Staff Threat Hunting & Intelligence Engineer
Core
A hybrid role combining threat intelligence, threat hunting, and engineering to track adversaries, deliver actionable intelligence, and build automation for Splunk's security operations.
Role type
Staff Threat Hunting & Intelligence Engineer
Builds
Automation, tooling, and scripts for threat-data ingestion, processing, enrichment, and scaling intelligence/hunting use cases.
Domain
Cybersecurity, Threat Intelligence, Threat Hunting, Splunk
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cyber threat intelligence, threat hunting, Splunk (SPL), attacker behavior analysis, AI application for analysis/development, scripting, API integration, cloud technologies (AWS/GCP/Azure), Linux, network/host-based logs analysis
Preferred skills
Threat actor/campaign attribution, DevOps, infrastructure-as-code, CI/CD tooling, incident response support, detection rule gap analysis
Technologies
Splunk, AWS, GCP, Azure, Linux, AI/ML
Responsibilities
Deliver actionable threat intelligence during active incidents; Produce cadenced and ad-hoc intelligence products; Plan and conduct threat hunts; Build and maintain automation scripts and API integrations; Apply AI to accelerate intelligence analysis and tooling; Uncover adversary activity missed by current detection rules; Mentor analysts and engineers
Seniority
Staff, hands-on IC with mentorship