Principal Advanced Threat Response Analyst
Core
Lead complex threat investigations, proactive threat hunting, and incident response for Advanced Persistent Threats (APTs), ransomware, and nation-state activity across enterprise and cloud environments.
Role type
Principal Advanced Threat Response Analyst (Senior IC)
Builds
Enhanced detection capabilities, custom playbooks, and automated response workflows for HPE's global security organization.
Domain
Cybersecurity / Threat Intelligence / Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Advanced threat hunting, incident command, purple team exercises, MITRE ATT&CK framework, adversary emulation, cloud security (AWS/Azure/GCP), SIEM/EDR expertise, Python/PowerShell/Bash scripting, technical leadership
Preferred skills
Advanced SANS certifications (GCFA, GREM, etc.), Offensive certifications (OSCP, OSEP), hands-on platform recognition (Hack The Box, Cyber Defenders)
Technologies
Splunk, Sentinel, ELK, CrowdStrike, Carbon Black, Defender ATP, Cobalt Strike, Empire, Metasploit, Sliver, Mimikatz
Responsibilities
Lead complex threat investigations involving APTs and ransomware; Drive proactive threat hunting programs; Develop and execute purple team exercises; Collaborate with red teams to translate attacker TTPs into detections; Perform incident command during major security events; Develop custom detections and automation; Mentor junior analysts and responders
Seniority
Principal, hands-on IC with mentorship responsibilities