Threat Hunter
Lintasarta- Posted 13 hours ago
- Be among the first 10 applicants
Job Description
Roles and Responsibilities
Proactive Threat Hunting & Hypotheses
● Hypothesis Generation: Develop and execute proactive, data-driven threat hunting hypotheses based on real-world attacker behaviors, emerging zero-days, and structural infrastructure risks.
● Stealth Adversary Detection: Scrutinize telemetry data across endpoints, cloud microservices, and network traffic to isolate advanced persistent threats (APTs), living-off-the-land attacks, and insider threats.
● Data Aggregation: Build, structure, and refine large-scale data analytics pipelines, profiling normal environmental baselines to catch subtle behavioral anomalies
Advanced Detection Engineering & Intelligence
● Operationalizing Threat Intel: Analyze tactical threat intelligence, ingest Indicators of Behavior (IoBs), and map advanced persistent threat actor tactics directly to the MITRE ATT&CK framework.
● Content Development: Translate successful threat hunting discoveries into long-term automated detection engineering logic (SIEM rules, EDR watchlists, YARA/Sigma rules).
● Root-Cause Analysis: Conduct deep post-incident forensics on critical network events, uncovering structural architectural flaws to recommend permanent hardening mitigations.
Strategic Leadership & Knowledge Share
● Architectural Advisory: Partner directly with security architecture, engineering, and infrastructure teams to design comprehensive log-ingestion policies and visibility maps.
● Tier Elevation: Conduct technical knowledge-sharing workshops, table-top exercises, and write analytical documentation to upskill Tier-1 and Tier-2 analysts.
Technical Skills & Tools
Advanced Forensic Analytics & Data Science
● Advanced SIEM & Data Lakes: Mastery of complex log manipulation, correlation, and statistical behavioral mapping using Splunk (SPL), Microsoft Sentinel (KQL), or custom Jupyter Notebook integrations.
● Telemetry Extraction: Deep technical expertise pulling artifact footprints from memory spaces, master file tables (MFT), event logs, and kernel structures via tools like Velociraptor or KAPE.
● Scripting & Tool Development: High proficiency in Python, PowerShell, Go, or SQL to query enterprise telemetry data, parse massive log sets, and automate hunting routines via APIs.
Infrastructure & Behavioral Profiling
● Cloud & Hybrid Expertise: Expert knowledge tracking identity perimeters and service-principal compromises across distributed AWS, Azure, or GCP environments.
● Behavioral Detection Engineering: Mastery using standardized signature and rule syntaxes, specifically Sigma (for log detection) and YARA (for file/memory analysis).
Experience & Qualifications
● Total Security Experience: Minimum of 5–7+ years of dedicated technical experience in specialized cybersecurity domains, such as Digital Forensics and Incident Response (DFIR), Penetration Testing, or Advanced SOC operations.
● Hunting Track Record: At least 2–3 years of proven, documented experience specifically conceptualizing and executing structured threat hunts in enterprise environments.
Preferred Professional Certifications
● Advanced Cyber Defense:
GIAC Certified Forensic Analyst (GCFA)
GIAC Advanced Smartphone Forensics / Network Forensics (GNFA)
GIAC Cyber Threat Intelligence (GCTI)
● Offensive/Defensive Mastery:
Offensive Security Certified Professional (OSCP)
eLearnSecurity Certified Threat Hunter (ECTHP)
More Info
Key Skills
Velociraptor
Jupyter Notebook
KAPE
YARA
Splunk SPL
Microsoft Sentinel KQL
Advanced Forensic Analytics
