Senior Exposure Threat Hunter

Posted 15 Days Ago
Be an Early Applicant
Oak Hill, Austin, TX, USA
In-Office
Senior level
Automotive • Internet of Things • Mobile • Semiconductor • Industrial
The Role
Conduct proactive threat hunting and exposure validation across enterprise environments. Investigate attack paths, misconfigurations, identity risks, cloud findings, endpoint activity, logs, and threat intelligence to identify exploitable security weaknesses. Assess attacker techniques and business impact, support detection engineering, collaborate on remediation, research emerging threats, and provide actionable recommendations to reduce attack surface and improve security posture.
Summary Generated by Built In

Job Title: Senior Exposure Threat Hunter

Location: Austin, USA

Role Summary 

We are seeking an experienced and highly analytical Exposure Threat Hunter to join our Information Security team. This role is focused on proactively identifying, investigating, and validating security exposures, attack paths, and security weaknesses that could be leveraged by threat actors across the enterprise.

The ideal candidate will have a strong Information Security background with experience in Security Operations (SOC), Threat Hunting, Security Engineering, Detection Engineering, or Incident Response. They should understand attacker methodologies, common attack techniques, security tooling, and investigative processes, and be capable of identifying potential risks before they can be exploited.

This position requires a proactive security mindset, strong investigative skills, and the ability to bridge technical findings with actionable risk reduction strategies.

Job Responsibility 

  • Proactively identify, investigate, and validate security exposures, attack paths, misconfigurations, and control weaknesses across enterprise environments.
  • Conduct threat hunting activities to uncover potential risks, attacker opportunities, and indicators of compromise that may not be detected through traditional monitoring.
  • Analyze security telemetry, logs, identity-related data, cloud security findings, endpoint activity, and threat intelligence to identify security gaps and exploitable conditions.
  • Assess exposures from an attacker’s perspective and determine potential exploitation scenarios and business impact.
  • Leverage security tools and technologies to investigate findings and uncover relationships between assets, identities, privileges, and security controls.
  • Collaborate with Security Operations, Vulnerability Management, Engineering, Cloud Security, and Incident Response teams to validate findings and support remediation efforts.
  • Contribute to the development and improvement of exposure hunting methodologies, investigative procedures, and operational processes.
  • Assist in the creation, tuning, and optimization of detection rules and monitoring capabilities that help identify attacker behaviors and high-risk exposures.
  • Research emerging threats, attacker techniques, and industry trends to improve threat hunting and exposure management capabilities.
  • Document findings, risk assessments, recommendations, and remediation guidance in a clear and actionable manner.
  • Provide strategic recommendations to reduce organizational attack surface and improve overall security posture.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
  • Minimum 5 years of experience in Information Security, preferably within one or more of the following areas:
    • Security Operations Center (SOC)
    • Threat Hunting
    • Security Engineering
    • Detection Engineering
    • Incident Response
  • Strong understanding of security operations processes, methodologies, and investigative workflows.
  • Solid understanding of the cyber-attack lifecycle and common attacker tactics, techniques, and procedures (TTPs).
  • Experience working with enterprise security technologies such as:
    • SIEM platforms
    • EDR/XDR solutions
    • Identity security tools
    • Cloud security platforms
    • Exposure management and attack surface management solutions
  • Knowledge of common attack techniques, including:
    • Initial access
    • Credential abuse
    • Privilege escalation
    • Persistence
    • Lateral movement
    • Defense evasion
    • Data access and exfiltration techniques
  • Experience analyzing security logs, endpoint telemetry, authentication activity, network events, and cloud-native security data.
  • Understanding security detections, alerting mechanisms, and investigative techniques.
  • Familiarity with industry frameworks and methodologies such as:
    • MITRE ATT&CK
    • Cyber Kill Chain
    • Threat Hunting methodologies
    • Risk-based prioritization approaches
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written and verbal communication skills.

Preferred Qualifications

  • Experience working within large-scale enterprise Information Security environments.
  • Experience with exposure management, attack path analysis, identity security, attack surface management, or adversary exposure validation programs.
  • Strong knowledge of SIEM platforms and security event analysis, including the ability to investigate, correlate, and analyze security telemetry from multiple data sources to identify attacker activity, security weaknesses, and emerging threats.
  • Understanding of cloud security concepts across Azure, AWS, or Google Cloud environments.
  • Experience developing, tuning, or maintaining security detections and analytics.
  • Familiarity with threat intelligence and its application within security investigations and threat hunting activities.
  • Experience working with automation or orchestration capabilities within security operations environments.

Preferred Certifications

GIAC Certified Incident Handler (GCIH)

GIAC Certified Forensic Analyst (GCFA)

GIAC Cyber Threat Intelligence (GCTI)

GIAC Certified Intrusion Analyst (GCIA)

Offensive Security Certified Professional (OSCP)

More information about NXP in the United States...

NXP is an Equal Opportunity/Affirmative Action Employer regardless of age, color, national origin, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, marital status, status as a disabled veteran and/or veteran of the Vietnam Era or any other characteristic protected by federal, state or local law. In addition, NXP will provide reasonable accommodations for otherwise qualified disabled individuals.

#LI-97b2

Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience
  • At least 5 years of Information Security experience
  • Experience in SOC, threat hunting, security engineering, detection engineering, or incident response
  • Understanding of security operations processes, methodologies, and investigative workflows
  • Understanding of the cyber-attack lifecycle and attacker tactics, techniques, and procedures
  • Experience with SIEM, EDR/XDR, identity security, cloud security, exposure management, and attack surface management technologies
  • Knowledge of attack techniques including initial access, credential abuse, privilege escalation, persistence, lateral movement, defense evasion, data access, and exfiltration
  • Experience analyzing security logs, endpoint telemetry, authentication activity, network events, and cloud-native security data
  • Understanding of security detections, alerting mechanisms, and investigative techniques
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, threat hunting methodologies, and risk-based prioritization
  • Strong analytical, troubleshooting, and problem-solving skills
  • Excellent written and verbal communication skills
  • Experience in large-scale enterprise Information Security environments
  • Experience with exposure management, attack path analysis, identity security, attack surface management, or adversary exposure validation
  • Strong knowledge of SIEM platforms and security event analysis
  • Understanding of cloud security across Azure, AWS, or Google Cloud
  • Experience developing, tuning, or maintaining security detections and analytics
  • Familiarity with threat intelligence in security investigations and threat hunting
  • Experience with security operations automation or orchestration
  • GIAC Certified Incident Handler, GIAC Certified Forensic Analyst, GIAC Cyber Threat Intelligence, GIAC Certified Intrusion Analyst, or OSCP certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eindhoven
21,993 Employees
Year Founded: 2006

What We Do

NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer and more sustainable world through innovation. As a world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. Built on more than 60 years of combined experience and expertise, the company has approximately 34,500 employees in more than 30 countries and posted revenue of $13.21 billion in 2022. Find out more at www.nxp.com. Privacy Policy: https://www.nxp.com/company/about-nxp/privacy-policy-for-social-media-pages:PRIVACY-POLICY-SOCIAL-MEDIA

Similar Jobs

Ericsson Logo Ericsson

People Analytics and AI Intern

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Hybrid
Plano, TX, USA
88000 Employees

Ericsson Logo Ericsson

Head of Commercial Management

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Plano, TX, USA
88000 Employees

Ericsson Logo Ericsson

Director Automation Enablement

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Plano, TX, USA
88000 Employees

Ericsson Logo Ericsson

Financial Analyst

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Hybrid
Plano, TX, USA
88000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account