SoTalent logo

Senior Threat Hunt Engineer

SoTalent

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Senior Threat Hunt Engineer

Key Responsibilities

Threat Hunting Program Leadership

  • Design, maintain, and continuously improve the organization's threat hunting framework.
  • Develop and standardize hunt processes, methodologies, templates, and operational procedures.
  • Establish repeatable and scalable hunt practices across Cyber Defense teams.
  • Mature hunt operations through continuous optimization and strategic improvements.

Proactive Threat Hunting

  • Conduct proactive and intelligence-driven hunts across:
    • SIEM Platforms
    • EDR Solutions
    • Network Telemetry
    • Cloud Environments
    • Identity Systems
    • Endpoint Data Sources
  • Investigate suspicious activity and emerging attack patterns.
  • Identify threats before they become security incidents.
  • Develop hunt hypotheses based on adversary behaviors and threat intelligence.

Threat Intelligence Analysis

  • Research current and emerging cyber threats relevant to the business and industry.
  • Monitor:
    • Threat Actors
    • Threat Clusters
    • Malware Families
    • Adversary Campaigns
    • Industry Threat Trends
  • Analyze adversary tactics, techniques, and procedures (TTPs).
  • Convert intelligence findings into actionable hunting opportunities and defensive recommendations.

Detection Engineering Collaboration

  • Partner with Detection Engineering teams to operationalize hunt findings.
  • Translate hunt discoveries into:
    • Detection Rules
    • Analytics Content
    • Correlation Logic
    • Monitoring Enhancements
  • Identify detection coverage gaps and recommend improvements.
  • Contribute detection candidates through established engineering workflows.

Security Automation & Integration

  • Design and build integrations across the hunt lifecycle.
  • Develop automation capabilities using:
    • REST APIs
    • Webhooks
    • Security Platforms
    • Intelligence Feeds
    • Workflow Automation Tools
  • Integrate security tooling including:
    • SIEM
    • EDR
    • Ticketing Systems
    • Collaboration Platforms
    • Threat Intelligence Platforms
    • Knowledge Management Systems
  • Improve operational efficiency through automation and orchestration.

AI-Enabled Security Operations

  • Evaluate and implement AI-assisted capabilities for threat hunting workflows.
  • Support:
    • Query Generation
    • Hypothesis Creation
    • MITRE ATT&CK Mapping
    • Investigation Summarization
    • Threat Research Acceleration
  • Establish guardrails and validation processes for AI-supported outputs.
  • Improve analyst productivity through responsible AI adoption.

Threat Reporting & Executive Communication

  • Produce technical and executive-level threat assessments.
  • Document findings related to:
    • Threat Activity
    • Risk Exposure
    • Detection Gaps
    • Control Weaknesses
    • Recommended Mitigations
  • Communicate complex technical findings effectively to both technical and business audiences.
  • Deliver management reporting on hunt program outcomes and security improvements.

Security Tooling & Platform Management

  • Evaluate, implement, and maintain threat hunting and threat intelligence technologies.
  • Assess new security products and services for operational value.
  • Optimize platform configurations and integrations.
  • Support long-term evolution of threat intelligence and hunting capabilities.

Mentorship & Technical Leadership

  • Mentor analysts, hunters, and junior security professionals.
  • Lead technical workshops, deep dives, and knowledge-sharing sessions.
  • Help elevate threat hunting maturity across Cyber Defense teams.
  • Promote best practices for investigations, documentation, and analytics.

Incident Response & Security Operations Support

  • Assist with advanced investigations and incident analysis.
  • Provide threat intelligence and hunt support during security incidents.
  • Partner with Incident Response teams to assess adversary activity.
  • Support threat-informed defense initiatives across the organization.

Cross-Functional Collaboration

  • Partner with:
    • Threat Intelligence Teams
    • Detection Engineers
    • Incident Responders
    • Security Operations Center (SOC)
    • Security Engineering Teams
    • Business Stakeholders
  • Serve as a trusted cybersecurity advisor.
  • Participate in industry information-sharing and threat collaboration initiatives.

Qualifications

Education

  • Bachelor's Degree in:
    • Cybersecurity
    • Computer Science
    • Information Technology
    • Engineering
    • Related Technical Discipline

OR

  • Equivalent combination of education and professional experience.

Experience

  • 5–10+ years of experience in:
    • Threat Hunting
    • Threat Intelligence
    • Incident Response
    • Detection Engineering
    • Cyber Defense
  • Experience conducting proactive and intelligence-driven threat hunts.
  • Experience supporting enterprise-scale security programs.
  • Experience developing security automation and integrations.

Technical Skills

Threat Hunting & Intelligence

  • Threat Hunting Methodologies
  • Threat Intelligence Analysis
  • MITRE ATT&CK Framework
  • Unified Kill Chain
  • Open-Source Intelligence (OSINT)
  • Adversary Emulation

Security Platforms

  • SIEM Technologies
  • EDR/XDR Platforms
  • IDS/IPS Solutions
  • Threat Intelligence Platforms
  • SOAR Platforms
  • Security Analytics Tools

Automation & Development

  • Python (Required)
  • PowerShell
  • Bash
  • REST APIs
  • Webhooks
  • Security Automation Development
  • Integration Engineering

Enterprise Security

  • Network Security
  • Endpoint Security
  • Cloud Security
  • Identity Security
  • Malware Analysis
  • Vulnerability Management
  • Threat-Informed Defense

Cloud & Infrastructure

  • AWS
  • Azure
  • GCP
  • Cloud-Native Security Controls
  • Cloud API Integrations

Preferred Certifications

  • GCTI (GIAC Cyber Threat Intelligence)
  • GCIH (GIAC Certified Incident Handler)
  • GCFA (GIAC Certified Forensic Analyst)
  • GCIA (GIAC Certified Intrusion Analyst)
  • GCDA
  • OSCP
  • CEH
  • CISSP
  • AWS Security Specialty
  • GCP Professional Cloud Security Engineer

Preferred Qualifications

  • Experience with AI-enabled security workflows.
  • Experience building threat hunting programs from the ground up.
  • Familiarity with version-controlled hunting methodologies.
  • CI/CD pipeline experience for security content deployment.
  • SOAR playbook development experience.
  • Cloud-native security tooling expertise.
  • Experience in financial services or other highly regulated industries.
  • Contributions to:
    • Open-Source Security Projects
    • Threat Research Publications
    • Public Threat Intelligence Initiatives

Core Competencies

  • Threat Hunting
  • Threat Intelligence
  • Detection Engineering
  • Incident Response
  • SIEM Engineering
  • EDR/XDR Operations
  • Security Automation
  • AI for Cyber Defense
  • Threat Research
  • MITRE ATT&CK
  • Malware Analysis
  • Cloud Security
  • Security Analytics
  • Adversary Tracking
  • Cyber Threat Reporting
  • Security Program Development
  • Technical Leadership
  • Cross-Functional Collaboration

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at SoTalent was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.