4 дня назад
Security (L3 Threat Hunter)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security (L3 Threat Hunter) (Cybersecurity/SIEM): Proactively identifying malicious activity that has evaded traditional security controls by analyzing large-scale security telemetry, attacker tradecraft, and cyber threat intelligence with an accent on hypothesis-driven hunting and behavioral analysis. Focus on developing advanced queries, investigating emerging threats, and improving detection coverage across enterprise environments.
Location: Budapest, Hungary
Company
runs and reimagines mission-critical technology systems for leading businesses, using AI-powered insights to support smarter decisions and innovation.
What you will do
- Conduct intelligence-driven, behavioral, situational, and hypothesis-based threat hunts.
- Analyze large-scale security telemetry, attacker tradecraft, and cyber threat intelligence.
- Transform investigative findings into detection opportunities and security improvements.
- Investigate emerging threats and uncover hidden adversary activity across enterprise environments.
- Collaborate with Threat Intelligence, Detection Engineering, Incident Response, and SOC teams.
- Continuously improve detection coverage and customer cyber resilience.
Requirements
- At least 5 years of relevant cybersecurity industry experience in threat hunting, detection engineering, digital forensics, incident response, or penetration testing.
- Strong enterprise log analytics skills with platforms such as Microsoft Sentinel, QRadar, Elastic, Splunk, Palo Alto XSIAM, or similar.
- Experience conducting hypothesis-driven threat hunts using large-scale telemetry and security logs.
- Deep understanding of telemetry logs, attacker TTPs, intrusion lifecycles, and lateral movement.
- Advanced query development using KQL, SPL, ES|QL, SQL, or equivalent analytics languages.
- Strong analytical, problem-solving, structured, and investigative skills.
Nice to have
- Experience with MITRE ATT&CK, threat intelligence integration, malware analysis, network forensics, and EDR/XDR platforms.
- Scripting or data analytics experience with Python, PowerShell, or equivalent tools.
- Understanding of enterprise security controls, SIEM pipelines, and data correlation techniques.
- Relevant certifications such as GCFA, GCFE, eCTHP, GCIH, GCED, GNFA, OSCP, OSEP, OSWE, CRTO, GXPN, GPEN, or GDAT.
Culture & Benefits
- Full-time role in a flexible, hybrid-friendly work culture.
- Well-being programs supporting financial, mental, physical, and social health.
- Personalized development goals, continuous feedback, coaching, and hands-on learning.
- Access to certification and learning opportunities from Microsoft, Google, and Amazon.
- Inclusive culture focused on belonging, empathy, continuous learning, and shared success.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →