All roles

Attack Surface Management Analyst

Remote · USA Full-time New today

Attack Surface Management (ASM) Analysts deliver our managed Polus Attack Surface Management service to our clients on a continuous basis to help them reduce risks to their internet-facing assets. This involves validating vulnerabilities, performing manual discovery of their attack surface and helping our clients interpret prioritised findings. Our aim is to become trusted advisors to our clients.You will help our clients to build cyber resilience, enhance their understanding of the threat landscape and become better prepared to face dynamic and evolving security risks. This will involve being on the front foot of new and emerging threats, and ensuring our clients receive quick feedback as to whether they may be affected and actions they can take.

  • Main Duties and Responsibilities
The main responsibilities of this role will include working closely with the ASM practice lead and Customer Success Managers to ensure that a high value service is delivered to clients. This will include:
  • Technical testing; vulnerability scanning, attack surface discovery, manual exploit validation, light-touch pentesting and Open-Source Intelligence (OSINT) gathering
  • Client Engagement; translating client challenges into solutions that fit S-RM's ASM service offerings and value proposition, understanding and supporting the proposal process and ensuring delivery timelines are understood inline with project resourcing requirements
  • Reporting; Delivering findings in a range of formats, including via the Polus ASM platform, via written report and also through Quarterly Service Reviews
You will also be required to keep abreast of threat intelligence developments, and work closely with S-RM's Threat Intelligence and Incident Response teams to integrate key data points into our service.Support to other teams will be required where ASM is used as a value-add to assessment-based engagements in our Risk & Resilience practice, and also where ASM is used to support incident investigation with our Incident Response practice.You will be required to work closely with the other managed service teams (Managed Detection and Response and Cyber Threat Intelligence) to ensure that managed service delivery is unified across all three offerings. Through this, you will also be given the opportunity to support and shape the development of the service, by working with the ASM practice lead, managed service teams and technical development teams to identify opportunities for innovation and improvement.
  • Who are we looking for?
We are looking for individuals keen to keep their finger on the pulse when it comes to the latest threats and vulnerabilities, with good client-facing skills needed to provide long term support to the organisations we work with. We're not looking for prior Attack Surface Management experience (although bonus points if you do), but we're looking for individuals who may fall into the following profiles with regards to experience:
  • Pentesters with a minimum of 1 year experience (including carrying out external pentests) looking to specialise in threat led approaches
  • Cyber Security Analysts with experience running vulnerability scans and triaging issues, looking to move into managed service delivery with an offensive security focus
  • Threat Intelligence Analysts with good knowledge of offensive security concepts and familiarity with running security tooling, keen to develop their technical skills
Candidates must have permission to work in the UK by the start of their employmentOUR BENEFITSWe offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, this includes but is not exhaustive of:Our benefitsWe offer thoughtful, balanced rewards and support to help our people do their best work and live their lives outside it, this includes but is not exhaustive of:
  • 25 days holiday per year in addition to bank holidays (+1 day for every year of service up to a maximum of 30 days);
  • Hybrid working and flexible working hours;
  • Matching pension contribution up to 7% and financial education;
  • Fertility treatment leave – 5 days of leave per cycle of treatment per year;
  • Maternity leave – 26 weeks of full pay followed by 13 weeks of half pay;
  • Paternity leave – 6 weeks of full pay.
  • Private dental and medical insurance (taxable benefit) for you and your family;
  • Virtual GP for you and your family members that live in the same household;
  • Various gym discounts for you and your partner;
The role will be based in our London office. However, we have flexible working arrangements available.THE APPLICATION PROCESSWe want to get to know you, and for you to get to know us, to see if we'd be a good fit. We are responsive and respectful of people's time throughout our hiring process.A typical application process includes:
  • Initial screening of your application by our recruiting team.
  • Interview to assess your baseline technical skills.
  • An interview to discuss your previous experience, broader competencies, and suitability for the role.
To apply for this role, please send a cover letter and CV to: Job Application for Attack Surface Management Analyst at S-RM

apply to this job

Related roles

Business Administration Apprentice ? 2026

Remote · USA Full-time

Divisional Financial Controller (Places for Lon...

Remote · USA Full-time

Consultant/Senior Consultant Technical Business...

Remote · USA Full-time

Executive Assistant – Global CEO (Late-Day Busi...

Remote · USA Full-time

Activity Leaders Summer 2026 (Residential) - No...

Remote · USA Full-time

Trainee Train Planner

Remote · USA Full-time

Coordinator, Global Investment Firm

Remote · USA Full-time

Identity and Access Senior Manager

Remote · USA Full-time

Customer Assistant (Hiring Immediately)

Remote · USA Full-time

Home Visits Optical Assistant

Remote · USA Full-time

Remote Customer Service Representative (Chat / No Calling / No Experience / Work at Home)

Remote · USA Full-time

Senior Product Designer (UX)

Remote · USA Full-time

Experienced Customer Service Representative – Virtual Customer Support Team at arenaflex

Remote · USA Full-time

[Remote] Computer Sciences - Graduates - AI Training - Baltimore, US

Remote · USA Full-time

Experienced Full Stack Data Analyst – Quality Control Standards and Data Insights

Remote · USA Full-time

Virtual Assistant & Communications Coordinator (US Healthcare) - EST Hours

Remote · USA Full-time

Meat Cutter - Scottsdale, AZ - 966

Remote · USA Full-time

Compassionate Remote Crisis Chat & Text Counselor – Full‑Time Position with arenaflex Supporting Deaf, Hard‑of‑Hearing & Deaf‑Plus Communities

Remote · USA Full-time

Founding Team – Ops & GTM

Remote · USA Full-time

Chief Data Officer – Insurance

Remote · USA Full-time