We are seeking a highly skilled and strategic Cyber Security Incident Response & Threat Intelligence expert to our security operations function and turn intelligence into actionable security improvements. This role bridges threat intelligence and detection engineering to strengthen our cybersecurity defenses.
Key Responsibilities
- Perform hypothesis-driven and intelligence-led threat hunts across multiple data sources
- Detect and investigate suspicious activity using EDR/XDR and SIEM tools
- Ingest and correlate threat intelligence feeds with internal telemetry
- Operationalize IOCs and map activity to MITRE ATT&CK;
- Develop and tune detection rules and alerts
- Produce explicit, actionable reports for technical and business stakeholders
- Support incident investigations and response efforts
Required Qualifications
- 5+ years of experience in threat hunting, intelligence, or incident response
- Experience with CrowdStrike (or similar), SIEM platforms (Splunk, Sentinel)
- Strong understanding of MITRE ATT&CK; and threat intelligence concepts
- Proficiency in KQL, SQL, or SPL
Preferred
- Relevant certifications (GIAC, CISSP, CEH, OSCP)
- Scripting experience (Python, PowerShell)
- Exposure to TIPs, SOAR, and cloud environments