Job at a glance
Job Title: Senior Exposure Threat Hunter Location: Austin, USA Role Summary We are seeking an experienced and highly analytical Exposure Threat Hunter to join our Information Security team. This role is focused on proactively identifying, investigating, and validating security exposures, attack paths, and security weaknesses that could be leveraged by threat actors across the enterprise. The ideal candidate will have a strong Information Security background with experience in Security Operations (SOC), Threat Hunting, Security Engineering, Detection Engineering, or Incident Response.
They should understand attacker methodologies, common attack techniques, security tooling, and investigative processes, and be capable of identifying potential risks before they can be exploited. This position requires a proactive security mindset, strong investigative skills, and the ability to bridge technical findings with actionable risk reduction strategies. Job Responsibility Proactively identify, investigate, and validate security exposures, attack paths, misconfigurations, and control weaknesses across enterprise environments.
Conduct threat hunting activities to uncover potential risks, attacker opportunities, and indicators of compromise that may not be detected through traditional monitoring. Analyze security telemetry, logs, identity-related data, cloud security findings, endpoint activity, and threat intelligence to identify security gaps and exploitable conditions. Assess exposures from an attacker’s perspective and determine potential exploitation scenarios and business impact.
Leverage security tools and technologies to investigate findings and uncover relationships between assets, identities, privileges, and security controls. Collaborate with Security Operations, Vulnerability Management, Engineering, Cloud Security, and Incident Response teams to validate findings and support remediation efforts. Contribute to the development and improvement of exposure hunting methodologies, investigative procedures, and operational processes.
Assist in the creation, tuning, and optimization of detection rules and monitoring capabilities that help identify attacker behaviors and high-risk exposures. Research emerging threats, attacker techniques, and industry trends to improve threat hunting and exposure management capabilities. Document findings, risk assessments, recommendations, and remediation guidance in a clear and actionable manner.
Provide strategic recommendations to reduce organizational attack surface and improve overall security posture. Required Qualifications Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience. Minimum 5 years of experience in Information Security, preferably within one or more of the following areas: Security Operations Center (SOC) Threat Hunting Security Engineering Detection Engineering Incident Response Strong understanding of security operations processes, methodologies, and investigative workflows.
Solid understanding of the cyber-attack lifecycle and common attacker tactics, techniques, and procedures (TTPs). Experience working with enterprise security technologies such as: SIEM platforms EDR/XDR solutions Identity security tools Cloud security platforms Exposure management and attack surface management solutions Knowledge of common attack techniques, including: Initial access Credential abuse Privilege escalation Persistence Lateral movement Defense evasion Data access and exfiltration techniques Experience analyzing security logs, endpoint telemetry, authentication activity, network events, and cloud-native security data.
Understanding security detections, alerting mechanisms, and investigative techniques. Familiarity with industry frameworks and methodologies such as: MITRE ATT&CK Cyber Kill Chain Threat Hunting methodologies Risk-based prioritization approaches Strong analytical, troubleshooting, and problem-solving skills. Exc