Lead proactive threat hunting to identify and disrupt attacks before damage occurs.
Responsibilities
Conduct proactive threat hunting to identify malware, malicious behavior, and insider threats.
Build, evolve, and expand hunting tooling, techniques, and use-cases.
Integrate threat intelligence and dark web data into active hunting operations.
Advise engineering teams on platform enhancements to improve hunting effectiveness.
Work with clients to remediate threats and improve long-term security posture.
Required Skills
5+ years of experience in cybersecurity roles such as security engineering, SOC operations, digital forensics, penetration testing, or malware analysis.
Proven experience in endpoint-focused threat hunting.
Strong Python scripting skills, specifically for API integration, DB integration, data manipulation, and multiprocessing.
Ability to write clean code following Python best practices.
Experience working with large datasets to extract actionable intelligence.
Deep understanding of common malware activity on endpoints and operating system internals (Windows, Linux, OSX).
Practical knowledge of the MITRE ATT&CK framework and known APT group activity.
Experience utilizing EDR technologies and Cyber Threat Intelligence (CTI) tools.
Working knowledge of git, GCP, Amazon Cloud solutions, and Scrum methodologies.