[Hiring] Cyber Threat Exposure Management Analyst @Version 1
Cyber Threat Exposure Management Analyst @Version 1
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 4d ago

[Hiring] Cyber Threat Exposure Management Analyst @Version 1

4d ago - Version 1 is hiring a remote Cyber Threat Exposure Management Analyst. 💸 Salary: unspecified 📍Location: India

Role Description

We are seeking a Cyber Threat Exposure Analyst to support our exposure management programme across the estate. The role spans vulnerability management, attack surface management, cloud security posture, and secure development practice. Working as a fully contributing team member, you will own end-to-end vulnerability lifecycle activity, maintain prioritised exposure views, and communicate risk clearly to internal stakeholders. You operate with limited supervision, take clear ownership of your assignments, and consistently deliver to a high standard of quality.

Key Responsibilities

  • Attack Surface Management (ASM / EASM)
    • Maintain a continuous inventory of Internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, and third-party-hosted assets.
    • Operate EASM/CAASM tooling to surface unowned or unmanaged assets and route them to the correct owner.
    • Enrich attack surface findings with threat intelligence, active exploitation trends, and KEV data to support prioritisation.
    • Proactively identify gaps in asset coverage and bring forward improvement ideas without waiting to be directed.
  • Vulnerability Management
    • Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation.
    • Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths.
    • Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF.
    • Break down complex vulnerability backlogs into prioritised, actionable components and drive them to closure with minimal supervision.
  • Cloud Security Posture Management (CSPM)
    • Monitor cloud misconfigurations, identity risk, and posture drift across AWS, Azure, and OCI.
    • Partner with cloud platform teams to remediate CSPM findings and reduce recurring misconfiguration classes.
    • Extend CSPM coverage as new cloud services, apps, and workloads are onboarded.
    • Build and maintain strong working relationships with platform and engineering teams; negotiate remediation timelines and handle pushback constructively.
  • CTEM / Exposure Management
    • Operate the Scope, Discover, Prioritise, Validate, and Mobilise phases of the CTEM programme.
    • Consolidate attack surface, vulnerability, and posture data into a single exposure view for stakeholders.
    • Track and report exposure reduction metrics against agreed KPIs, maintaining accurate and well-organised records across all workstreams.
  • Secure SDLC
    • Embed security requirements, threat modelling, and secure code review checkpoints into the SDLC.
    • Work with engineering teams to reduce vulnerability injection at source rather than relying only on downstream remediation.
    • Maintain secure-by-design standards and guidance for development teams.
  • Pentest & Purple Team Support
    • Support the commission and management of third-party penetration testing and purple team engagements.
    • Review scope, rules of engagement, and quality of third-party findings before acceptance.
    • Translate external test results into prioritised, actionable remediation guidance for internal teams.
  • Reporting & Stakeholder Communication
    • Produce dashboards and reports translating technical exposure data into business risk language for senior stakeholders.
    • Present exposure trends, remediation progress, and residual risk to management and audit/compliance functions.
    • Support audit and certification cycles (ISO 27001, Cyber Essentials Plus, SOC 1, client MSP audits) with evidence of exposure management practice.
    • Adapt communication style to the audience; explain technical risk clearly to non-technical colleagues and business stakeholders.
  • Ways of Working
    • Meet all team commitments and deadlines; support colleagues encountering blockers and contribute to a collaborative team environment.
    • Seek out and act on feedback; treat problems as learning opportunities and continuously update skills and knowledge.
    • Adapt readily to changing priorities, new tooling, and evolving threat landscapes without disruption to delivery quality.
    • Live and demonstrate Version 1 Core Values in everyday work, acting as a visible example for more junior colleagues.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
  • 3+ years' experience in cyber security with hands-on exposure to vulnerability management, attack surface management, and/or cloud security.
  • Relevant certifications: CompTIA CySA+, CEH, OSCP, CISSP, or equivalent.
  • Working knowledge of NIST CSF, ISO 27001, MITRE ATT&CK, and CTEM principles.
  • Strong written and verbal communication skills; able to translate technical risk for non-technical stakeholders.

Benefits

  • Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits.
  • Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme.
  • Flexible/remote working, Version 1 is tremendously understanding of life events and people’s individual circumstances and offer flexibility to help achieve a healthy work life balance.
  • Financial Wellbeing initiatives including; Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme.
  • Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more.
  • Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies.
  • Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat.
  • Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform.
  • Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes.
  • And many more exciting benefits… drop us a note to find out more.
Before You Apply
remote Be aware of the location restriction for this remote position: India
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Cyber Threat Exposure Management Analyst @Version 1
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 4d ago
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 125,000+ Remote Jobs
remote Be aware of the location restriction for this remote position: India
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 125,000+ Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later