WHAT YOU’LL DO
We are seeking a skilled and experienced Attack Surface Reduction Analyst with a strong background in penetration testing to join our cybersecurity team. The successful candidate will be responsible for identifying potential security risks and vulnerabilities in our organization's systems, applications, and networks, performing penetration testing, and facilitating and managing third-party penetration testing engagements.
WHO YOU’LL WORK WITH
Attack Surface Reduction team helps and contribute to improve the security posture of H&M by operating within an Agile model. We play a crucial role in proactively identifying and help in mitigating potential security risks and vulnerabilities across H&M's systems, applications, and networks, with the aim of preventing unauthorized access, data breaches, and other security incidents.
Key Responsibilities:
- Conduct comprehensive vulnerability assessments (VA) and penetration tests (PT) on H&M's systems, networks, and applications.
- Utilize industry-standard tools and methodologies to identify potential vulnerabilities and weaknesses in our attack surface.
- Collaborate with cross-functional teams to prioritize and remediate identified vulnerabilities in a timely manner.
- Experience in designing, implementing, and managing vulnerability management processes and workflows.
- Facilitate and manage penetration testing engagements with third-party vendors.
- Collaborate with other members of the cybersecurity team to develop and implement strategies to reduce our attack surface.
- Develop and maintain security policies and procedures for our organization's systems, applications, and networks.
- Monitor our organization's systems, applications, and networks for unauthorized access, suspicious activity, and other security threats.
- Stay up to date with the latest trends and developments in the field of cybersecurity, specifically related to attack surface reduction techniques.
WHO YOU ARE
We are looking for people with…
- Bachelor's degree in computer science, information security, or a related field.
- 6-10 years of experience in vulnerability scanning, vulnerability management, and penetration testing.
- Solid knowledge of common vulnerabilities and exposures (CVEs), common attack vectors, and security best practices.
- Strong knowledge of security assessment tools, vulnerability scanning, and penetration testing.
- Proficient in using industry-standard vulnerability assessment and penetration testing tools (e.g., Kali Distro, Qualys, Burp Suite, etc.).
- Familiarity with industry frameworks and standards, such as NIST, OWASP, and CIS.
- Effective communication skills, with the ability to clearly convey technical concepts to both technical and non-technical stakeholders.
- Excellent analytical, problem-solving, and communication skills.
- Relevant certifications, such as SANS, OSCP, OSEP, CompTIA Security+ or CREST are a plus.
WHY YOU’LL LOVE WORKING HERE
At H&M, we are proud to be a vibrant and welcoming company. We offer our employees attractive benefits with extensive development opportunities around the globe.
We offer all our employees at H&M attractive benefits with extensive development opportunities around the globe. All our employees receive a staff discount card, usable on all our H&M brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET, Afound. In addition to our staff discount, all our employees are included in our H&M Incentive Program – HIP. You can read more about our H&M Incentive Program here.
In addition to our global benefits, all our local markets offer different competitive perks and benefits. Please note that they may differ between employment types and countries.
JOIN US
Our uniqueness comes from a combination of many things – our inclusive and collaborative culture, our strong values, and opportunities for growth. But most of all, it’s our people who make us who we are.
Take the next step in your career together with us. The journey starts here.
*We are committed to a recruitment process that is fair, equitable, and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
ADDITIONAL INFORMATION
This is a full-time position, starting in June 2025.
Apply by sending in your CV in English as soon as possible, but no later than the 30th of May 2025. Due to data policies, we only accept applications through the SmartRecruiters or career page
Similar Jobs
What We Do
Founded in 1947, H&M Group is a global design company with ~4,702 stores in 76 markets and 56 online markets. At H&M Group, we believe in making great design available to everyone. It’s essential in everything we do. Our family of brands and business ventures offer customers around the world a wealth of fashion, beauty, accessories and homeware, as well as modern menus with fresh and local produce at some of the brands’ in-store eateries.
But design is so much more than just products; it’s about clever design processes, efficient product flows, creating experiences that enrich, and smart solutions that benefit all our customers.
Sustainability is always at the core of our business. Not only because we like to do what’s right — but it’s also beneficial for our business. We will continue to push for change and lead the way towards a more inclusive and sustainable fashion future.
Do you want to join us? We will trust you with great responsibility right from the start, reward a passionate mindset and encourage an entrepreneurial spirit. When you start a career with H&M Group, there’s no limit to where it can take you.
H&M Group's Moderation Policy:
Welcome to H&M Group’s official LinkedIn page. Ask questions, exchange ideas and meet members and employees from all over the world.
This page is moderated daily and we always do our best to answer each one of you in a timely manner. Please remember to keep a friendly tone and in line with LinkedIn’s legal terms at https://www.linkedin.com/legal/user-agreement
Comments and posts that contain foul language, are off-topic or unnecessarily rude will be deleted. We also encourage you to report any inappropriate content.
We use an external tool to handle the comments on our page, so please note that your comments can be stored. For questions, please contact our team at [email protected].







