Cyber Threat Exposure Management Analyst
Bengaluru, KA, India
What you’ll work on
Full postingMaintain a continuous inventory of Internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, and third-party-hosted assets.
Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation.
Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF.
From the employer’s posting
Attack Surface Management (ASM / EASM) Maintain a continuous inventory of Internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, and third-party-hosted assets. Operate EASM/CAASM tooling to surface unowned or unmanaged assets and route them to the correct owner.
Vulnerability Management Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation. Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths.
Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths. Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF. Break down complex vulnerability backlogs into prioritised, actionable components and drive them to closure with minimal supervision.
See how this role fits your experience
Add your resume to compare the role’s scope, tools and requirements with your experience.
Pay, work setup, and employment type unconfirmed
Not confirmed in this saved copy: pay, work setup, employment type. Check the full posting
Tools in this posting
- aws
- azure
- snowflake
Source — Tool mentions in context
Cloud Security Posture Management (CSPM) - Monitor cloud misconfigurations, identity risk, and posture drift across AWS, Azure, and OCI. - Partner with cloud platform teams to remediate CSPM findings and reduce recurring misconfiguration classes.
- Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more. Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies - Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat - Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform.
Company Description Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services. We’re an award-winning employer reflecting how our employees are at the very heart of what we do:
We’re an award-winning employer reflecting how our employees are at the very heart of what we do: - UK & Ireland's premier AWS, Microsoft & Oracle partner - 3300+ strong, €350/£300m revenue business
Find answers in the posting
AIAlready applied? Track this application
About applying
Apply opens the employer’s site in a new tab. Add your outcome here after you submit.
Source details & eligibility
Before you apply
Source excerptsSelected passages from the saved posting. Check the full description for conditions and exceptions.
- Pay
No pay amount identified in the saved description.
- Location & working pattern
Bengaluru, KA, India
- Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme - Flexible/remote working, Version 1 is tremendously understanding of life events and people’s individual circumstances and offer flexibility to help achieve a healthy work life balance - Financial Wellbeing initiatives including; Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme
- Work authorization
No clear work-authorization passage found. Eligibility is unconfirmed.
Posting history
- Status in our records
- Active
- First seen by us
- Sep 10, 2026
- Recorded sightings
- 1
These dates show when we found the listing. Check the employer’s website to confirm it is still accepting applications.
Report an errorJob description
Job Description
We are seeking a Cyber Threat Exposure Analyst to support our exposure management programme across the estate. The role spans vulnerability management, attack surface management, cloud security posture, and secure development practice. Working as a fully contributing team member, you will own end-to-end vulnerability lifecycle activity, maintain prioritised exposure views, and communicate risk clearly to internal stakeholders. You operate with limited supervision, take clear ownership of your assignments, and consistently deliver to a high standard of quality.
Key Responsibilities
Attack Surface Management (ASM / EASM)
- Maintain a continuous inventory of Internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, and third-party-hosted assets.
- Operate EASM/CAASM tooling to surface unowned or unmanaged assets and route them to the correct owner.
- Enrich attack surface findings with threat intelligence, active exploitation trends, and KEV data to support prioritisation.
- Proactively identify gaps in asset coverage and bring forward improvement ideas without waiting to be directed.
Vulnerability Management
- Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation.
- Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths.
- Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF.
- Break down complex vulnerability backlogs into prioritised, actionable components and drive them to closure with minimal supervision.
Cloud Security Posture Management (CSPM)
- Monitor cloud misconfigurations, identity risk, and posture drift across AWS, Azure, and OCI.
- Partner with cloud platform teams to remediate CSPM findings and reduce recurring misconfiguration classes.
- Extend CSPM coverage as new cloud services, apps, and workloads are onboarded.
- Build and maintain strong working relationships with platform and engineering teams; negotiate remediation timelines and handle pushback constructively.
CTEM / Exposure Management
- Operate the Scope, Discover, Prioritise, Validate, and Mobilise phases of the CTEM programme.
- Consolidate attack surface, vulnerability, and posture data into a single exposure view for stakeholders.
- Track and report exposure reduction metrics against agreed KPIs, maintaining accurate and well-organised records across all workstreams.
Secure SDLC
- Embed security requirements, threat modelling, and secure code review checkpoints into the SDLC.
- Work with engineering teams to reduce vulnerability injection at source rather than relying only on downstream remediation.
- Maintain secure-by-design standards and guidance for development teams.
Pentest & Purple Team Support
- Support the commission and management of third-party penetration testing and purple team engagements.
- Review scope, rules of engagement, and quality of third-party findings before acceptance.
- Translate external test results into prioritised, actionable remediation guidance for internal teams.
Reporting & Stakeholder Communication
- Produce dashboards and reports translating technical exposure data into business risk language for senior stakeholders.
- Present exposure trends, remediation progress, and residual risk to management and audit/compliance functions.
- Support audit and certification cycles (ISO 27001, Cyber Essentials Plus, SOC 1, client MSP audits) with evidence of exposure management practice.
- Adapt communication style to the audience; explain technical risk clearly to non-technical colleagues and business stakeholders.
Ways of Working
- Meet all team commitments and deadlines; support colleagues encountering blockers and contribute to a collaborative team environment.
- Seek out and act on feedback; treat problems as learning opportunities and continuously update skills and knowledge.
- Adapt readily to changing priorities, new tooling, and evolving threat landscapes without disruption to delivery quality.
- Live and demonstrate Version 1 Core Values in everyday work, acting as a visible example for more junior colleagues.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 3+ years' experience in cyber security with hands-on exposure to vulnerability management, attack surface management, and/or cloud security.
- Relevant certifications: CompTIA CySA+, CEH, OSCP, CISSP, or equivalent.
- Working knowledge of NIST CSF, ISO 27001, MITRE ATT&CK, and CTEM principles.
- Strong written and verbal communication skills; able to translate technical risk for non-technical stakeholders.
Beneficial Skills
- Hands-on experience with EASM/CAASM, CSPM, or exposure management platforms.
- Familiarity with AI-augmented vulnerability triage or detection tooling.
- Experience with Defender XDR, Defender CSPM, Zscaler, Tanium, or equivalent platforms.
- Familiarity with Identity Security Posture Management (ISPM) and attack path mapping.
- Exposure to regulatory/audit frameworks such as Cyber Essentials Plus, SOC 1, or FSQS.
Additional Information
Why Version 1?
At Version 1, we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing, professional growth, and financial stability.
Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits
Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme
Flexible/remote working, Version 1 is tremendously understanding of life events and people’s individual circumstances and offer flexibility to help achieve a healthy work life balance
Financial Wellbeing initiatives including; Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme
Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more. Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies
Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat
Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform.
Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes.
And many more exciting benefits… drop us a note to find out more.
Version 1 is an equal opportunities employer.
We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring including those shaped by disability and neurodiversity.
We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process, please contact your recruiter at Version 1. We will consider all requests carefully, respectfully and confidentially.
Video links:
https://www.youtube.com/watch?v=F_d3ELTH5zo
Company Description
Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services.
We’re an award-winning employer reflecting how our employees are at the very heart of what we do:
- UK & Ireland's premier AWS, Microsoft & Oracle partner
- 3300+ strong, €350/£300m revenue business
- 10+ years as a Great Place to Work in Ireland & UK
- Best Workplace for Women in the UK & Ireland by GPTW
- Best Workplace for Wellbeing in the UK by GPTW
We’re a core values driven company, we hire people who share our values, and we reward those who display and foster them, it’s deeply embedded within our DNA. Invest in us and we’ll invest in you!.