Senior Cyber Analyst - Threat Exposure Management

Posted 6 Hours Ago
Be an Early Applicant
560064, Yelahanka, Karnataka, IND
Hybrid
Senior level
Logistics • Transportation
The Role
Perform threat exposure and vulnerability management across code, applications, AI/ML, cloud, infrastructure, and identity environments. Conduct asset discovery, scanning, exploitability assessment, validation, prioritization, and remediation tracking. Analyze identity attack paths, misconfigurations, privilege issues, and certificate-related threats. Maintain integrations and data quality across security platforms, produce exposure metrics and dashboards, collaborate with intelligence and incident response teams, and improve operational procedures and tooling.
Summary Generated by Built In

We are looking for a Senior Cyber Analyst specialising in Threat Exposure Management for AppSec and AI within the ‘Identify’ Capability.

The ‘Identify’ capability focusses on managing the attack surface and continually evaluating the accessibility, exposure, and exploitability of our environments and assets. This involves in supporting building and running all the services (technology, people and process) to perform Threat Exposure Management along with responsibility for managing the output and working with stakeholders to close any discovered issues.

As part of the ‘Identify’ capability within the Threat Exposure Management function, the Senior Cyber Analyst – Threat Exposure Management has the responsibility for overseeing the continual evolution of the organisation’s threat exposure management lifecycle and reduction programmes within a given scope, and reports to the Cyber Manager – Threat Exposure Management. This role ensures that exposures across the Code, Application and AI environments are proactively identified, prioritised, validated, and remediated in alignment with business risk and operational resilience requirements.

The successful candidate must demonstrate a strong track record in performing in-depth technical assessments, and delivering clear, expert insights on identified vulnerabilities and exposures, including validation, prioritisation, and contextual analysis. They will be responsible for helping to establish and refine best practices for threat exposure management and vulnerability management, whilst effectively influencing stakeholders across the organisation. The role requires advanced technical expertise in exposure analysis and defensive and offensive security, with the ability to lead detailed technical discussions and perform complex investigations across Identity technologies.

Key Responsibilities:

> Threat Exposure Management and Vulnerability Management

  • Perform detailed analysis of vulnerabilities and exposures across the source-code repositories, applications, and AI/ML ecosystems attack surface.
  • Support other attack surface technologies such as IT, OT/ICS, cloud environments, containers, applications, identity systems, data platforms.
  • Execute the full exposure lifecycle, including asset discovery, authenticated scanning, enumeration, exploitability assessment, enrichment, and risk-based prioritisation.
  • Maintain reliable integration and data quality across VM, CTEM, AppSec, CSPM, ASM/EASM, and asset-inventory platforms to ensure complete and accurate attack-surface visibility.
  • Collaborate with Threat Intelligence, Red Team, and Incident Response to validate exploit paths, map findings to adversary TTPs, and translate technical risks into clear remediation actions.
  • Assess cloud, code assets, and AI/ML technologies for misconfigurations, privilege issues, insecure interfaces, and emerging exposure patterns, supporting timely remediation and control hardening.

> Operational Excellence & Quality Obsession

  • Contribute to SOPs, playbooks, and continuous-improvement initiatives across VM and CTEM services, ensuring processes are consistent, repeatable, and aligned with high-standards services and deliverables.
  • Support optimisation of VM, ASM/EASM, CSPM, CTEM, and AppSec toolsets, ensuring reliable coverage, accurate data, and high-fidelity results.
  • Ensure high data-quality standards across exposure findings, asset attribution, prioritisation logic, and reporting outputs.
  • Collaborate effectively across Identity, Respond, Detect, Protect, Strategy, Delivery, Platform Engineering, Threat Intelligence, Architecture, Risk, Issues Engineers, and Portfolio Cyber Leads to drive aligned, timely remediation outcomes.

> Reporting, Analytics & Metrics

  • Support to produce accurate reporting and dashboards on vulnerabilities, Critically Exposed Assets (CEAs), exposure windows, burndown trends, and remediation progress, ensuring high data quality across all sources.
  • Validate and maintain data integrity by troubleshooting attribution issues, correcting inconsistencies across VM, CTEM, AppSec, CSPM, ASM/EASM, and asset-inventory platforms.
  • Analyse exposure patterns and metric trends to provide insights that support prioritisation, operational decisions, and continuous-improvement actions.
  • Support leadership reporting by preparing inputs for scorecards, deep dives, and performance reviews, while identifying opportunities to enhance KPIs and metric definitions.

We are looking for:

  • 5-7+ years of progressive experience in enterprise cyber security with demonstrable in-depth technical expertise across Threat Exposure Management, Vulnerability Management, Defensive and Offensive Security applied to Identity technologies, whilst Application Security, Cloud Security, Data, OT/ICS, and AI/ML Security are beneficial.
  • Experience must span large-scale, heterogeneous environments with complex technology stacks. Certifications such as CISSP, GIAC, Microsoft Identity and Security, IGA, PAM are advantageous, but equivalent hands-on technical capability, advanced analytical proficiency, and a strong record of continuous learning and practical security training are essential.
  • Deep understanding of vulnerability classes, exploit vectors, configuration weaknesses, and exposure patterns across Windows, Linux, network devices, cloud services, containers, applications, and OT/ICS systems.
  • Strong ability to perform exploitability assessment, correlate vulnerabilities with attacker behaviour (MITRE ATT&CK), and differentiate real risk from noise or false positives.
  • Hands-on experience with VM/CTEM tooling and pipelines, including, but not limited to authenticated scanning, asset discovery methods, CSPM, AppSec (SAST/SCA/DAST/IaC), ASM/EASM platforms, passive/active enumeration and validating high-risk Critically Exposed Assets (CEAs).
  • Strong capability to validate data accuracy, match assets, reconcile mismatches, and ensure consistent exposure attribution and ability to analyse trend data, identify anomalies, and provide actionable insights.
  • Strong knowledge of AD/Entra ID, Kerberos, NTLM, PKI, certificate chains, CRLs/OCSP, SPNs, federation, MFA, and the ability to identify high-risk identity misconfigurations such as insecure trust relationships, expired or weak certificates, unconstrained delegation, and stale privileges.
  • Skilled in analysing identity attack paths, identifying lateral movement, privilege escalation, token abuse, SPN abuse, mis-issued certificates, and validating high-fidelity identity exposures including certificate-related attack vectors.
  • Proficient in cloud and hybrid identity setups (Azure AD/Entra, ADFS, Azure AD Connect) including IAM roles, service principals, OAuth/OIDC flows, certificate-based authentication, SCIM provisioning, and detection of identity drift, sync failures, or insecure connectors.
  • Ability to identify cloud and DNS-related exposure paths such as dangling DNS records, orphaned service endpoints, misconfigured identity endpoints, excessive cloud privileges, insecure APIs, and domain-federation weaknesses across CSPs such as, Azure, AWS, and GCP.
  • Knowledge of PAM/PAW, JIT/JEA models, IGA (SailPoint, Saviynt), and Zero Trust identity principles, with the ability to spot toxic privilege combinations, entitlement sprawl, and policy drift.
  • Ability to correlate identity exposures with adversary TTPs, credential abuse techniques, Golden Ticket/SAML attacks, and map identity weaknesses within wider attack paths across apps, cloud, and infrastructure.
  • Knowledge of PAM/PAW, JIT/JEA, IGA platforms (SailPoint, Saviynt), certificate lifecycle governance, and Zero Trust identity principles, with the ability to spot toxic privileges, over-permissioned service accounts, and unmanaged certificate trust chains.
  • Ability to correlate identity exposures with adversary TTPs, including certificate forgery (Golden Ticket, Golden SAML, forged smartcard auth), credential theft, dangling DNS exploitation, and map identity weaknesses into broader attack paths across infrastructure, cloud, and applications.

#LI-SS1

#hybrid

Maersk is committed to a diverse and inclusive workplace, and we embrace different styles of thinking. Maersk is an equal opportunities employer and welcomes applicants without regard to race, colour, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability, medical condition, pregnancy or parental leave, veteran status, gender identity, genetic information, or any other characteristic protected by applicable law. We will consider qualified applicants with criminal histories in a manner consistent with all legal requirements.

 

We are happy to support your need for any adjustments during the application and hiring process. If you need special assistance or an accommodation to use our website, apply for a position, or to perform a job, please contact us by emailing  [email protected]

Skills Required

  • 5-7+ years of progressive experience in enterprise cybersecurity
  • In-depth technical expertise in Threat Exposure Management, Vulnerability Management, Defensive Security, and Offensive Security
  • Experience securing Identity technologies in large-scale, heterogeneous environments
  • Understanding of vulnerability classes, exploit vectors, configuration weaknesses, and exposure patterns across Windows, Linux, network devices, cloud services, containers, applications, and OT/ICS
  • Experience performing exploitability assessments and correlating vulnerabilities with attacker behavior using MITRE ATT&CK
  • Hands-on experience with VM/CTEM tooling, authenticated scanning, asset discovery, CSPM, AppSec, ASM/EASM, enumeration, and Critically Exposed Asset validation
  • Ability to validate security data accuracy, reconcile asset mismatches, analyze trends, identify anomalies, and provide actionable insights
  • Strong knowledge of AD/Entra ID, Kerberos, NTLM, PKI, certificate chains, CRLs/OCSP, SPNs, federation, and MFA
  • Experience analyzing identity attack paths, lateral movement, privilege escalation, token abuse, SPN abuse, and certificate-related exposures
  • Proficiency with cloud and hybrid identity technologies including Azure AD/Entra, ADFS, Azure AD Connect, IAM roles, service principals, OAuth/OIDC, certificate authentication, and SCIM
  • Ability to identify cloud, DNS, API, domain federation, and identity exposure paths across Azure, AWS, and GCP
  • Knowledge of PAM/PAW, JIT/JEA, IGA platforms, certificate lifecycle governance, and Zero Trust identity principles
  • Knowledge of SailPoint and Saviynt
  • CISSP, GIAC, Microsoft Identity and Security, IGA, or PAM certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Copenhagen
58,338 Employees

What We Do

A.P. Moller - Maersk is an integrated transport and logistics company; going all the way, together, for our customers and society. ALL THE WAY is our commitment to connect the world so that everyone has both the possibility and the ability to trade, grow and thrive. The company employs roughly 110.000 employees across operations in 130 countries.

Similar Jobs

Cloudflare Logo Cloudflare

Senior Oracle Fusion Developer

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4400 Employees

JPMorganChase Logo JPMorganChase

Client Data

Financial Services
Hybrid
2 Locations
289097 Employees

ZS Logo ZS

Director - R&D Technologist

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
2 Locations
15000 Employees

TransUnion Logo TransUnion

Manager - Data Science & Analytics

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
World Trade Center, Yeshwanthpur, Bengaluru Urban, Karnataka, IND
13000 Employees

Similar Companies Hiring

Blissway Thumbnail
Computer Vision • Fintech • Hardware • Internet of Things • Machine Learning • Software • Transportation
Denver, CO
24 Employees
Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees
Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account