Назад
Company hidden
20 часов назад

Threat Expert (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
Bulgaria
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat Expert (Cybersecurity): Managing cyber threat intelligence, proactive threat hunting, and detection content for a Security Operations Center with an accent on MITRE ATT&CK-driven analysis, SIEM/EDR detections, and customer-facing reporting. Focus on leading hypothesis-driven hunts, translating intelligence into defensive capabilities, and supporting complex incident investigations and response.

Location: Sofia, Bulgaria; in-person collaboration is prioritized

Company

hirify.global is a Fortune 500 global IT services company delivering technical solutions across industries and geographies.

What you will do

  • Monitor threats, campaigns, and emerging risks across open, commercial, and closed intelligence sources.
  • Lead hypothesis-driven threat hunts using cyber threat intelligence and MITRE ATT&CK techniques.
  • Maintain threat intelligence platforms, hunt playbooks, and documented findings with actionable outcomes.
  • Produce tactical, operational, and strategic threat intelligence and threat hunting reports for SOC teams, customers, and leadership.
  • Contribute to SIEM and EDR detection rules and content based on intelligence and hunt findings.
  • Support security operations teams during investigations, incident response, and threat management improvement initiatives.

Requirements

  • Degree or diploma in computer science, computer engineering, cyber defense, computer forensics, management information systems, or equivalent recognized security certifications.
  • 2–3 years of hands-on experience with SIEM, EDR, or threat intelligence platforms.
  • Working knowledge of MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain.
  • Fluent written and verbal English is required.
  • Experience with security operations, intrusion detection, proxy support, security device administration, compliance monitoring, and reporting.
  • Technical experience with Wireshark, Linux, SIEM and XDR tools such as Microsoft Sentinel, ArcSight, Splunk, Sumo Logic, Microsoft Defender, CrowdStrike, Carbon Black, or 7AI.

Culture & Benefits

  • 24 days of paid vacation, medical and life insurance, and monthly food vouchers.
  • Premium learning platforms, company-sponsored certifications, and continuous development opportunities.
  • Employee recognition and referral programs, discounts, and special offers.
  • 24/7 wellbeing support for employees and their families.
  • International environment with in-person collaboration, flexibility for individual work styles, and community initiatives.

Hiring process

  • Submit a CV in English.
  • Only shortlisted candidates will be contacted.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →