Senior Threat Hunting Researcher (Unit 42)
Core
Proactively hunt for suspicious behaviors, malware activity, and emerging threats across large-scale customer telemetry to identify gaps in security coverage.
Role type
Senior hands-on IC threat hunting researcher (detection engineering)
Builds
High-fidelity hunting logic, reusable detection opportunities, and evidence-based technical reports
Domain
Cybersecurity / Threat Intelligence / Managed Detection and Response (MDR)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery
Required skills
Threat hunting methodologies, incident investigation workflows, behavior-based detection concepts, XDR/EDR/SIEM platform analysis, complex query logic (XQL/SQL/KQL/SPL), detection quality analysis (true/false positives, signal-to-noise), coverage gap identification
Preferred skills
Python scripting, SQL automation, data science techniques (anomaly detection, clustering, behavioral baselining)
Technologies
XQL, SQL, KQL, SPL, XDR, EDR, SIEM, cloud platforms, identity platforms
Responsibilities
Hunt for suspicious behaviors and threat actor tradecraft across diverse telemetry; Build and tune hunting and detection logic across multiple data sources; Translate low-fidelity signals into high-fidelity hunting content; Investigate suspicious activity and communicate findings; Improve detection quality by reducing false positives and identifying coverage gaps; Collaborate with MDR, IR, and Product teams to improve protection
Seniority
Senior, hands-on IC