Search

Cybersecurity Threat Hunter

PublishedPublished: 6/14/2022
Technology

Job Description

Job Description

Cybersecurity Threat Hunter


Overview

The Senior Threat Hunter creates underlying datasets used to design and deploy sophisticated analytical models, statistical techniques, and machine learning approaches to identify anomalous patterns, malicious activity, and emerging attacker tradecraft within large-scale security telemetry.

This position uses hunting strategy and methodology, collaborates with SOC, threat intelligence, incident response, and digital product teams to translate findings into detection logic, and drives automation and maturity of hunting capabilities across the organization. This role requires exploration and adoption of new technologies made available by IT engineering and cybersecurity teams.

Responsibilities

  • Creates datasets from endpoint, network, cloud, and identity telemetry, identifying adversary behaviors, anomalies, and indicators of compromise not caught by existing detections.
  • Advise and consult AI engineers on detect malicious patterns, behavioral anomalies, and emerging attacker tactics, techniques, and procedures (TTPs) at scale.
  • Serve as a data science point of contact with SOC, incident response, threat intelligence, and digital product teams improving response decisions.
  • Leverage and help shape threat intelligence (internal and external) programs to hypotheses and prioritize efforts against the most relevant adversary activity.
  • Evaluate, pilot, and drive adoption of new technologies and tooling provided by IT engineering and cybersecurity teams to advance AI capabilities.
  • Validate the effectiveness of AI models created by AI engineering team.
  • Operate with a high degree of autonomy and sound judgment, setting direction for hunting initiatives with minimal oversight.

Educational Requirements / Qualifications

  • Bachelor’s degree and six (6) years of experience in cybersecurity, threat hunting, or data science; four additional years of related experience may substitute for the degree.
  • Demonstrated experience conducting proactive threat hunting or intrusion analysis using security telemetry (endpoint, network, cloud, or identity data), with a track record of identifying novel or previously undetected threats.
  • Experience with SIEM, EDR, or other security data platforms, along with relational database management systems and open-source frameworks.
  • Expert knowledge of adversary tactics, techniques, and procedures, with experience applying frameworks such as MITRE ATT&CK.
  • Familiarity with the Risk Management Framework (RMF) process.
  • Relevant certifications (e.g., GCTI, GCFA, GNFA, OSCP, or equivalent) preferred.

\nCompany Description

IT Professional Services Firm focused on networking, UC, Cloud, security, automation, cyber security - www.quadtec.com

Company Description

IT Professional Services Firm focused on networking, UC, Cloud, security, automation, cyber security - www.quadtec.com

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...