Cyber Threat Hunter
Core
Senior individual contributor building behavior-based detection capabilities and signal engineering to identify adversary activity before incidents become material using enterprise telemetry, data science, and AI-enabled workflows.
Role type
Senior IC Cyber Threat Hunter / Detection Engineer
Builds
Behavior-based detections, signal pipelines, and operational detection logic for proactive threat hunting
Domain
Cybersecurity, Threat Intelligence, Data Science
Deliverable
production ML models | product features
Required skills
behavior-based detection engineering, digital forensics and incident response (DFIR), malware analysis, reverse engineering, Python for data analysis and automation, statistical modeling, machine learning techniques, threat research, red teaming/purple teaming, MITRE ATT&CK classification
Preferred skills
Google SecOps or Chronicle detection content development, API integration for security tools, detection-as-code practices (Git, CI/CD), AI-assisted development tools
Technologies
Python, statistical modeling, machine learning, MITRE ATT&CK, Google SecOps, Chronicle
Responsibilities
Build and maintain behavior-based detections across identity, endpoint, cloud, and network telemetry; Translate attacker techniques into testable detection logic; Define telemetry and normalization requirements; Apply statistical methods and ML to develop behavioral models; Validate suspicious behaviors using DFIR methods; Partner with security teams to operationalize detections with triage guidance and playbook alignment
Seniority
Senior, hands-on IC