Staff Security Engineer (Cyber Threat Hunting)
Core
Proactive Cyber Threat Hunter leading hypothesis-driven threat hunting across enterprise systems to identify subtle anomalies and IOCs using advanced analytics and behavioral baselines.
Role type
Staff Cyber Threat Hunter (Proactive Security)
Builds
Reusable threat hunting playbooks, automated processes, and detection capabilities for the Proactive Security GHOST team.
Domain
Cybersecurity, Threat Intelligence, Enterprise Security Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Threat hunting, Adversary tradecraft (TTPs), MITRE ATT&CK framework, SIEM/EDR/NDR telemetry analysis, Multi-domain log analysis, Python/PowerShell scripting, Behavioral baselining, Statistical analysis, Incident response collaboration, Technical mentoring
Preferred skills
Adversary simulation, Malware analysis, Network forensics, EDR/XDR internals, Hypothesis-driven hunting research, Security control gap analysis, Enterprise log platforms (Splunk/ELK/QRadar), Query languages (SPL/KQL/SQL)
Technologies
Python, PowerShell, Splunk, ELK, UEBA, QRadar, SIEM, EDR, NDR, Cloud, IAM, Network platforms
Responsibilities
Lead proactive threat hunting activities across the enterprise using attacker TTPs and threat intelligence; Analyze large multi-domain log datasets to identify subtle anomalies and IOCs; Apply and evolve cyber defense frameworks (MITRE ATT&CK, Diamond Model, NIST); Investigate telemetry from diverse security data sources with focus on cross-domain correlation; Collaborate with SOC, IR, and Detection Engineering teams to operationalize findings; Develop automated hunting playbooks and processes; Provide technical mentoring to the security group.
Seniority
Staff, hands-on IC with strategic impact