or apply directly on Uvcyber's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 13 days Uvcyber's roles stay open a median of 44 days
- Reposted
- No
- Salary listed
- No 0% of Uvcyber's roles list one
- Ghost-job risk at Uvcyber
- low 0 stale, 0 reposted of 26 open
- Hiring momentum
- 34 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from Uvcyber's own lever board since 2026-08-04. Full hiring picture for Uvcyber.
About this role
The Security Analyst in Attack Surface Management will focus on validating vulnerabilities identified through various sources, including red team tests and bug bounty submissions. The role involves assessing the impact of these vulnerabilities, tracking their remediation, and collaborating with engineering teams to ensure timely resolution. Additionally, the analyst will document findings and provide clear remediation guidance while maintaining visibility into the organization's attack surface.
- benefits
- 1/5
- freshness
- 4/5
- career value
- 4/5
- role clarity
- 4/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of Uvcyber as an employer.
What you need
- Two or more years in application security, vulnerability management, penetration testing, or bug bounty work.
- Working proficiency in web application and API penetration testing.
- Practical knowledge of OWASP Top 10 and OWASP API Security Top 10.
- Familiarity with MITRE ATT&CK techniques.
- Severity determination beyond a CVSS calculator.
- Hands-on experience with Burp Suite and standard web and API testing tooling.
Nice to have
- Demonstrated bug bounty track record on Bugcrowd, HackerOne, or Intigriti.
- Experience triaging submissions from the program side.
- Cloud security exposure across AWS or Azure.
- Certifications such as BSCP, OSWA, OSCP, CPTS, or PNPT.
- Scripting in Python for reproduction harnesses and finding automation.
Worth weighing
- This role is not focused on applying patches, which may limit hands-on technical remediation experience.
- The position requires strong communication skills to convince engineering teams of the validity and importance of findings.
- No specific benefits or compensation details are provided in the posting.
Summarised from Uvcyber's posting. Read the full original.
Listed by Uvcyber on their lever job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at Uvcyber
- Systems Administrator (RHEL)Herndon, VA
- Senior Security Engineer - SplunkNational Harbor, MD
- Principal Cyber Security Solutions ArchitectNational Harbor, MD
- Automation Data Integration EngineerWashington, DC
- Senior Cybersecurity Incident Response SpecialistHyderabad
- Senior SOC Analyst | MDRRemote