Applied Materials
Posted 1mo ago

Cybersecurity Analyst – Attack Surface Management & Attack Path Analysis

Applied Materials
Bengaluru, Karnataka, India
OnsiteFull Time
Responsibilities
  • discovering assets
  • modeling paths
  • prioritizing remediation
Requirements
  • Bachelor's degree and 5+ years in cybersecurity with hands-on EASM/CAASM
  • Attack path modeling
  • Cloud experience (AWS/Azure/GCP)
  • Python scripting
  • MITRE ATT&CK knowledge, and strong communication
Technical tools mentioned
EASMCAASMMITRE ATT&CKPythonAWSAzureGCPREST APIs

Job description

Who We Are

Applied Materials is a global leader in materials engineering solutions used to produce virtually every new chip and advanced display in the world. We design, build and service cutting-edge equipment that helps our customers manufacture display and semiconductor chips – the brains of devices we use every day. As the foundation of the global electronics industry, Applied enables the exciting technologies that literally connect our world – like AI and IoT. If you want to push the boundaries of materials science and engineering to create next generation technology, join us to deliver material innovation that changes the world. 

What We Offer

Location:

Bangalore,IND

You’ll benefit from a supportive work culture that encourages you to learn, develop, and grow your career as you take on challenges and drive innovative solutions for our customers. We empower our team to push the boundaries of what is possible—while learning every day in a supportive leading global company. Visit our Careers website to learn more. 

At Applied Materials, we care about the health and wellbeing of our employees. We’re committed to providing programs and support that encourage personal and professional growth and care for you at work, at home, or wherever you may go. Learn more about our benefits

Key Responsibilities 

Attack Surface Management 

  • Own and continuously evolve the enterprise external attack surface inventory — internet-facing assets, domains, IP ranges, cloud services, third-party integrations, and shadow IT 

  • Proactively discover unauthorized, unmanaged, or impersonation-related assets and investigate exposed services, SSL/TLS and DNS misconfigurations, open ports, cloud storage exposure, and leaked credentials surfaced through EASM tooling 

  • Track assets across the full discovery-to-remediation lifecycle and maintain authoritative records in the CAASM platform 

Attack Path Analysis & Threat Exposure Modeling 

  • Model attack paths across hybrid on-premises, cloud, and identity infrastructure (Active Directory, Entra ID, cloud IAM) using graph-based tooling to expose lateral movement and privilege escalation opportunities 

  • Prioritize remediation by attack path criticality, asset business value, and exploitability — beyond CVSS — and identify choke points whose remediation eliminates the greatest number of paths 

  • Partner with red team, purple team, and breach-and-attack simulation engagements to validate models, mapping findings to MITRE ATT&CK and CTEM program metrics 

Asset Intelligence & CAASM 

  • Build and maintain a unified, authoritative asset view by integrating telemetry across endpoints, cloud APIs, network scanners, CMDBs, and identity directories, enriched with criticality ratings and business ownership 

  • Drive asset criticality modeling and support EPM governance so the Vulnerability & Exposure Management team can prioritize remediation by business impact, not volume 

Automation, Analytics & Reporting 

  • Build dashboards for attack surface posture, attack path risk, remediation velocity, and security KPIs for operational and executive audiences 

  • Develop scripting and automation (Python, REST APIs) and apply AI-assisted analytics to improve data collection, enrichment, risk correlation, and predictive risk signals 

  • Produce posture reports and executive summaries, and manage cybersecurity exceptions, risk acceptances, and governance documentation per policy 

Cross-Functional Partnership 

  • Serve as the subject-matter expert on attack surface and attack path topics during architecture reviews, onboarding, and risk assessments, partnering with Vulnerability & Exposure Management, Cloud Security, Network, SOC, Application Security, and Governance teams to drive end-to-end risk reduction 

  • Communicate technical risk findings and remediation recommendations clearly to both technical teams and non-technical business stakeholders 

 

 

Required Qualifications 

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, or a related field 

  • 5+ years of progressive experience in Cybersecurity, Security Operations, Vulnerability/Exposure Management, or Attack Surface Management 

  • Hands-on experience across EASM (asset discovery and exposure analysis), CAASM (asset data integration and unified inventory), attack path / attack graph modeling across hybrid environments, and exposure-based prioritization that goes beyond basic CVSS 

  • Working knowledge of MITRE ATT&CK adversary techniques (initial access, lateral movement, privilege escalation, persistence) 

  • Hands-on experience with cloud environments (AWS, Azure, or GCP) and cloud-specific exposure risks (storage misconfigurations, IAM over-privilege, exposed APIs) 

  • Proficiency in scripting for automation and data analysis (Python preferred) and integrating security tools via APIs to build dashboards and workflows 

  • Strong written and verbal communication; able to translate technical risk into clear business language for senior stakeholders 

 

Certifications (Preferred) 

  • CISSP, CISM, or CISA 

  • Offensive/exposure-focused: CEH, OSCP, or GIAC (GPEN, GWAPT, GCIH) 

  • Cloud security: AWS Security Specialty, Microsoft AZ-500, or (ISC)² CCSP

Additional Information

Time Type:

Full time

Employee Type:

Assignee / Regular

Travel:

Yes, 10% of the Time

Relocation Eligible:

Yes

Applied Materials is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, national origin, citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other basis prohibited by law.

About Applied Materials

Manufacturers of equipment for semiconductor and display production.

Similar jobs

Cybersecurity Analyst roles near Bengaluru, Karnataka
3d
Save
Mark Applied
Hide
CYBER SECURITY ANALYST L4
Bengaluru, Karnataka, India
OnsiteFull Time
Wipro
WiproNYSE: WIT: Global technology services and consulting for digital transformation.
5+ YOERequires 5–8 years of experience and AI security expertise, with responsibilities spanning threat analysis, incident response, forensic analysis, disaster recovery, compliance, and audit readiness.
AI Security
3d
Save
Mark Applied
Hide
GMS-Senior-SEG-DAG
Bengaluru, Karnataka, India
OnsiteFull Time
EY
EY: Global firm providing audit, tax, and professional consulting services.
4+ YOERequires 4+ years in cybersecurity, email security, or data security; hands-on Proofpoint, Microsoft Defender for Office 365, Exchange Online Protection, and Varonis experience; strong security operations and governance skills.
Proofpoint Email Protection, Microsoft Defender for Office 365, Exchange Online Protection (EOP), Varonis Data Security Platform, Microsoft 365, SIEM, SPF, DKIM, DMARC
3d
Save
Mark Applied
Hide
Cybersecurity Analyst
Bengaluru, Karnataka, India
OnsiteFull Time
Smiths Group
Smiths GroupLondon Stock Exchange: SMIN: Engineers specialized technologies for energy, security, and aerospace markets.
2+ YOERequires 2–4 years in SOC or security operations, SIEM and endpoint security expertise, incident response, threat and log analysis, alert triage, MITRE ATT&CK familiarity, and strong communication skills.
SIEM, EDR, MITRE ATT&CK, Rapid7
2w
Save
Mark Applied
Hide
Cybersecurity Sr. Analyst
Bangalore, Karnataka, India
OnsiteFull Time
Unisys
UnisysNYSE: UIS: Provides enterprise-scale IT services and digital transformation solutions.
Bachelor's degree or equivalent combination of education and experience, plus 4–6 years of relevant experience in cybersecurity analysis.
2w
Save
Mark Applied
Hide
Cyber Security Lead Analyst - (2600099R)
Bangalore, Karnataka, India
OnsiteFull Time
CGI
CGINYSE: GIB: Provides information technology and business consulting services.
7+ YOEBachelor's in computer science or related, 7+ years IT experience, expertise in Tanium, WAF and firewall review, DLP analysis, Databricks/DBX data engineering skills, scripting (Python/Linux Shell/VBS), and strong communication and stakeholder management.
Tanium, CloudProtector, Azure WAF, Symantec Endpoint Protection, DLP, Python, Linux Shell, VBS, Databricks, Delta Lake, PySpark, Spark SQL, Unity Catalog, SQL Warehouse, AWS, Azure, CI/CD, MLFlow, DBX
1mo
Save
Mark Applied
Hide
Sr Cybersecurity Analyst
Bengaluru, Karnataka, India
HybridFull Time
Dexcom
DexcomNasdaq: DXCM: Manufacturer of continuous glucose monitoring systems for diabetes management.
3+ YOEBachelor's or equivalent,3+ years cybersecurity/IT operations experience,enterprise IT fundamentals,secure configuration and vulnerability remediation,PowerShell/Python/Bash scripting,Agile/Jira experience,strong communication.
Windows, Linux, Active Directory, Microsoft Entra ID, PowerShell, Python, Bash, Jira, CASB, SWG, DLP, IAM, PAM
1mo
Save
Mark Applied
Hide
Sr Cybersecurity Analyst
Bengaluru, Karnataka, India
OnsiteFull Time
Dexcom
DexcomNASDAQ: DXCM: Develops continuous glucose monitoring systems for diabetes management.
3+ YOE3+ years cybersecurity or related IT experience, bachelor’s in a technical field or equivalent, experience with enterprise hardening, vulnerability remediation, identity and access controls, scripting/automation, and security toolsets.
Windows, Linux, Active Directory, Entra ID, PowerShell, Python, Bash, Jira, CASB, SWG, DLP, IAM, PAM, SaaS
1mo
Save
Mark Applied
Hide
Cybersecurity
Bengaluru, Karnataka, India
OnsiteFull Time
Tata Consultancy Services
Tata Consultancy ServicesNational Stock Exchange of India: TCS: Global provider of IT services, consulting, and business solutions.
7+ YOEDesign, implement and manage IAM and PAM solutions on Azure/AWS; SIEM expertise; support incident response for CyberArk PAM; strong collaboration and knowledge sharing; Bachelor of Engineering required.
Azure, AWS, SIEM, CyberArk