Description
The Security Analyst, Attack Surface Management role validates vulnerability submissions, assesses real-world impact, tracks High and Medium findings through remediation, documents compensating controls, writes remediation guidance, escalates Critical findings to Incident Response, and partners with engineering and product teams. The role requires at least two years of application security, vulnerability management, penetration testing, or bug bounty experience, proficiency in web and API penetration testing, knowledge of OWASP and MITRE ATT&CK, Burp Suite experience, and strong written communication.
