Назад
Company hidden
1 час назад

Threat Hunter (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Hunter (Cybersecurity) (SIEM/EDR/MSSP): Proactively identifying and investigating cyber threats across multi-tenant client environments using threat intelligence, behavioral analytics, and endpoint and network telemetry with an accent on threat hunting, detection engineering, and incident response. Focus on modeling attacker behavior, analyzing malware and host/network forensics, tuning SIEM and EDR detections, and improving client security controls.

Location: Nashville, Tennessee, United States (Remote)

Company

Technology services provider delivering managed and professional services across cloud infrastructure, networking, cybersecurity, data and AI, automation, intelligence, and enterprise service management.

What you will do

  • Perform proactive threat hunting across multi-tenant client environments using SIEM, EDR, NDR, and other telemetry sources.
  • Model attacker behavior, test hunting hypotheses, analyze indicators of compromise, and investigate anomalies and analyst escalations.
  • Create and tune SIEM rules, correlation logic, signatures, and other detection content to improve threat visibility.
  • Support incident response activities, including containment, eradication, recovery, and post-incident recommendations.
  • Document hunting processes and findings, advise clients on security control improvements, and participate in onboarding, security reviews, and incident briefings.
  • Maintain and enhance client security solutions, including firewalls, IDS/IPS, DLP, vulnerability scanners, PAM, and endpoint protection tools.

Requirements

  • Bachelor’s degree or diploma in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
  • 3+ years of hands-on experience in threat hunting, incident response, SOC analysis, or threat intelligence, preferably in a service provider environment.
  • Understanding of Windows, Linux, authentication protocols, networking fundamentals, cloud security platforms such as AWS, Azure, and GCP, and frameworks including MITRE ATT&CK and NIST.
  • Proficiency with EDR and SIEM tools such as CrowdStrike, SentinelOne, Splunk, or QRadar.
  • Experience with malware analysis, packet capture analysis, host and network forensics, and scripting or automation using Python or PowerShell.
  • Strong analytical, communication, troubleshooting, prioritization, and client-facing skills, with discretion when handling sensitive client data.

Nice to have

  • Certifications such as GCIH, GCFA, GCIA, Security+, CEH, or CISSP.

Culture & Benefits

  • Flexible work schedule and remote work options.
  • Health, dental, and vision insurance plans.
  • Retirement savings plan with employer matching.
  • Professional development and training opportunities.
  • Collaborative and inclusive work culture with opportunities for career growth.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →