Sr Threat Hunting (Lead) (India)

Sr Threat Hunting (Lead) (India)

27 Sep
|
Elixir 360
|
India

27 Sep

Elixir 360

India

Job Summary

At Allstate, outstanding things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

We are seeking a Senior Threat Hunter to lead hypothesis-driven, intelligence-led hunts across enterprise, cloud, and OT/IoT environments. This role proactively identifies adversary tradecraft that evades existing detections, operationalizes findings into durable detection logic, and partners with Threat Intelligence, Detection Engineering, IR, Exposure Management, and REM to reduce dwell time and shrink the enterprise exposure plane. The hunter will leverage MITRE ATT&CK;, the Pyramid of Pain, and the Diamond Model to drive measurable risk reduction.

Key Responsibilities

- Lead hypothesis-driven, intelligence-led hunt campaigns from formulation through reporting, mapped to MITRE ATT&CK.;

- Design and execute custom analytics against large-scale security telemetry (SIEM, EDR/XDR, identity, cloud, network) to uncover adversary tradecraft that evades existing detections.

- Perform identity-centric hunting across Entra ID, Active Directory, and SaaS platforms - token theft, session hijacking, MFA bypass, OAuth abuse, and conditional access circumvention.

- Conduct cloud-native hunting across AWS, Azure, M365, and SaaS control planes, including audit logs, identity events, and workload telemetry.

- Convert hunt findings into durable detections, signatures, and SOAR playbooks in partnership with Detection Engineering, closing the hunt-to-detect loop.





- Perform Deception Operations by defining adversary-aligned use cases, authoring detection requirements for deception-generated activity, and tuning signal vs. noise thresholds.

- Leverage AI and LLM-assisted tooling to accelerate hunting, including query generation, log summarization, entity pivoting, anomaly clustering, and large-scale pattern discovery across disparate telemetry sources.

- Hunt within AI and LLM environments, including enterprise copilots, internal/external LLM deployments, AI agents, RAG pipelines, model endpoints, and AI/ML infrastructure, for threats such as prompt injection, model abuse, data exfiltration via AI channels, agent hijacking, supply-chain compromise of models, and unauthorized model access.

- Produce post-hunt reports with explicit evidence and measurable outcomes tied to exposure reduction.

- Partner with Threat Intelligence to operationalize finished intel into targeted hunt missions and feed collection requirements upstream.

- Support purple-team exercises and validate detection efficacy against adversary emulation campaigns (Atomic Red Team, CALDERA, Stratus Red Team).

- Develop and maintain custom tooling and automation to support hunting, investigation, and analyst efficiency.

- Mentor junior hunters; contribute to internal knowledge bases, hunt libraries, and team training.

- Support Incident Response, Forensics, and Insider Threat / Fraud investigations as a senior technical resource when adversary expertise is needed.





- Serve as a liaison for Threat Services across Cyber Operations, communicating findings clearly to technical peers and executive leadership.

- Identify needs, drive solutions, and operate autonomously within strategic priorities.

Required Qualifications

- 7+ years of experience in security operations, with 4+ of those dedicated to threat hunting.

- Deep experience hunting in large, complex enterprise environments.

- Demonstrable experience executing MITRE ATT&CK-aligned; hunts with documented outcomes and detection handoff.

- Hands-on experience with up-to-date SIEM (Splunk, Sentinel, Elastic) and EDR/XDR (CrowdStrike, Defender, SentinelOne, Tanium).

- Demonstrated experience using AI/LLM-assisted tooling (eg, Security Copilot, custom GPTs, agentic workflows, embeddings-based analytics) to accelerate hunting, triage, and analytic development.

- Working knowledge of hunting in AI/LLM environments - familiarity with the MITRE ATLAS framework, OWASP Top 10 for LLM Applications, and common AI-specific threats (prompt injection, model theft, training data poisoning, agent abuse, sensitive data leakage through AI channels).

- Working knowledge of threat intelligence frameworks: Diamond Model, Kill Chain, and the Pyramid of Pain.

- Strong scripting and automation skills in Python, PowerShell, GO, and/or Bash.

- Deep understanding of common network and application stack protocols: TCP/IP, DNS, TLS, HTTP, SMTP, etc.

- Experience with signature and analytic development: CQL/KQL/S.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Sr Threat Hunting (Lead) (India)
🏢 Elixir 360
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr threat hunting (lead) (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: sr threat hunting (lead) (india) / india