Talent.com
easyJet Airline Company PLC
Attack Surface Management AnalysteasyJet Airline Company PLC • Luton, England, UK
Attack Surface Management Analyst

Attack Surface Management Analyst

easyJet Airline Company PLC • Luton, England, UK
11 days ago
Job type
  • Full-time
Job description

Job Description – Attack Surface Management Analyst (17023)

We are easyJet – a FTSE listed, £multi-billion low-cost airline that serves tens of millions of customers every single year. If you’re reading this, you have probably already been an easyJet customer, and you’ll know that there is no more iconic (or Orange!) travel brand in Europe.

We fly more than 1,207 routes, connecting 38 countries across Europe, and employ more than 18,000 colleagues. We’re on a mission to make low-cost travel easy – and whatever your role here, you’ll connect millions of people to what they love using Europe’s best airline network, great value fares, and friendly service.

What makes us easyJet?

Our Promise Behaviours - we are Safe, Bold, Welcoming and Challenging. Four Behaviours. One Spirit. One easyJet.

Read on if you

  • Have experience in vulnerability management, attack surface management or cybersecurity
  • Enjoy solving complex security challenges and reducing cyber risk
  • Thrive in a fast‑paced, collaborative environment
  • Are passionate about emerging technologies and secure innovation
  • Want to make a real impact across a large, complex digital estate

The Team

You’ll join the Attack Surface Management (ASM) team within easyJet’s Cyber Threat Exposure Management (CTEM) function. The team is focused on identifying, validating and reducing cyber exposures across cloud, on‑prem and third‑party environments.

Working closely with Cyber Threat Intelligence, Advanced Threat Protection, SOC, Engineering and business teams, you’ll help deliver threat‑led vulnerability management and measurable risk reduction across the organisation.

The Role

As an Attack Surface Management Analyst, you’ll play a key role in helping easyJet identify and reduce cyber exposures across our technology landscape. You’ll turn vulnerability and exposure data into clear, prioritised actions and work closely with stakeholders across technology and the wider business to drive remediation and reduce risk.

You’ll also support the development of vulnerability management capabilities in emerging technology areas, including AI‑enabled systems, helping ensure new technologies are deployed securely and responsibly.

Key responsibilities include:

  • Identifying, validating and assessing exposures across cloud, on‑prem and third‑party assets
  • Triaging vulnerabilities and prioritising remediation based on threat, exploitability and business impact
  • Partnering with IT, Engineering and business teams to drive remediation through to resolution
  • Tracking remediation activity and helping remove blockers to progress
  • Supporting analysis of recurring vulnerabilities and exposure trends to reduce repeat issues
  • Helping improve secure build and deployment practices across the software development lifecycle
  • Supporting the identification and management of vulnerabilities within AI‑enabled systems and supporting pipelines
  • Assisting with vulnerability disclosure programme submissions and remediation workflows
  • Producing clear reporting and dashboards on vulnerability trends and remediation progress
  • Supporting the effective use and optimisation of vulnerability management and CNAPP tooling
  • Collaborating across Cyber Threat Exposure Management teams to strengthen detection and response capabilities

Requirements of the Role

What we’re looking for

  • Understanding of cloud environments including AWS, Azure and GCP, and associated security risks
  • Knowledge of common security exposures such as misconfiguration, identity risk, secrets exposure and API security
  • Familiarity with vulnerability management tooling and/or CNAPP platforms
  • Strong analytical, communication and problem‑solving skills
  • Understanding of vulnerability scoring, prioritisation and remediation processes
  • Ability to build strong working relationships across multidisciplinary teams
  • A proactive mindset and confidence working in a dynamic environment

Desirable experience

  • Experience within vulnerability management, attack surface management or a related cybersecurity field
  • Knowledge of frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Awareness of security and compliance standards such as PCI‑DSS
  • Relevant security certifications including GIAC, AWS or CompTIA
  • Experience with application security testing tools such as SAST or DAST

What you’ll get in return

  • Up to 20% bonus
  • 25 days holiday
  • BAYE, SAYE and Performance Share schemes
  • PMI
  • Life assurance
  • Flexible benefits package
  • Excellent staff travel benefits

Practicalities

This is a full‑time position. We support hybrid working and spend time together as a team in our Luton HQ offices.

Reasonable adjustments

At easyJet, we are dedicated to fostering an inclusive workplace that reflects the diverse customers we serve across Europe. We welcome candidates from all backgrounds. If you require specific adjustments or support during the application or recruitment process, such as extra time for assessments or accessible interview locations, please contact us at ma.recruitment@easyjet.com. We are committed to providing reasonable adjustments throughout the recruitment process to ensure accessibility and accommodation.

#J-18808-Ljbffr
Create a job alert for this search

Attack Surface Management Analyst • Luton, England, UK

Similar jobs

Security Analyst III - Identity & Access Management (Cloud Governance)

Tesco UKWelwyn Garden City, England, GB
Full-time

In this role you are responsible for both continually improving the insight in your area of specialism and working across teams to step change approaches and tooling as required to achieve security... Show more

 • Promoted

Security Analyst III - Identity & Access Management (Cloud Governance)

Tesco TechnologyWelwyn Garden City, England, GB
Full-time

In this role you are responsible for continually improving the insight in your area of specialism and working across teams to step change approaches and tooling as required to achieve security outc... Show more

 • Promoted

Senior Messaging IT Analyst: Exchange & Security Automation

Parker HannifinDacorum, England, GB
Full-time

Parker Hannifin in Dacorum is looking for a Messaging Senior Analyst to lead administration and improvement of their enterprise messaging environment.This role requires expertise in Microsoft Excha... Show more

 • Promoted

Security Analyst III - Identity & Access Management (Cloud Governance)

TescoWelwyn Garden City, England, GB
Full-time

Tesco UK • Welwyn Garden City • Hybrid • Full‑Time • Working hours 36.In this role you are responsible for continually improving insight in your area of specialism and collaborating across teams to... Show more

 • Promoted

Security Analyst III - Identity & Access Management (Cloud Governance)

Tesco - CorporateWelwyn Garden City, England, GB
Full-time

Tesco UK • Welwyn Garden City • Hybrid • Full‑Time • Working hours 36.In this role you are responsible for continually improving insight in your area of specialism and collaborating across teams to... Show more

 • Promoted

Hybrid Network & Security Architect (DV Clearance)

MBDA UK LtdStevenage, England, GB
Full-time

MBDA UK Ltd in Stevenage is seeking a Network Architect to contribute to secure project designs and management.This role involves working on various projects, from inception through to delivery, of... Show more

 • Promoted

DV-Cleared SOC Shift Lead — Critical Infra Monitoring

Searchability NS&DWatford, England, GB
Full-time

A cybersecurity firm is seeking an experienced SOC Shift Lead in Watford to lead a team focused on critical national infrastructure.Responsibilities include directing SOC Analysts, enhancing detect... Show more

 • Promoted

M365 Core-view Architect

CognizantWatford, England, GB
Full-time

Excellent opportunity for M365 Core-view Architect to be part of our Cloud Infrastructure & Security services practice.Cognizant Infrastructure Services – Provides IT infrastructure & Cloud service... Show more

 • Promoted

Senior Geotechnical Engineer

Kier GroupSaint Neots, ENG, GB
Full-time +1

We're looking for a Senior Geotechnical Engineer to join our East West Rail team based in St Neots, Cambridgeshire.Location: St Neots, Cambridgeshire hybrid workingHours: Permanent Fulltime 45 ... Show more

 • Promoted

Lead SOC Analyst – 24/7 Threat Hunting & Response

Sopra SteriaHemel Hempstead, England, GB
Full-time

Sopra Steria is seeking a Lead SOC Analyst to head a 24/7 Security Operations Centre in the UK.You will remain hands‑on while guiding investigations, incident response and threat hunting across mul... Show more

 • Promoted

SOC Analyst

Techtrace PartnersLetchworth, England, GB
Full-time

South of England | On-Site | British Citizens Only | Shift-Based | Open to Relocators |.Must be eligible for DV Clearence.Step into a mission-critical cyber defence environment where every alert, a... Show more

 • Promoted

Secure Network Architect – High-Assurance & Cloud

Electus Recruitment SolutionsStevenage, England, GB
Full-time

Electus Recruitment Solutions in the United Kingdom is seeking a Senior Network Architect to own secure network architecture across defence programmes, shaping decisions from concept to delivery, w... Show more

 • Promoted

Attack Surface Management Analyst

easyJet Airline Company PLCLuton, England, GB
Full-time

Job Description – Attack Surface Management Analyst (17023).We are easyJet – a FTSE listed, £multi-billion low-cost airline that serves tens of millions of customers every single year.If you’re rea... Show more

 • Promoted

Infrastructure Security Engineer

COMPUTACENTER (UK) LIMITEDHatfield, ENG, GB
Full-time

Security Cleared - 3rd Line Support Analyst Wintel AD.Competitive Salary + on-call, + overtime + comprehensive and flexible benefits.Hatfield, Nottingham or Milton Keynes (full-time in office).Must... Show more

 • Promoted

Asbestos Surveyor, Analyst, P402, P403, P404, COR7521

Corriculo LtdStevenage, ENG, GB
Full-time

Asbestos Surveyor, Analyst, P402, P403, P404, COR7521The RoleThis is an excellent opportunity for an experienced Asbestos Surveyor / Analyst to join a company with a growing reputation in the envir... Show more

 • Promoted

Hybrid Network Engineer – Defence Proving & Integration

MBDA UKStevenage, England, GB
Full-time

MBDA UK is seeking a Networking and IT Engineer – Proving and Integration (Missiles) to design and maintain secure trials networks that underpin our advanced missile systems.The role combines hands... Show more

 • Promoted

Senior Security Platform Engineer (m/f/d)

NTT Global Data CentersDacorum, England, GB
Full-time

The Senior Security Platform Engineer (m/f/d), is an advanced subject matter expert, responsible for facilitating problem resolution and mentoring for the overall Global Data Centers Office of Info... Show more

 • Promoted

Remote IT Access Engineer — Cloud & On-Prem Security

SikaWelwyn Garden City, England, GB
Remote
Full-time

A global specialty chemicals company is seeking an IT Access Engineer to automate and improve their access management solution for a custom-built R&D data platform.The role, designed for remote wor... Show more

 • Promoted

Network and Security Architect

MBDAStevenage, England, GB
Full-time

Do you have a Network architecture background and looking for your next challenge?.Circa £65,000 depending on experience.British Citizen able to achieve DV.Restrictions and/or limitations relating ... Show more

 • Promoted

Director of Cloud Engineering - Lead Global Cloud, Remote

OAGLuton, England, GB
Remote
Full-time

OAG is seeking an experienced Director of Cloud Engineering in the UK to lead a distributed team and drive cloud strategy.The ideal candidate has proven experience in scaling distributed teams, str... Show more