Job Title:Senior Exposure Threat Hunter
Location:Bangalore, India
Role Summary
We are seeking an experienced and highly analytical Exposure Threat Hunter to join our Information Security team. This role is focused on proactively identifying, investigating, and validating security exposures, attack paths, and security weaknesses that could be leveraged by threat actors across the enterprise.
The ideal candidate will have a strong Information Security background with experience in Security Operations (SOC), Threat Hunting, Security Engineering, Detection Engineering, or Incident Response. They should understand attacker methodologies, common attack techniques, security tooling, and investigative processes, and be capable of identifying potential risks before they can be exploited.
This position requires a proactive security mindset, strong investigative skills, and the ability to bridge technical findings with actionable risk reduction strategies.
Job Responsibility
- Proactively identify, investigate, and validate security exposures, attack paths, misconfigurations, and control weaknesses across enterprise environments.
- Conduct threat hunting activities to uncover potential risks, attacker opportunities, and indicators of compromise that may not be detected through traditional monitoring.
- Analyze security telemetry, logs, identity-related data, cloud security findings, endpoint activity, and threat intelligence to identify security gaps and exploitable conditions.
- Assess exposures from an attacker's perspective and determine potential exploitation scenarios and business impact.
- Leverage security tools and technologies to investigate findings and uncover relationships between assets, identities, privileges, and security controls.
- Collaborate with Security Operations, Vulnerability Management, Engineering, Cloud Security, and Incident Response teams to validate findings and support remediation efforts.
- Contribute to the development and improvement of exposure hunting methodologies, investigative procedures, and operational processes.
- Assist in the creation, tuning, and optimization of detection rules and monitoring capabilities that help identify attacker behaviors and high-risk exposures.
- Research emerging threats, attacker techniques, and industry trends to improve threat hunting and exposure management capabilities.
- Document findings, risk assessments, recommendations, and remediation guidance in a clear and actionable manner.
- Provide strategic recommendations to reduce organizational attack surface and improve overall security posture.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
- Minimum 10+ years of experience in Information Security, preferably within one or more of the following areas:
- Security Operations Center (SOC)
- Threat Hunting
- Security Engineering
- Detection Engineering
- Incident Response
- Strong understanding of security operations processes, methodologies, and investigative workflows.
- Solid understanding of the cyber-attack lifecycle and common attacker tactics, techniques, and procedures (TTPs).
- Experience working with enterprise security technologies such as:
- SIEM platforms
- EDR/XDR solutions
- Identity security tools
- Cloud security platforms
- Exposure management and attack surface management solutions
- Knowledge of common attack techniques, including:
- Initial access
- Credential abuse
- Privilege escalation
- Persistence
- Lateral movement
- Defense evasion
- Data access and exfiltration techniques
- Experience analyzing security logs, endpoint telemetry, authentication activity, network events, and cloud-native security data.
- Understanding security detections, alerting mechanisms, and investigative techniques.
- Familiarity with industry frameworks and methodologies such as:
- MITRE ATT&CK
- Cyber Kill Chain
- Threat Hunting methodologies
- Risk-based prioritization approaches
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent written and verbal communication skills.
Preferred Qualifications
- Experience working within large-scale enterprise Information Security environments.
- Experience with exposure management, attack path analysis, identity security, attack surface management, or adversary exposure validation programs.
- Strong knowledge of SIEM platforms and security event analysis, including the ability to investigate, correlate, and analyze security telemetry from multiple data sources to identify attacker activity, security weaknesses, and emerging threats.
- Understanding of cloud security concepts across Azure, AWS, or Google Cloud environments.
- Experience developing, tuning, or maintaining security detections and analytics.
- Familiarity with threat intelligence and its application within security investigations and threat hunting activities.
- Experience working with automation or orchestration capabilities within security operations environments.
Preferred Certifications
GIAC Certified Incident Handler (GCIH)
GIAC Certified Forensic Analyst (GCFA)
GIAC Cyber Threat Intelligence (GCTI)
GIAC Certified Intrusion Analyst (GCIA)
Offensive Security Certified Professional (OSCP)
#LI-29f4