--- title: 'Security Analyst, Attack Surface Management at UltraViolet Cyber' canonical: 'https://feeny.ai/job/security-analyst-attack-surface-management-ultraviolet-cyber-hyderabad-exq15855gvtk' type: 'job' last_seen: '2026-09-12' --- # Security Analyst, Attack Surface Management at UltraViolet Cyber - **Company:** UltraViolet Cyber - **Location:** Hyderabad, India - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-09-03 - **Last confirmed live:** 2026-09-12 - **Apply:** https://jobs.lever.co/uvcyber/ad8d1205-52dc-45e3-899e-fd0115514e2b ## Job description Job Title: Security Analyst, Attack Surface Management Summary The Attack Surface Management team owns what happens after a vulnerability is found. Findings arrive from red team pentests, adversary simulations, external bug bounty submissions, and scanning coverage. This role validates them, determines real impact, and drives them to closure with the engineering teams that own the affected assets. Critical findings route to Incident Response. Everything rated High and Medium is this team's responsibility until it is patched or a compensating control is in place and documented. This is not a patch operations role. Separate teams apply fixes. This role decides what matters, why it matters, and holds the line until it is resolved. ## Responsibilities - Triage and validate inbound Bugcrowd submissions: reproduce the reported issue, confirm or reject it, deduplicate against known findings, and determine payout-relevant severity. - Independently assess impact rather than accepting a submitter's or a scanner's rating. Factor in exploitability, asset exposure, data sensitivity, authentication requirements, and existing controls. - Track High and Medium findings from red team engagements and adversary simulations through remediation, including retest and closure verification. - Evaluate and document compensating controls where a fix is not immediately viable, and set expiry conditions rather than leaving exceptions open indefinitely. - Write remediation guidance that an application or platform engineer can act on without further translation. - Escalate Critical findings to Incident Response with the reproduction detail and blast radius assessment they need to act. - Partner with application owners and product teams on remediation timelines, and raise risk acceptance decisions to leadership when timelines slip. - Maintain visibility into externally exposed assets and flag newly surfaced attack surface for assessment. Required Qualifications - Two or more years in application security, vulnerability management, penetration testing, or bug bounty work. - Working proficiency in web application and API penetration testing. You should be able to independently reproduce a submitted finding, escalate it if the submitter undersold it, and prove it is a false positive if it is one. - Practical knowledge of OWASP Top 10 and OWASP API Security Top 10, including what remediation actually looks like for each class of issue. - Familiarity with MITRE ATT&CK techniques and the ability to connect a finding to how an attacker would chain it. - Severity determination beyond a CVSS calculator. You can explain why a High-scoring finding on an isolated internal asset may matter less than a Medium on an internet-facing authentication flow. - Hands-on experience with Burp Suite and standard web and API testing tooling. - Clear written communication. Much of this role is convincing an engineering team that a finding is real and worth their sprint capacity. ## Preferred Qualifications - Demonstrated bug bounty track record on Bugcrowd, HackerOne, or Intigriti. - Experience triaging submissions from the program side. - Cloud security exposure across AWS or Azure, particularly identity and storage misconfigurations. - Certifications such as BSCP, OSWA, OSCP, CPTS, or PNPT. A public bug bounty profile carries equal weight. Scripting in Python for reproduction harnesses and finding automation. ## About UltraViolet Cyber ## Company Overview - **One-liner**: UltraViolet Cyber is a tech-enabled managed security services provider that unifies offensive and defensive cybersecurity operations to protect Global 2000 and Federal Government customers. - **Entity Type**: Private (Series A in 2017; Private Equity round in 2023) - **Headquarters**: McLean, Virginia, United States - **Founded**: Not publicly available (earliest known funding round: 2017) - **Founders**: Not publicly available (leadership includes CEO Ira Goldstein and President/COO Atif Ghauri) ## Core Business - **Primary industry**: Cybersecurity (Managed Security Services Provider, MSSP) - **Target customers**: Global 2000 enterprises and U.S. Federal Government agencies (B2B, Enterprise, Government) - **Mission**: "To enable secure, resilient operations so our customers can serve, innovate, and lead with confidence." ## Products & Services - **UV Lens**: Flagship security-as-a-service solution that removes operational silos and integrates security capabilities (SaaS/Managed Service). - **Managed Detection & Response (MDR)**: 24/7 threat monitoring and response (Service). - **SOC as-a-Service**: Outsourced Security Operations Center (Service). - **Continuous Penetration Testing**: Ongoing offensive security assessments (Service). - **Continuous Threat Exposure Management**: Proactive vulnerability identification and prioritization (Service). - **Dedicated Defense**: Custom, dedicated security teams for clients (Service). ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total funding of $4.1M (one Series A round in 2017 and one Private Equity round in 2023) - **Notable Investors/Partners**: Not publicly named (one investor in the 2023 PE round); acquired Black Duck’s Application Security Testing Services Business. - **Growth Signals**: - Ranked #2642 on Inc. 5000 list of America’s Fastest-Growing Private Companies. - Ranked #19 on MSSP Alert's Top 250 MSSPs. - 509 employees (as of mid-2026) with offices in McLean (HQ), Lehi (UT), Phoenix (AZ), Hyderabad (India), and remote workers in UK and Canada. - 52,000+ LinkedIn followers with monthly growth of +1.1%. - Active job postings: 34 (monthly increase of +9.7%). ## Competitive Advantages - **First-to-market unified security operations**: Combines red (offensive) and blue (defensive) teams under one platform – the "UltraViolet" approach. - **Founding pedigree**: Led by cybersecurity experts trained by the NSA and Federal Government, giving deep intelligence community expertise. - **Security-as-code platform**: Delivers integrated capabilities through a potent, automated platform rather than siloed tools. - **Customer base**: Serves Global 2000 and Federal clients, indicating high trust and stringent compliance requirements. ## Strategic Focus - **Current priorities**: Scaling the unified security operations model, expanding tech-enabled managed services, and deepening partnerships with enterprise and government clients. - **Innovation in delivery**: Custom solutions and innovative delivery models to disrupt the traditional MSSP market. - **Growth direction**: Continued hiring (34 open roles across engineering, sales, consulting) and geographic expansion (notably in India and UK). ## Why Work Here - **Culture**: "Growing community of professionals passionate about cybersecurity, innovation, accountability, consistency, and a strong will to win." Emphasis on transparency, collaboration, and delivery excellence. - **Work policy**: Hybrid and remote options available (roles in Lehi, UT; Salt Lake City; Bluemont, VA; Hyderabad, India; and fully remote positions for engineers and consultants). - **Benefits**: Excellent benefits, compensation, training, 401k, and paid time off. Career advancement opportunities through dynamic project work. - **Engineering culture**: Hands-on with cutting-edge security tech; teams include red team consultants, cloud security engineers, SOC analysts, and DevOps engineers. - **Salary examples** (from Indeed): Cloud Security Engineer $100k–$150k, Associate Principal Red Team Consultant $165k–$195k, SOC Analyst ~$101k, Security Engineer ~$142k. ## Sources 1. [uvcyber.com/careers](https://www.uvcyber.com/careers) 2. [uvcyber.com/about](https://www.uvcyber.com/about) 3. [linkedin.com/company/uvcyber](https://linkedin.com/company/uvcyber) 4. [indeed.com/cmp/Ultraviolet-Cyber](https://www.indeed.com/cmp/Ultraviolet-Cyber) ## Other roles at UltraViolet Cyber - [Senior SOC Analyst | MDR](https://feeny.ai/job/senior-soc-analyst-mdr-ultraviolet-cyber-remote-ve8vz6pdbdkn) - [Senior Cybersecurity Incident Response Specialist](https://feeny.ai/job/senior-cybersecurity-incident-response-specialist-ultraviolet-cyber-hyderabad-w0rwp8q4p57s) — Hyderabad, India - [Automation Data Integration Engineer](https://feeny.ai/job/automation-data-integration-engineer-ultraviolet-cyber-washington-s5kcx7gvh338) — Washington, DC - [Principal Cyber Security Solutions Architect](https://feeny.ai/job/principal-cyber-security-solutions-architect-ultraviolet-cyber-national-harbor-nrzczr3dqkka) — National Harbor, MD - [Systems Administrator (RHEL)](https://feeny.ai/job/systems-administrator-rhel-ultraviolet-cyber-herndon-ntn1e24y27bc) — Herndon, VA - [Senior Security Engineer - Splunk](https://feeny.ai/job/senior-security-engineer-splunk-ultraviolet-cyber-national-harbor-yx5w5qrxn343) — National Harbor, MD - [Information Security Systems Engineer (RHEL Focus)](https://feeny.ai/job/information-security-systems-engineer-rhel-focus-ultraviolet-cyber-herndon-tqww8j7m6ncn) — Herndon, VA - [Security Engineer (Active Secret Clearance)](https://feeny.ai/job/security-engineer-active-secret-clearance-ultraviolet-cyber-herndon-5jvh7v1ww82a) — Herndon, VA - [Sr. Accountant](https://feeny.ai/job/sr-accountant-ultraviolet-cyber-hyderabad-gnf39m1yzp2a) — Hyderabad, India - [Senior Security Engineer - Crowdstrike](https://feeny.ai/job/senior-security-engineer-crowdstrike-ultraviolet-cyber-national-harbor-rke6gveen9yn) — National Harbor, MD