Attack Surface Management Analyst

Attack Surface Management Analyst

Full-Time 55000 - 65000 £ / year (est.) Home office (partial)
easyJet Airline Company PLC

At a Glance

  • Tasks: Identify and reduce cyber exposures across easyJet's technology landscape.
  • Company: Join easyJet, Europe's iconic low-cost airline with a mission to make travel easy.
  • Benefits: Enjoy a competitive salary, bonus, flexible benefits, and excellent staff travel perks.
  • Other info: Hybrid working environment with a focus on collaboration and career growth.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: Experience in vulnerability management and strong analytical skills required.

The predicted salary is between 55000 - 65000 £ per year.

We are easyJet – a FTSE listed, £multi-billion low-cost airline that serves tens of millions of customers every single year. We fly more than 1,207 routes, connecting 38 countries across Europe, and employ more than 18,000 colleagues. We’re on a mission to make low-cost travel easy – and whatever your role here, you’ll connect millions of people to what they love using Europe’s best airline network, great value fares, and friendly service.

What makes us easyJet?

Our Promise Behaviours - we are Safe, Bold, Welcoming and Challenging. Four Behaviours. One Spirit. One easyJet.

Read on if you:

  • Have experience in vulnerability management, attack surface management or cybersecurity
  • Enjoy solving complex security challenges and reducing cyber risk
  • Thrive in a fast‑paced, collaborative environment
  • Are passionate about emerging technologies and secure innovation
  • Want to make a real impact across a large, complex digital estate

The Team

You’ll join the Attack Surface Management (ASM) team within easyJet’s Cyber Threat Exposure Management (CTEM) function. The team is focused on identifying, validating and reducing cyber exposures across cloud, on‑prem and third‑party environments. Working closely with Cyber Threat Intelligence, Advanced Threat Protection, SOC, Engineering and business teams, you’ll help deliver threat‑led vulnerability management and measurable risk reduction across the organisation.

The Role

As an Attack Surface Management Analyst, you’ll play a key role in helping easyJet identify and reduce cyber exposures across our technology landscape. You’ll turn vulnerability and exposure data into clear, prioritised actions and work closely with stakeholders across technology and the wider business to drive remediation and reduce risk. You’ll also support the development of vulnerability management capabilities in emerging technology areas, including AI‑enabled systems, helping ensure new technologies are deployed securely and responsibly.

Key responsibilities include:

  • Identifying, validating and assessing exposures across cloud, on‑prem and third‑party assets
  • Triaging vulnerabilities and prioritising remediation based on threat, exploitability and business impact
  • Partnering with IT, Engineering and business teams to drive remediation through to resolution
  • Tracking remediation activity and helping remove blockers to progress
  • Supporting analysis of recurring vulnerabilities and exposure trends to reduce repeat issues
  • Helping improve secure build and deployment practices across the software development lifecycle
  • Supporting the identification and management of vulnerabilities within AI‑enabled systems and supporting pipelines
  • Assisting with vulnerability disclosure programme submissions and remediation workflows
  • Producing clear reporting and dashboards on vulnerability trends and remediation progress
  • Supporting the effective use and optimisation of vulnerability management and CNAPP tooling
  • Collaborating across Cyber Threat Exposure Management teams to strengthen detection and response capabilities

Requirements of the Role

What we’re looking for:

  • Understanding of cloud environments including AWS, Azure and GCP, and associated security risks
  • Knowledge of common security exposures such as misconfiguration, identity risk, secrets exposure and API security
  • Familiarity with vulnerability management tooling and/or CNAPP platforms
  • Strong analytical, communication and problem‑solving skills
  • Understanding of vulnerability scoring, prioritisation and remediation processes
  • Ability to build strong working relationships across multidisciplinary teams
  • A proactive mindset and confidence working in a dynamic environment

Desirable experience:

  • Experience within vulnerability management, attack surface management or a related cybersecurity field
  • Knowledge of frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Awareness of security and compliance standards such as PCI‑DSS
  • Relevant security certifications including GIAC, AWS or CompTIA
  • Experience with application security testing tools such as SAST or DAST

What you’ll get in return:

  • Up to 20% bonus
  • 25 days holiday
  • BAYE, SAYE and Performance Share schemes
  • PMI Life assurance
  • Flexible benefits package
  • Excellent staff travel benefits

Practicalities

This is a full‑time position. We support hybrid working and spend time together as a team in our Luton HQ offices.

Reasonable adjustments

At easyJet, we are dedicated to fostering an inclusive workplace that reflects the diverse customers we serve across Europe. We welcome candidates from all backgrounds. If you require specific adjustments or support during the application or recruitment process, such as extra time for assessments or accessible interview locations, please contact us at ma.recruitment@easyjet.com. We are committed to providing reasonable adjustments throughout the recruitment process to ensure accessibility and accommodation.

Attack Surface Management Analyst employer: easyJet Airline Company PLC

At easyJet, we pride ourselves on being a dynamic and inclusive employer that values innovation and collaboration. As an Attack Surface Management Analyst, you'll be part of a forward-thinking team dedicated to enhancing cybersecurity across our extensive digital landscape, with opportunities for professional growth and development in a supportive environment. Enjoy competitive benefits, including flexible working arrangements and excellent staff travel perks, all while contributing to our mission of making low-cost travel easy for millions.

easyJet Airline Company PLC

Contact Details:

easyJet Airline Company PLC Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Attack Surface Management Analyst

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including easyJet Airline Company PLC, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through easyJet Airline Company PLC

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at easyJet Airline Company PLC. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Attack Surface Management Analyst

Vulnerability Management
Attack Surface Management
Cybersecurity
Cloud Environments (AWS, Azure, GCP)
Security Risk Assessment
Vulnerability Scoring and Prioritisation
Analytical Skills

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at easyJet Airline Company PLC insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to easyJet Airline Company PLC that you’re committed to staying ahead in the game.

How to prepare for a job interview at easyJet Airline Company PLC

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at easyJet Airline Company PLC to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at easyJet Airline Company PLC.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.