication An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood and actionable manner Strong organizational skills with proven ability to manage multiple high visibility issues simultaneously Proactive attitude, seeking for improvement opportunities which can positively impact the security posture and the business

Personal Attributes

Excellent oral and interpersonal communication skills Outstanding writing and documentation skills Able to communicate ideas in both technical and user-friendly language Highly self-motivated and directed, with keen attention to detail Able to prioritize and execute tasks in a high-pressure environment Experience working in a team-oriented, collaborative environment Willing to travel globally as required

Additional Information

Experian Careers - Creating a better tomorrow together

Find out what its like to work for Experian by clicking here



  • Hyderabad, Telangana, India Experian Full time

    Job DescriptionExperian is seeking a skilled Attack Surface Management Engineer to join our team. As a key member of our cybersecurity team, you will play a critical role in ensuring the comprehensive visibility of our attack surface and vulnerabilities.Key Responsibilities:Continuously monitor and improve visibility of the attack surface to detect anomalies...


  • Hyderabad, Telangana, India Experian Full time

    Job DescriptionExperian is seeking a highly skilled Attack Surface Management Engineer to join our team. As a key member of our security team, you will be responsible for ensuring comprehensive visibility of our attack surface and vulnerabilities.Key ResponsibilitiesMonitor and improve visibility of the attack surface to detect anomalies faster and reduce...


  • Hyderabad, Telangana, India Experian Full time

    Job DescriptionExperian is seeking a skilled Attack Surface Management Engineer to join our team. As a key member of our cybersecurity team, you will be responsible for ensuring comprehensive visibility of our attack surface and vulnerabilities.Key ResponsibilitiesMonitor and improve visibility of the attack surface to detect anomalies faster and reduce...


  • Hyderabad, Telangana, India Experian Full time

    Job DescriptionExperian is seeking a skilled Attack Surface Management Security Specialist to join our team. In this role, you will be responsible for monitoring and improving visibility of Experian's attack surface to detect anomalies faster and reduce incidences of cyber-attacks.Key ResponsibilitiesFollow Attack Surface Management processes to continuously...


  • Hyderabad, Telangana, India Experian Full time

    Job Title: Attack Surface Management EngineerAbout the Role:We are seeking a highly skilled Attack Surface Management Engineer to join our team at Experian. As a key member of our cybersecurity team, you will be responsible for identifying and mitigating vulnerabilities in our attack surface.Key Responsibilities:Monitor and improve visibility of the attack...


  • Hyderabad, Telangana, India Satyam Venture Engineering Services Full time

    We are seeking a skilled Creo and Surfacing Modeling Engineer to join our team at Satyam Venture Engineering Services.Key Responsibilities:• Strong proficiency in Creo and Surfacing Modeling is required.• Experience in building Class B Surfaces is a must.Requirements:• 5-8 years of experience in Creo and Surfacing Modeling.• Interested candidates...


  • Hyderabad, India DastagirMachines Full time

    Experience in Surface Grinding Machine Operation - Experience in Cylindrical Grinding Machine Operation - Good understanding of Engineering Drawings, GD&T Symbols - Knowledge of inspection gauges **Job Types**: Full-time, Permanent **Salary**: From ₹12,000.00 per month **Benefits**: - Leave encashment - Paid time off Schedule: - Day shift - Night...

  • Infosec Engineer

    3 months ago


    Hyderabad, India 860 GapTech India Full time

    About the Role In this role you will be part of the Defensive Engineering team within Enterprise Security. Defensive Engineering comprises of Endpoint Protection, Vulnerability Management & Attack Surface Management is responsible to upkeep the security state of all the assets within the organization. You will build relationships and collaborate with...


  • Hyderabad, Telangana, India Microsoft Full time

    Job Title: Security Operations EngineerAt Microsoft, we're committed to making the world a safer place for all. As a Security Operations Engineer, you'll play a critical role in defending our customers from sophisticated cyber-attacks and adversaries.Responsibilities:Monitor and analyze alerts and incidents generated by the Microsoft 365 Defender suite of...


  • Hyderabad, Telangana, India Claranet Full time

    About ClaranetWe are a leading business modernisation expert delivering solutions across 11+ countries. Our approach helps customers make genuine, significant shifts in their business strategy to deliver financial savings, boost innovation, and create a resilient business.About The RoleThe Continuous Security Testing service is a consultant-led vulnerability...


  • Hyderabad, Telangana, India Microsoft Full time

    Job SummaryAs a Security Operations Engineer at Microsoft, you will play a critical role in defending our customers from sophisticated cyber-attacks and adversaries. We are seeking a highly skilled and experienced professional to join our Microsoft 365 Defender Experts team, where you will be responsible for monitoring incidents and alerts from our security...


  • Hyderabad, Telangana, India Microsoft Full time

    Job DescriptionOverviewIn a world where digital threats and regulatory scrutiny are pervasive, our customers rely on us to ensure their security. As a Security Operations Engineer, you will be part of the Microsoft Security team, responsible for monitoring incidents and alerts generated by the Microsoft 365 Defender suite of products. Your expertise will be...


  • Hyderabad, Telangana, India Microsoft Full time

    OverviewAt Microsoft, we're committed to making the world a safer place for all. Our Security Operations team is at the forefront of this mission, working tirelessly to protect our customers from sophisticated cyber threats. As a Security Operations Engineer, you'll play a critical role in monitoring and analyzing alerts and incidents generated by our...


  • Hyderabad, Telangana, India Microsoft Full time

    Job SummaryMicrosoft is seeking a highly skilled Security Operations Engineer to join our team. As a Security Operations Engineer, you will be responsible for monitoring and analyzing alerts and incidents generated by the Microsoft 365 Defender suite of products, and providing timely and effective response and remediation, ensuring optimal coverage and...


  • Hyderabad, Telangana, India Microsoft Full time

    Job SummaryMicrosoft is seeking a highly skilled Security Operations Engineer to join our team. As a Security Operations Engineer, you will be responsible for monitoring and analyzing alerts and incidents generated by the Microsoft 365 Defender suite of products, and providing timely and effective response and remediation, ensuring optimal coverage and...


  • Hyderabad, Telangana, India Claranet Full time

    About the RoleThe Continuous Security Testing service is a consultant-led vulnerability identification and verification service that utilizes automated vulnerability scanning and manual testing to monitor a customer's external attack surface. The purpose of this service is to continually identify new vulnerabilities, changes in the scope of the attack...


  • Hyderabad, Telangana, India PepsiCo Full time

    Overview: **The Infosec Lead** is a strategic partner to the business and is responsible for supporting information security risk management and technical security analysis within the sector. This role requires a technical security expert to assess, mitigate, and remediate security risks, driving security initiatives within the sector and promoting security...

  • Senior DLP Engineer

    4 days ago


    Hyderabad, Telangana, India ValueLabs Full time

    Job RequirementsWe are looking for a highly skilled and experienced DLP engineer to join our team at ValueLabs.ExperienceThe ideal candidate should have at least 10 years of experience in the field of DLP, with a minimum of 4-5 years of experience in engineering roles. The candidate should have a strong background in implementation, deployment, and patching...


  • Hyderabad, India NopalCyber Full time

    NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Managed extended detection and response (MXDR), attack surface management (ASM), breach and attack simulation (BAS), and advisory services fortify your cybersecurity across both offense and defense. AI-driven intelligence in...


  • hyderabad, India NopalCyber Full time

    NopalCyber makes cybersecurity manageable, affordable, reliable, and powerful for companies that need to be resilient and compliant. Managed extended detection and response (MXDR), attack surface management (ASM), breach and attack simulation (BAS), and advisory services fortify your cybersecurity across both offense and defense. AI-driven intelligence in...