The Cyber Threat Intelligence & Exposure Management Analyst

NXP Semiconductors

Austin (TX)

On-site

USD 130,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NXP Semiconductors is seeking a Cyber Threat Intelligence & Exposure Management Analyst to identify, analyze, and communicate cyber threats and organizational exposures. The role combines threat intelligence, attack surface visibility, vulnerability intelligence, and exposure management to deliver actionable insights that reduce business risk.

You will collaborate with Security Operations, Vulnerability Management, and Risk teams to drive risk reduction.

Qualifications

  • Proficient in threat intelligence and exposure management concepts.

Responsibilities

  • Monitor emerging cyber threats, adversary activity, malware campaigns, vulnerability exploitation trends, and geopolitical developments.

Skills

Threat intelligence
Attack surface
Vulnerability management
Incident response
Risk assessment
Threat hunting
Geopolitical intel
OSINT
Python
Data analysis
RBVM

Tools

Cortex Xpanse
CrowdStrike Exposure Management
Tenable
Maltego
VirusTotal
Shodan
OpenCTI
MISP
Power BI
Databricks
ELK Stack
ThreatQ

Job description

Role Summary The Cyber Threat Intelligence & Exposure Management Analyst is responsible for identifying, analyzing, and communicating cyber threats and organizational exposures that present risk to the enterprise. This role combines cyber threat intelligence, attack surface visibility, digital risk monitoring, vulnerability intelligence, and exposure management to deliver actionable insights that improve security posture and reduce business risk. The analyst continuously monitors the threat landscape, tracks adversary activity, evaluates internal and external exposures, and provides threat-informed prioritization of vulnerabilities, misconfigurations, internet-facing assets, and emerging cyber risks. By correlating intelligence with organizational asset context and business criticality, this role enables Security Operations, Vulnerability Management, Incident Response, Engineering, and Risk teams to focus remediation efforts on the risks that matter most. Success in this role requires a strong understanding of adversary tradecraft, attack surface management, cyber risk assessment, threat intelligence methodologies, and the ability to translate technical findings into actionable recommendations for both technical and executive audiences.

Job Responsibilities
  • Monitor emerging cyber threats, adversary activity, malware campaigns, vulnerability exploitation trends, and relevant geopolitical developments.
  • Track threat actors and analyze their capabilities, infrastructure, targeting patterns, and tactics, techniques, and procedures (TTPs).
  • Conduct intelligence-driven investigations using internal telemetry, threat intelligence platforms, OSINT, and digital footprint analysis.
  • Discover, inventory, and assess internet-facing assets, cloud resources, domains, certificates, and external attack surfaces that may increase organizational risk.
  • Identify, validate, and prioritize security exposures including vulnerabilities, misconfigurations, exposed services, shadow IT, credential exposures, and third-party risks.
  • Correlate threat intelligence with vulnerability, asset, business criticality, and exposure data to provide risk-based remediation recommendations.
  • Analyze exploitability, adversary activity, KEV intelligence, and emerging attack trends to prioritize remediation efforts.
  • Develop threat-informed exposure assessments and risk reports for security, engineering, and business stakeholders.
  • Lead IOC collection, enrichment, validation, and lifecycle management activities.
  • Maintain intelligence records, exposure findings, indicators, and threat artifacts within intelligence and exposure management platforms.
  • Support continuous attack surface monitoring and identify newly discovered assets, services, and externally exposed technologies.
  • Produce tactical, operational, and strategic intelligence products on threats, exposures, and cyber risks.
  • Deliver intelligence and exposure management briefings to leadership, security teams, and business stakeholders.
  • Support incident response activities through adversary analysis, attribution support, infrastructure investigations, and threat hunting.
  • Partner with Security Operations, Vulnerability Management, Cloud Security, Product Security, and Risk Management teams to drive threat-informed risk reduction.
  • Develop metrics and reporting that measure exposure reduction, remediation effectiveness, vulnerability prioritization, and attack surface risk.
  • Identify intelligence gaps, emerging risks, and opportunities to improve organizational resilience and defensive capabilities.
Professional Experience
  • 5+ years of experience in Cyber Threat Intelligence, Exposure Management, Attack Surface Management, Vulnerability Management, Security Operations, Incident Response, or related cybersecurity disciplines. Experience tracking threat actors, cyber campaigns, exploited vulnerabilities, and emerging threat trends. Demonstrated experience identifying and assessing attack surface risks and external exposures. Experience producing tactical, operational, and strategic intelligence products for technical and executive audiences. Proven ability to correlate threat intelligence, business context, asset criticality, and vulnerability data to support risk-based decision making. Experience conducting investigations involving internet-facing assets, cloud environments, exposed technologies, and digital footprint analysis. Experience supporting vulnerability prioritization, remediation strategies, and threat-informed risk reduction initiatives.
Technical Skills
  • Strong understanding of Cyber Threat Intelligence tradecraft, Exposure Management, Attack Surface Management (ASM), and Risk-Based Vulnerability Management (RBVM). Knowledge of MITRE ATT&CK, ATT&CK Navigator, Cyber Kill Chain, Diamond Model, STIX/TAXII, Intelligence Lifecycle, Structured Analytic Techniques, and Exposure Assessment methodologies. Experience with Exposure Management and ASM platforms such as Cortex Xpanse, CrowdStrike Exposure Management, Rapid7 Exposure Command, Tenable, Wiz, Microsoft Defender EASM, Bitsight, SecurityScorecard, or similar technologies. Experience with Threat Intelligence Platforms such as Anomali, ThreatConnect, ThreatQ, OpenCTI, MISP, or equivalent solutions. Proficiency with intelligence and investigative platforms including Maltego, VirusTotal, Shodan, Censys, GreyNoise, DomainTools, SecurityTrails, URLScan, PassiveTotal, and similar tools. Experience conducting infrastructure analysis involving domains, DNS, passive DNS, IP addresses, ASNs, certificates, cloud services, hosting providers, and internet-facing assets. Understanding of CVSS, EPSS, KEV, vulnerability exploitation trends, threat-informed vulnerability management, and cyber risk quantification concepts. Experience with cloud security concepts, SaaS security, external attack surface discovery, shadow IT identification, and exposure validation. Knowledge of Sigma, YARA, Suricata, Snort, malware analysis principles, and intelligence automation techniques. Experience with Python, automation, APIs, large-scale data analysis, ELK Stack, Databricks, Power BI, and security data correlation workflows.
More information about NXP in the United States

More information about NXP in the United States...

NXP is an Equal Opportunity/Affirmative Action Employer regardless of age, color, national origin, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, marital status, status as a disabled veteran and/or veteran of the Vietnam Era or any other characteristic protected by federal, state or local law.

In addition, NXP will provide reasonable accommodations for otherwise qualified disabled individuals.

#LI-97b2 NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer, and more sustainable world through innovation.

As the world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets.

For more information, visit www.nxp.com

Bright Minds. Bright Futures.

We believe that a key component to growing our business is to develop our people.

To enable you to grow your career at NXP, we offer online and offline learning opportunities to help you develop some of your core and professional skills.

Commitment At NXP

We recognize NXP is a powerful change agent as we continue to deliver innovative solutions that advance a more sustainable future.

We remain steadfast in our commitment to sustainability and making measurable year-on-year progress.

We have programs in place focused on diversity, inclusion and equality.

Also, we aim to create an inclusive work environment and we will not tolerate racism, discrimination or harassment of any kind.

Thank you for considering a career at NXP.

Any candidate profiles or resume submitted without a prior written agreement or explicit request from our Talent Acquisition team will be considered unsolicited. Such submissions will be deemed free of any obligations, and no fees will be paid by NXP or any of its affiliates, subsidiaries, or divisions - regardless of whether the candidate is hired, either coincidentally or otherwise. Thank you for your understanding.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Exposure Threat Hunter
Senior Exposure Threat Hunter

NXP Semiconductors • Austin (TX)

On-site
USD 130,000 - 190,000
Data Analytics Engineer Intern - Summer 2027
Data Analytics Engineer Intern - Summer 2027

NXP Semiconductors • Austin (TX)

Hybrid
USD 25,000 - 41,000
AI Security Engineer
AI Security Engineer

NXP Semiconductors • Austin (TX)

On-site
USD 130,000 - 180,000
Embedded Machine Learning & Radar Processing Intern - Summer 2027
Embedded Machine Learning & Radar Processing Intern - Summer 2027

NXP Semiconductors • San Jose (CA)

On-site
USD 64,000 - 108,000
Agentic Security Engineer
Agentic Security Engineer

NXP Semiconductors • Austin (TX)

On-site
USD 120,000 - 190,000
Device Engineering Intern - Summer 2027
Device Engineering Intern - Summer 2027

NXP Semiconductors • Chandler (AZ)

On-site
USD 28,000 - 34,000
Entry Level Digital Design Engineer
Entry Level Digital Design Engineer

NXP Semiconductors • Austin (TX)

On-site
USD 75,000 - 95,000
Senior Technical Business Analyst – AI Search & Digital Experience
Senior Technical Business Analyst – AI Search & Digital Experience

NXP Semiconductors • Austin (TX)

On-site
USD 110,000 - 145,000
AI Application Security Engineer
AI Application Security Engineer

NXP Semiconductors • Austin (TX)

On-site
USD 120,000 - 190,000
AI Application Security Engineer (R-10066600)
AI Application Security Engineer (R-10066600)

NXP Semiconductors • Austin (TX)

On-site
USD 120,000 - 180,000