← Back to Directory
This position has been filled. Applications are no longer being accepted.

External Attack Surface Management Analyst

BAE Systems · Frimley, UK
Clearance Level
BPSS
Salary Range
Competitive
Employment Type
FULL TIME
Work Style
onsite

// Role Summary

Join BAE Systems as an External Attack Surface Management Analyst to bolster our cyber defenses by identifying, assessing, and testing external vulnerabilities. This role is crucial for ensuring our security controls are effective and aligned with organizational standards.

// Key Responsibilities

  • Proactively discover and track external attack surface assets, including shadow IT.
  • Investigate and validate externally visible exposures for real-world risk.
  • Monitor changes in external exposure and emerging risks.
  • Collaborate with Threat Intelligence and Cyber Operations for aligned remediation.
  • Produce clear, actionable reports on external exposures and security posture.
  • Utilize OSINT and reconnaissance techniques to identify internet-facing assets.

// Role Specification

About the Role

Join BAE Systems' Cyber Operations team and play a vital role in safeguarding our organisation against evolving cyber threats. You will enhance our External Attack Surface Management (EASM) capability across people, process, and technology, contributing to an intelligence-led approach to cyber operations.

This role focuses on identifying, assessing, and continuously testing external assets to ensure they are secure. You will support detection assurance by uncovering shadow IT and unmanaged exposures, providing leadership with confidence in the effectiveness of our security controls and monitoring capabilities.

Core Duties

  • Proactively discover, track, and maintain visibility of external attack surface assets, including unknown and shadow IT exposures.
  • Investigate and validate externally visible exposures, assessing real-world risk, attacker relevance, and exploitability.
  • Monitor changes in external exposure, identifying new assets, regressions, and emerging risks across the estate.
  • Collaborate with Threat Intelligence and Cyber Operations to align exposure findings with attacker activity and remediation priorities.
  • Produce clear, actionable reporting on external exposures, trends, and security posture to support risk reduction and decision-making.

Essential Skills and Experience

  • Good understanding of external reconnaissance techniques, OSINT, and how attackers identify and profile internet-facing assets.
  • Proven experience in attack surface discovery, asset enumeration, and identifying unknown or shadow IT exposures.
  • A strong investigative mindset with the ability to analyse incomplete or ambiguous external data and determine genuine security risk.
  • Ability to assess and distinguish between observed external artefacts, misconfigurations, and true exploitable exposures from an attacker’s perspective.
  • Experience working with internet-facing protocols and data sources (e.g., DNS, HTTP, TLS, certificate transparency, scanning datasets) to identify patterns, relationships, and anomalies.

About BAE Systems Cyber Operations

The Cyber Operations team is dedicated to protecting BAE Systems and its employees from cyber attacks by various threat actors. Indirectly, we contribute to protecting those who protect us, including military personnel who rely on our products and services. Through Threat Intelligence, Detection, Incident Response, and Active Defence, we continuously evolve our cyber operations into a world-class capability.

Working at BAE Systems

Build a career with purpose and limitless possibilities. We offer lifelong learning, meaningful work, and a supportive culture where you can grow with confidence. You will be recognised for your contributions and enjoy rewards tailored to your needs, supporting your financial and personal wellbeing, and promoting a balanced lifestyle. Embrace sustainable ways of working in an environment with a strong sense of shared purpose, where you can feel you belong and be proud of the difference you make.

Inclusivity at BAE Systems

We are committed to building an inclusive workplace where everyone feels valued and supported. We believe that a diversity of backgrounds, perspectives, and experiences strengthens our teams and is vital to the work we do.

Security and Export Control Restrictions

Please be aware that many roles at BAE Systems are subject to security and export control restrictions. These restrictions may impact your eligibility for certain roles based on factors such as your nationality, previous nationalities, and place of birth. All applicants must achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting, typically requiring 5 to 10 years of continuous residency in the UK, depending on the vetting level.

Location and Working Arrangements

This role is based in Preston or Frimley with a hybrid working model, requiring 2 days a month onsite. We offer a range of hybrid and flexible working arrangements; please discuss the specific options for this role with your recruiter.

Salary

Circa £45,000, depending on skills and experience.

Closing Date

14th July 2026. We reserve the right to close this vacancy early if sufficient applications are received.