Cyber Threat Intelligence Hunter (Unit 42)
Core
Proactive, intelligence-led threat hunting across customer environments to identify adversary traces and behavioral fingerprints.
Role type
Tactical cyber threat intelligence hunter (IC)
Builds
Actionable hunting hypotheses, investigation workflows, hunting queries, and customer-facing findings
Domain
Cybersecurity / Threat Intelligence / DFIR
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
tactical threat hunting, cyber threat intelligence (CTI), DFIR, advanced security operations, mapping intrusions, translating intelligence to hunting hypotheses, log-based query development
Preferred skills
incident response, managed services, Python, SQL, malware analysis, security research
Technologies
endpoint telemetry, network telemetry, cloud telemetry, identity telemetry, Unit 42 research, adversary campaigns, malware activity, infrastructure, indicators, TTPs, IOCs
Responsibilities
Analyze public and private threat intelligence and adversary TTPs; Translate intelligence into hunting hypotheses and queries; Execute hunting workflows and investigate detections; Compose professional reports on findings; Monitor threat landscape for emerging campaigns; Collaborate with detection engineers and incident responders; Escalate high-impact security events
Seniority
Mid-Senior, hands-on IC