20 часов назад
Threat Expert (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Expert (Cybersecurity): Managing cyber threat intelligence, proactive threat hunting, and detection content for a Security Operations Center with an accent on MITRE ATT&CK-driven analysis, SIEM/EDR detections, and customer-facing reporting. Focus on leading hypothesis-driven hunts, translating intelligence into defensive capabilities, and supporting complex incident investigations and response.
Location: Sofia, Bulgaria; in-person collaboration is prioritized
Company
is a Fortune 500 global IT services company delivering technical solutions across industries and geographies.
What you will do
- Monitor threats, campaigns, and emerging risks across open, commercial, and closed intelligence sources.
- Lead hypothesis-driven threat hunts using cyber threat intelligence and MITRE ATT&CK techniques.
- Maintain threat intelligence platforms, hunt playbooks, and documented findings with actionable outcomes.
- Produce tactical, operational, and strategic threat intelligence and threat hunting reports for SOC teams, customers, and leadership.
- Contribute to SIEM and EDR detection rules and content based on intelligence and hunt findings.
- Support security operations teams during investigations, incident response, and threat management improvement initiatives.
Requirements
- Degree or diploma in computer science, computer engineering, cyber defense, computer forensics, management information systems, or equivalent recognized security certifications.
- 2–3 years of hands-on experience with SIEM, EDR, or threat intelligence platforms.
- Working knowledge of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain.
- Fluent written and verbal English is required.
- Experience with security operations, intrusion detection, proxy support, security device administration, compliance monitoring, and reporting.
- Technical experience with Wireshark, Linux, SIEM and XDR tools such as Microsoft Sentinel, ArcSight, Splunk, Sumo Logic, Microsoft Defender, CrowdStrike, Carbon Black, or 7AI.
Culture & Benefits
- 24 days of paid vacation, medical and life insurance, and monthly food vouchers.
- Premium learning platforms, company-sponsored certifications, and continuous development opportunities.
- Employee recognition and referral programs, discounts, and special offers.
- 24/7 wellbeing support for employees and their families.
- International environment with in-person collaboration, flexibility for individual work styles, and community initiatives.
Hiring process
- Submit a CV in English.
- Only shortlisted candidates will be contacted.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →