Search Jobs

Search by job, company or skills

Threat Hunter

Threat Hunter

Lintasarta
5-9 Years
  • Posted 13 hours ago
  • Be among the first 10 applicants

Job Description

Roles and Responsibilities

Proactive Threat Hunting & Hypotheses

● Hypothesis Generation: Develop and execute proactive, data-driven threat hunting hypotheses based on real-world attacker behaviors, emerging zero-days, and structural infrastructure risks.

● Stealth Adversary Detection: Scrutinize telemetry data across endpoints, cloud microservices, and network traffic to isolate advanced persistent threats (APTs), living-off-the-land attacks, and insider threats.

● Data Aggregation: Build, structure, and refine large-scale data analytics pipelines, profiling normal environmental baselines to catch subtle behavioral anomalies

Advanced Detection Engineering & Intelligence

● Operationalizing Threat Intel: Analyze tactical threat intelligence, ingest Indicators of Behavior (IoBs), and map advanced persistent threat actor tactics directly to the MITRE ATT&CK framework.

● Content Development: Translate successful threat hunting discoveries into long-term automated detection engineering logic (SIEM rules, EDR watchlists, YARA/Sigma rules).

● Root-Cause Analysis: Conduct deep post-incident forensics on critical network events, uncovering structural architectural flaws to recommend permanent hardening mitigations.

Strategic Leadership & Knowledge Share

● Architectural Advisory: Partner directly with security architecture, engineering, and infrastructure teams to design comprehensive log-ingestion policies and visibility maps.

● Tier Elevation: Conduct technical knowledge-sharing workshops, table-top exercises, and write analytical documentation to upskill Tier-1 and Tier-2 analysts.

Technical Skills & Tools

Advanced Forensic Analytics & Data Science

● Advanced SIEM & Data Lakes: Mastery of complex log manipulation, correlation, and statistical behavioral mapping using Splunk (SPL), Microsoft Sentinel (KQL), or custom Jupyter Notebook integrations.

● Telemetry Extraction: Deep technical expertise pulling artifact footprints from memory spaces, master file tables (MFT), event logs, and kernel structures via tools like Velociraptor or KAPE.

● Scripting & Tool Development: High proficiency in Python, PowerShell, Go, or SQL to query enterprise telemetry data, parse massive log sets, and automate hunting routines via APIs.

Infrastructure & Behavioral Profiling

● Cloud & Hybrid Expertise: Expert knowledge tracking identity perimeters and service-principal compromises across distributed AWS, Azure, or GCP environments.

● Behavioral Detection Engineering: Mastery using standardized signature and rule syntaxes, specifically Sigma (for log detection) and YARA (for file/memory analysis).

Experience & Qualifications

● Total Security Experience: Minimum of 5–7+ years of dedicated technical experience in specialized cybersecurity domains, such as Digital Forensics and Incident Response (DFIR), Penetration Testing, or Advanced SOC operations.

● Hunting Track Record: At least 2–3 years of proven, documented experience specifically conceptualizing and executing structured threat hunts in enterprise environments.

Preferred Professional Certifications

● Advanced Cyber Defense:

GIAC Certified Forensic Analyst (GCFA)

GIAC Advanced Smartphone Forensics / Network Forensics (GNFA)

GIAC Cyber Threat Intelligence (GCTI)

● Offensive/Defensive Mastery:

Offensive Security Certified Professional (OSCP)

eLearnSecurity Certified Threat Hunter (ECTHP)

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Velociraptor

Jupyter Notebook

KAPE

YARA

Splunk SPL

Microsoft Sentinel KQL

Advanced Forensic Analytics

About Company