Cyber Threat Exposure Management Analyst
Core
Own end-to-end vulnerability lifecycle, maintain prioritized exposure views, and communicate risk to stakeholders across vulnerability management, attack surface management, cloud security posture, and secure SDLC.
Role type
Cyber Threat Exposure Management Analyst
Builds
Single exposure view consolidating attack surface, vulnerability, and posture data; actionable remediation guidance for engineering teams.
Domain
Cybersecurity / Cloud Security / Vulnerability Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Vulnerability lifecycle management, Attack Surface Management (ASM/EASM), Cloud Security Posture Management (CSPM), Risk-based triage, Secure SDLC integration, Stakeholder communication, Audit support
Preferred skills
EASM/CAASM platform experience, AI-augmented triage tooling, Defender XDR/CSPM, Zscaler, Tanium, Identity Security Posture Management (ISPM), Regulatory audit frameworks
Technologies
AWS, Azure, OCI, NIST CSF, ISO 27001, MITRE ATT&CK, CTEM principles
Responsibilities
Maintain continuous inventory of Internet-facing assets and shadow IT; Operate EASM/CAASM tooling to surface unmanaged assets; Apply CVSS, EPSS, and business context to set remediation SLAs; Monitor cloud misconfigurations and identity risk across AWS, Azure, and OCI; Consolidate exposure data into a single view for stakeholders; Embed security requirements and threat modelling into the SDLC; Produce dashboards translating technical exposure data into business risk language.
Seniority
Mid-level, hands-on IC