About the role
Senior Threat Hunt Engineer
Key Responsibilities
Threat Hunting Program Leadership
- Design, maintain, and continuously improve the organization's threat hunting framework.
- Develop and standardize hunt processes, methodologies, templates, and operational procedures.
- Establish repeatable and scalable hunt practices across Cyber Defense teams.
- Mature hunt operations through continuous optimization and strategic improvements.
Proactive Threat Hunting
- Conduct proactive and intelligence-driven hunts across:
- SIEM Platforms
- EDR Solutions
- Network Telemetry
- Cloud Environments
- Identity Systems
- Endpoint Data Sources
- Investigate suspicious activity and emerging attack patterns.
- Identify threats before they become security incidents.
- Develop hunt hypotheses based on adversary behaviors and threat intelligence.
Threat Intelligence Analysis
- Research current and emerging cyber threats relevant to the business and industry.
- Monitor:
- Threat Actors
- Threat Clusters
- Malware Families
- Adversary Campaigns
- Industry Threat Trends
- Analyze adversary tactics, techniques, and procedures (TTPs).
- Convert intelligence findings into actionable hunting opportunities and defensive recommendations.
Detection Engineering Collaboration
- Partner with Detection Engineering teams to operationalize hunt findings.
- Translate hunt discoveries into:
- Detection Rules
- Analytics Content
- Correlation Logic
- Monitoring Enhancements
- Identify detection coverage gaps and recommend improvements.
- Contribute detection candidates through established engineering workflows.
Security Automation & Integration
- Design and build integrations across the hunt lifecycle.
- Develop automation capabilities using:
- REST APIs
- Webhooks
- Security Platforms
- Intelligence Feeds
- Workflow Automation Tools
- Integrate security tooling including:
- SIEM
- EDR
- Ticketing Systems
- Collaboration Platforms
- Threat Intelligence Platforms
- Knowledge Management Systems
- Improve operational efficiency through automation and orchestration.
AI-Enabled Security Operations
- Evaluate and implement AI-assisted capabilities for threat hunting workflows.
- Support:
- Query Generation
- Hypothesis Creation
- MITRE ATT&CK Mapping
- Investigation Summarization
- Threat Research Acceleration
- Establish guardrails and validation processes for AI-supported outputs.
- Improve analyst productivity through responsible AI adoption.
Threat Reporting & Executive Communication
- Produce technical and executive-level threat assessments.
- Document findings related to:
- Threat Activity
- Risk Exposure
- Detection Gaps
- Control Weaknesses
- Recommended Mitigations
- Communicate complex technical findings effectively to both technical and business audiences.
- Deliver management reporting on hunt program outcomes and security improvements.
Security Tooling & Platform Management
- Evaluate, implement, and maintain threat hunting and threat intelligence technologies.
- Assess new security products and services for operational value.
- Optimize platform configurations and integrations.
- Support long-term evolution of threat intelligence and hunting capabilities.
Mentorship & Technical Leadership
- Mentor analysts, hunters, and junior security professionals.
- Lead technical workshops, deep dives, and knowledge-sharing sessions.
- Help elevate threat hunting maturity across Cyber Defense teams.
- Promote best practices for investigations, documentation, and analytics.
Incident Response & Security Operations Support
- Assist with advanced investigations and incident analysis.
- Provide threat intelligence and hunt support during security incidents.
- Partner with Incident Response teams to assess adversary activity.
- Support threat-informed defense initiatives across the organization.
Cross-Functional Collaboration
- Partner with:
- Threat Intelligence Teams
- Detection Engineers
- Incident Responders
- Security Operations Center (SOC)
- Security Engineering Teams
- Business Stakeholders
- Serve as a trusted cybersecurity advisor.
- Participate in industry information-sharing and threat collaboration initiatives.
Qualifications
Education
- Bachelor's Degree in:
- Cybersecurity
- Computer Science
- Information Technology
- Engineering
- Related Technical Discipline
OR
- Equivalent combination of education and professional experience.
Experience
- 5–10+ years of experience in:
- Threat Hunting
- Threat Intelligence
- Incident Response
- Detection Engineering
- Cyber Defense
- Experience conducting proactive and intelligence-driven threat hunts.
- Experience supporting enterprise-scale security programs.
- Experience developing security automation and integrations.
Technical Skills
Threat Hunting & Intelligence
- Threat Hunting Methodologies
- Threat Intelligence Analysis
- MITRE ATT&CK Framework
- Unified Kill Chain
- Open-Source Intelligence (OSINT)
- Adversary Emulation
Security Platforms
- SIEM Technologies
- EDR/XDR Platforms
- IDS/IPS Solutions
- Threat Intelligence Platforms
- SOAR Platforms
- Security Analytics Tools
Automation & Development
- Python (Required)
- PowerShell
- Bash
- REST APIs
- Webhooks
- Security Automation Development
- Integration Engineering
Enterprise Security
- Network Security
- Endpoint Security
- Cloud Security
- Identity Security
- Malware Analysis
- Vulnerability Management
- Threat-Informed Defense
Cloud & Infrastructure
- AWS
- Azure
- GCP
- Cloud-Native Security Controls
- Cloud API Integrations
Preferred Certifications
- GCTI (GIAC Cyber Threat Intelligence)
- GCIH (GIAC Certified Incident Handler)
- GCFA (GIAC Certified Forensic Analyst)
- GCIA (GIAC Certified Intrusion Analyst)
- GCDA
- OSCP
- CEH
- CISSP
- AWS Security Specialty
- GCP Professional Cloud Security Engineer
Preferred Qualifications
- Experience with AI-enabled security workflows.
- Experience building threat hunting programs from the ground up.
- Familiarity with version-controlled hunting methodologies.
- CI/CD pipeline experience for security content deployment.
- SOAR playbook development experience.
- Cloud-native security tooling expertise.
- Experience in financial services or other highly regulated industries.
- Contributions to:
- Open-Source Security Projects
- Threat Research Publications
- Public Threat Intelligence Initiatives
Core Competencies
- Threat Hunting
- Threat Intelligence
- Detection Engineering
- Incident Response
- SIEM Engineering
- EDR/XDR Operations
- Security Automation
- AI for Cyber Defense
- Threat Research
- MITRE ATT&CK
- Malware Analysis
- Cloud Security
- Security Analytics
- Adversary Tracking
- Cyber Threat Reporting
- Security Program Development
- Technical Leadership
- Cross-Functional Collaboration
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at SoTalent was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
