Senior Exposure Threat Hunter

Posted Yesterday
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Automotive • Internet of Things • Mobile • Semiconductor • Industrial
The Role
Proactively identify and validate security exposures, attack paths, misconfigurations, and control weaknesses across enterprise environments. Conduct threat hunting using SIEM, endpoint, identity, cloud, network, and threat intelligence data. Assess exploitation scenarios and business impact, collaborate on remediation, improve hunting methodologies, and tune security detections. Research emerging threats, document actionable findings, and recommend strategies to reduce attack surface and improve security posture.
Summary Generated by Built In

Job Title: Senior Exposure Threat Hunter

Location: Bangalore, India

Role Summary 

We are seeking an experienced and highly analytical Exposure Threat Hunter to join our Information Security team. This role is focused on proactively identifying, investigating, and validating security exposures, attack paths, and security weaknesses that could be leveraged by threat actors across the enterprise.

The ideal candidate will have a strong Information Security background with experience in Security Operations (SOC), Threat Hunting, Security Engineering, Detection Engineering, or Incident Response. They should understand attacker methodologies, common attack techniques, security tooling, and investigative processes, and be capable of identifying potential risks before they can be exploited.

This position requires a proactive security mindset, strong investigative skills, and the ability to bridge technical findings with actionable risk reduction strategies.

Job Responsibility 

  • Proactively identify, investigate, and validate security exposures, attack paths, misconfigurations, and control weaknesses across enterprise environments.
  • Conduct threat hunting activities to uncover potential risks, attacker opportunities, and indicators of compromise that may not be detected through traditional monitoring.
  • Analyze security telemetry, logs, identity-related data, cloud security findings, endpoint activity, and threat intelligence to identify security gaps and exploitable conditions.
  • Assess exposures from an attacker’s perspective and determine potential exploitation scenarios and business impact.
  • Leverage security tools and technologies to investigate findings and uncover relationships between assets, identities, privileges, and security controls.
  • Collaborate with Security Operations, Vulnerability Management, Engineering, Cloud Security, and Incident Response teams to validate findings and support remediation efforts.
  • Contribute to the development and improvement of exposure hunting methodologies, investigative procedures, and operational processes.
  • Assist in the creation, tuning, and optimization of detection rules and monitoring capabilities that help identify attacker behaviors and high-risk exposures.
  • Research emerging threats, attacker techniques, and industry trends to improve threat hunting and exposure management capabilities.
  • Document findings, risk assessments, recommendations, and remediation guidance in a clear and actionable manner.
  • Provide strategic recommendations to reduce organizational attack surface and improve overall security posture.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
  • Minimum 10+ years of experience in Information Security, preferably within one or more of the following areas:
    • Security Operations Center (SOC)
    • Threat Hunting
    • Security Engineering
    • Detection Engineering
    • Incident Response
  • Strong understanding of security operations processes, methodologies, and investigative workflows.
  • Solid understanding of the cyber-attack lifecycle and common attacker tactics, techniques, and procedures (TTPs).
  • Experience working with enterprise security technologies such as:
    • SIEM platforms
    • EDR/XDR solutions
    • Identity security tools
    • Cloud security platforms
    • Exposure management and attack surface management solutions
  • Knowledge of common attack techniques, including:
    • Initial access
    • Credential abuse
    • Privilege escalation
    • Persistence
    • Lateral movement
    • Defense evasion
    • Data access and exfiltration techniques
  • Experience analyzing security logs, endpoint telemetry, authentication activity, network events, and cloud-native security data.
  • Understanding security detections, alerting mechanisms, and investigative techniques.
  • Familiarity with industry frameworks and methodologies such as:
    • MITRE ATT&CK
    • Cyber Kill Chain
    • Threat Hunting methodologies
    • Risk-based prioritization approaches
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written and verbal communication skills.

Preferred Qualifications

  • Experience working within large-scale enterprise Information Security environments.
  • Experience with exposure management, attack path analysis, identity security, attack surface management, or adversary exposure validation programs.
  • Strong knowledge of SIEM platforms and security event analysis, including the ability to investigate, correlate, and analyze security telemetry from multiple data sources to identify attacker activity, security weaknesses, and emerging threats.
  • Understanding of cloud security concepts across Azure, AWS, or Google Cloud environments.
  • Experience developing, tuning, or maintaining security detections and analytics.
  • Familiarity with threat intelligence and its application within security investigations and threat hunting activities.
  • Experience working with automation or orchestration capabilities within security operations environments.

Preferred Certifications

GIAC Certified Incident Handler (GCIH)

GIAC Certified Forensic Analyst (GCFA)

GIAC Cyber Threat Intelligence (GCTI)

GIAC Certified Intrusion Analyst (GCIA)

Offensive Security Certified Professional (OSCP)

More information about NXP in India...

#LI-29f4

Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience
  • 10+ years of experience in Information Security, preferably in SOC, Threat Hunting, Security Engineering, Detection Engineering, or Incident Response
  • Strong understanding of security operations processes, methodologies, and investigative workflows
  • Solid understanding of the cyber-attack lifecycle and common attacker tactics, techniques, and procedures
  • Experience with SIEM platforms, EDR/XDR solutions, identity security tools, cloud security platforms, and exposure or attack surface management solutions
  • Knowledge of initial access, credential abuse, privilege escalation, persistence, lateral movement, defense evasion, data access, and exfiltration techniques
  • Experience analyzing security logs, endpoint telemetry, authentication activity, network events, and cloud-native security data
  • Understanding of security detections, alerting mechanisms, and investigative techniques
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, threat hunting methodologies, and risk-based prioritization
  • Strong analytical, troubleshooting, and problem-solving skills
  • Excellent written and verbal communication skills
  • Experience in large-scale enterprise Information Security environments
  • Experience with exposure management, attack path analysis, identity security, attack surface management, or adversary exposure validation programs
  • Strong knowledge of SIEM platforms and multi-source security event analysis
  • Understanding of cloud security across Azure, AWS, or Google Cloud
  • Experience developing, tuning, or maintaining security detections and analytics
  • Familiarity with threat intelligence applied to security investigations and threat hunting
  • Experience with automation or orchestration in security operations environments
  • GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), GIAC Cyber Threat Intelligence (GCTI), GIAC Certified Intrusion Analyst (GCIA), or Offensive Security Certified Professional (OSCP)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eindhoven
21,993 Employees
Year Founded: 2006

What We Do

NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer and more sustainable world through innovation. As a world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. Built on more than 60 years of combined experience and expertise, the company has approximately 34,500 employees in more than 30 countries and posted revenue of $13.21 billion in 2022. Find out more at www.nxp.com. Privacy Policy: https://www.nxp.com/company/about-nxp/privacy-policy-for-social-media-pages:PRIVACY-POLICY-SOCIAL-MEDIA

Similar Jobs

Capital One Logo Capital One

Manager, Product Management

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
55000 Employees

Capital One Logo Capital One

Manager, Corporate Communications

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
55000 Employees

Optum Logo Optum

Software Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
160000 Employees

Ericsson Logo Ericsson

Window Exchange Expert

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
88000 Employees

Similar Companies Hiring

ARB Interactive Thumbnail
Gaming • Mobile • Software
Miami, Florida
190 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account