As a Threat Hunting and IR, you will:
- Proactively hunt threats, contain breaches and reduce organizational impact
- Investigate, analyze and respond to security events and incidents, performing in-depth technical analysis to determine root cause and impact
- Design, develop, and maintain security detections, alerts and monitoring capabilities across enterprise and cloud environments
- Perform security assessments and red team exercises
- Conduct network, protocol and technical research to identify emerging threats, attack techniques and defensive opportunities
- Analyze network traffic, system logs, endpoint telemetry and security events to identify suspicious activity and security gaps
- Conduct threat intelligence and OSINT research using internal and external data sources to identify threats and improve detection capabilities
- Partner with Engineering, Infrastructure, and Architecture teams to embed security-by-design principles into new products and services
- Develop automation and tooling to improve security monitoring, investigations and operational efficiency
If you have:
- Deep understanding of networking fundamentals: TCP/IP, DNS, HTTP/HTTPS, TLS/SSL, routing/switching, VPNs and network security architectures
- Strong proficiency in Python for security automation, log parsing, tooling development and multi-source data correlation
- Practical background in threat hunting, detection engineering or security operations
- Experience creating, tuning and investigating security alerts and detections
- Experience analyzing logs, network traffic and endpoint telemetry during investigations
- Hands-on experience with SIEM, EDR, IDS/IPS and related security monitoring technologies
- Strong analytical and problem-solving skills with the ability to conduct independent technical research
- Strong proficiency with security research, threat intelligence and attack surface discovery tools
- Familiarity with OSINT methodologies and intelligence gathering techniques
- Experience correlating data from multiple intelligence sources to support investigations and threat hunting
It would be great if you also have:
- Experience conducting red team or security assessment activities
- Experience developing custom security tooling and automation frameworks
- Familiarity with threat intelligence processes and threat actor tracking
- Experience working in large-scale enterprise environments
- Relevant industry certifications such as GIAC, GSEC, GCIA, GCIH, GPEN, OSCP or equivalent
