Cyber Security - Exposure Management Specialist x 3
Salary: Competitive Remuneration
Our enterprise client is seeking multiple Senior Cyber Exposure Management Specialists to join its Cyber Security team. These roles focus on identifying, assessing, and reducing cyber risk across complex enterprise environments. Operating across both external attack surfaces and internal technology environments, Specialists will ensure security exposures are discovered early, accurately prioritised, and remediated effectively.
Working closely with engineering, infrastructure, cloud, and security teams, you will bring a threat-informed approach to exposure management, helping the organisation stay ahead of emerging vulnerabilities, exploitation campaigns, and evolving attack techniques.
Key Responsibilities
- Continuously identify, assess, and prioritise cyber exposures across enterprise technology environments, including infrastructure, cloud, applications, APIs, and internet-facing assets.
- Maintain visibility of the organisation's attack surface through ongoing discovery, validation, and investigation of exposed services, systems, and technology assets.
- Drive vulnerability and exposure management activities from assessment through to remediation, working closely with asset owners and engineering teams.
- Prioritise remediation efforts using threat intelligence, exploitability, business impact, asset criticality, and attack path analysis.
- Lead the response to significant exposure events, including critical vulnerabilities, large-scale exploitation campaigns, and emerging threats.
- Validate high-risk findings and assess the effectiveness of security controls through technical analysis and exposure verification activities.
- Partner with security operations, threat detection, incident response, and engineering teams to improve overall cyber resilience.
- Contribute to the continuous improvement of exposure management processes, tooling, automation, reporting, and operational maturity.
Requirements
- Strong hands-on experience in exposure management, vulnerability management, attack surface management, or offensive security within a large enterprise environment.
- Proven ability to prioritise security risks based on exploitability, business context, threat intelligence, and operational impact rather than severity ratings alone.
- Strong technical knowledge across infrastructure, cloud platforms, applications, containers, APIs, identity services, and modern engineering environments.
- Practical experience with vulnerability assessment, attack surface discovery, security scanning, and exposure management platforms.
- Strong analytical and investigative skills, with the ability to assess technical risk and communicate recommendations clearly to both technical and non-technical stakeholders.
Desirable Skills & Experience
- Hands-on experience with external attack surface management (EASM) and asset discovery platforms such as Tenable, Qualys, Rapid7, runZero, or similar technologies.
- Exposure to cloud security, identity security, software supply chain risk, and modern DevSecOps practices.
- Experience supporting the response to large-scale vulnerability campaigns, supply chain incidents, or enterprise-wide remediation initiatives.
- Knowledge of threat intelligence sources and frameworks used to assess emerging cyber risks and exploitation trends.
Peoplebank and Leaders IT are committed to creating a diverse and inclusive workplace where everyone belongs. We welcome applications from people of all backgrounds, identities, and experiences. If you need adjustments to the recruitment process due to your circumstances, please let us know—we’re here to support you.