Threat Hunting Analyst
Core
Investigate security alerts and analyze telemetry across endpoint, network, and cloud platforms to identify and mitigate malicious activity.
Role type
Threat Hunting Analyst
Builds
Detection and response capabilities for global enterprise infrastructure
Domain
Cybersecurity / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM analysis, EDR analysis, network security monitoring, incident investigation, telemetry analysis, playbook development, cross-functional coordination, documentation, threat hunting, TTP analysis
Preferred skills
Splunk, Microsoft Defender, Python scripting, PowerShell, SQL, malware analysis, MITRE ATT&CK frameworks, cloud environment management (AWS, Azure, GCP)
Responsibilities
Investigate security alerts, suspicious activity, phishing reports, and potential security incidents; Analyze endpoint, network, cloud, identity, and email telemetry; Document investigations, analysis, decisions, and actions; Coordinate incidents with internal teams; Support operational improvement initiatives including detection tuning and automation; Participate in proactive threat hunting and intelligence-driven investigations; Contribute to continuous improvement efforts by identifying gaps and recommending solutions
Seniority
Mid-level, hands-on IC