Cyber Threat Intelligence & Exposure Management Analyst

NXP Semiconductors

Austin (TX)

On-site

USD 120,000 - 180,000

Full time

23 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NXP Semiconductors—an Austin, Texas based cybersecurity role—seeks a Cyber Threat Intelligence & Exposure Management Analyst to identify, analyze, and communicate threats and exposures across the enterprise. The role combines threat intel, attack surface visibility, vulnerability intel, and exposure management to drive risk-based remediation.

The analyst will monitor threat landscapes, track adversaries, and provide risk-informed prioritization for assets and exposures, supporting Security

Qualifications

  • 5+ years in Cyber Threat Intelligence or related cybersecurity disciplines.
  • Ability to correlate threat intel with asset context and business criticality.
  • Experience producing intelligence for technical and executive audiences.

Responsibilities

  • Monitor emerging cyber threats, adversary activity, and vulnerability trends.
  • Track threat actors, campaigns, TTPs, and infrastructure patterns.
  • Conduct intelligence-driven investigations using OSINT and telemetry.
  • Inventory and assess internet-facing assets, cloud resources, and external surfaces.
  • Identify, validate, and prioritize security exposures including vulnerabilities and misconfigurations.
  • Correlate threat intel with vulnerability and asset data for remediation guidance.
  • Analyze exploitability and KEV trends to prioritize actions.
  • Develop threat-informed exposure assessments and risk reports for stakeholders.
  • Lead IOC collection, enrichment, and lifecycle management.
  • Maintain intelligence records and threat artifacts in platforms.
  • Support continuous attack surface monitoring for newly discovered assets.
  • Deliver tactical, operational, and strategic intelligence products.
  • Provide leadership briefings to security teams and business stakeholders.
  • Collaborate with SOC, Vulnerability Mgmt, Cloud Security, and Risk teams.
  • Develop metrics to measure exposure reduction and remediation effectiveness.
  • Identify gaps and opportunities to improve resilience and defenses.

Skills

Cyber Threat Intelligence
Exposure Management
Attack Surface Management
Vulnerability Management
Security Operations
Incident Response
Risk Management
Threat Intelligence Lifecycle
Digital Footprint Analysis
Threat Hunting
KEV/Threat Trends

Tools

Cortex Xpanse
CrowdStrike Exposure Management
Rapid7 Exposure Command
Tenable
Wiz/ Defender EASM
Bitsight
SecurityScorecard
Anomali ThreatConnect ThreatQ OpenCTI MISP
Maltego
Shodan/Censys/URLScan
Python/Automation/Data Analysis

Job description

The Cyber Threat Intelligence & Exposure Management Analyst is responsible for identifying, analyzing, and communicating cyber threats and organizational exposures that present risk to the enterprise. This role combines cyber threat intelligence, attack surface visibility, digital risk monitoring, vulnerability intelligence, and exposure management to deliver actionable insights that improve security posture and reduce business risk.

The analyst continuously monitors the threat landscape, tracks adversary activity, evaluates internal and external exposures, and provides threat-informed prioritization of vulnerabilities, misconfigurations, internet-facing assets, and emerging cyber risks. By correlating intelligence with organizational asset context and business criticality, this role enables Security Operations, Vulnerability Management, Incident Response, Engineering, and Risk teams to focus remediation efforts on the risks that matter most.

Success in this role requires a strong understanding of adversary tradecraft, attack surface management, cyber risk assessment, threat intelligence methodologies, and the ability to translate technical findings into actionable recommendations for both technical and executive audiences.

Job Responsibilities
  • Monitor emerging cyber threats, adversary activity, malware campaigns, vulnerability exploitation trends, and relevant geopolitical developments.
  • Track threat actors and analyze their capabilities, infrastructure, targeting patterns, and tactics, techniques, and procedures (TTPs).
  • Conduct intelligence-driven investigations using internal telemetry, threat intelligence platforms, OSINT, and digital footprint analysis.
  • Discover, inventory, and assess internet-facing assets, cloud resources, domains, certificates, and external attack surfaces that may increase organizational risk.
  • Identify, validate, and prioritize security exposures including vulnerabilities, misconfigurations, exposed services, shadow IT, credential exposures, and third-party risks.
  • Correlate threat intelligence with vulnerability, asset, business criticality, and exposure data to provide risk-based remediation recommendations.
  • Analyze exploitability, adversary activity, KEV intelligence, and emerging attack trends to prioritize remediation efforts.
  • Develop threat-informed exposure assessments and risk reports for security, engineering, and business stakeholders.
  • Lead IOC collection, enrichment, validation, and lifecycle management activities.
  • Maintain intelligence records, exposure findings, indicators, and threat artifacts within intelligence and exposure management platforms.
  • Support continuous attack surface monitoring and identify newly discovered assets, services, and externally exposed technologies.
  • Produce tactical, operational, and strategic intelligence products on threats, exposures, and cyber risks.
  • Deliver intelligence and exposure management briefings to leadership, security teams, and business stakeholders.
  • Support incident response activities through adversary analysis, attribution support, infrastructure investigations, and threat hunting.
  • Partner with Security Operations, Vulnerability Management, Cloud Security, Product Security, and Risk Management teams to drive threat-informed risk reduction.
  • Develop metrics and reporting that measure exposure reduction, remediation effectiveness, vulnerability prioritization, and attack surface risk.
  • Identify intelligence gaps, emerging risks, and opportunities to improve organizational resilience and defensive capabilities.
Professional Experience
  • 5+ years of experience in Cyber Threat Intelligence, Exposure Management, Attack Surface Management, Vulnerability Management, Security Operations, Incident Response, or related cybersecurity disciplines.
  • Experience tracking threat actors, cyber campaigns, exploited vulnerabilities, and emerging threat trends.
  • Demonstrated experience identifying and assessing attack surface risks and external exposures.
  • Experience producing tactical, operational, and strategic intelligence products for technical and executive audiences.
  • Proven ability to correlate threat intelligence, business context, asset criticality, and vulnerability data to support risk-based decision making.
  • Experience conducting investigations involving internet-facing assets, cloud environments, exposed technologies, and digital footprint analysis.
  • Experience supporting vulnerability prioritization, remediation strategies, and threat-informed risk reduction initiatives.
Technical Skills
  • Strong understanding of Cyber Threat Intelligence tradecraft, Exposure Management, Attack Surface Management (ASM), and Risk-Based Vulnerability Management (RBVM).
  • Knowledge of MITRE ATT&CK, ATT&CK Navigator, Cyber Kill Chain, Diamond Model, STIX/TAXII, Intelligence Lifecycle, Structured Analytic Techniques, and Exposure Assessment methodologies.
  • Experience with Exposure Management and ASM platforms such as Cortex Xpanse, CrowdStrike Exposure Management, Rapid7 Exposure Command, Tenable, Wiz, Microsoft Defender EASM, Bitsight, SecurityScorecard, or similar technologies.
  • Experience with Threat Intelligence Platforms such as Anomali, ThreatConnect, ThreatQ, OpenCTI, MISP, or equivalent solutions.
  • Proficiency with intelligence and investigative platforms including Maltego, VirusTotal, Shodan, Censys, GreyNoise, DomainTools, SecurityTrails, URLScan, PassiveTotal, and similar tools.
  • Experience conducting infrastructure analysis involving domains, DNS, passive DNS, IP addresses, ASNs, certificates, cloud services, hosting providers, and internet-facing assets.
  • Understanding of CVSS, EPSS, KEV, vulnerability exploitation trends, threat-informed vulnerability management, and cyber risk quantification concepts.
  • Experience with cloud security concepts, SaaS security, external attack surface discovery, shadow IT identification, and exposure validation.
  • Knowledge of Sigma, YARA, Suricata, Snort, malware analysis principles, and intelligence automation techniques.
  • Experience with Python, automation, APIs, large-scale data analysis, ELK Stack, Databricks, Power BI, and security data correlation workflows.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

CHS Corporate • United States

On-site
USD 140,000 - 190,000
Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

Community Health Systems • United States

On-site
USD 120,000 - 150,000
Senior Advisor, Exposure Management
Senior Advisor, Exposure Management

Jobtailor • California (MO)

On-site
USD 140,000 - 190,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 150,000 - 190,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Check Point Software Technologies • Dallas (TX)

On-site
USD 65,000 - 90,000
Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

Invictus International • Colorado Springs (CO)

On-site
USD 95,000 - 125,000
Cyber Security Analyst
Cyber Security Analyst

Dale WorkForce Solutions • Columbia (SC)

On-site
USD 90,000 - 130,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Cyber Hunt Analyst
Cyber Hunt Analyst

Synergy ECP • Columbia (MD)

On-site
USD 120,000 - 160,000