⚡ Availability: Immediate Joiners / Serving Notice Period Preferred
? What You'll Do
- Conduct proactive threat hunting across endpoint, identity, email, and network telemetry to identify advanced attacker behaviors.
- Develop and execute hypothesis-driven hunts (IF–THEN) aligned with MITRE ATT&CK; techniques.
- Investigate complex security events using evidence-driven analysis and validate findings through available telemetry.
- Identify and investigate advanced techniques such as MFA bypass, RMM abuse, Living-off-the-Land (LOLBins), persistence, credential access, and cloud abuse.
- Translate emerging threats and attacker behaviors into actionable detection logic.
- Create and optimize detections across SIEM/EDR platforms such as Splunk, CrowdStrike, and Microsoft 365 Defender.
- Use advanced queries to investigate threats and identify suspicious patterns across security telemetry.
- Document investigations, findings, detection gaps, and recommendations in audit-ready and leadership-ready formats.
- Collaborate with Detection Engineering and Security Operations teams to close visibility gaps and improve detection coverage.
- Participate in threat hunting forums and contribute to improving investigation quality and consistency.
✅ What We're Looking For
- Strong hands-on experience with SIEM and EDR platforms, particularly Splunk, CrowdStrike,
and Microsoft 365 Defender.
- Deep understanding of attacker tradecraft and MITRE ATT&CK;.
- Advanced query-building skills using SPL, LogScale, KQL, or similar query languages.
- Strong experience detecting stealthy attacker techniques including LOLBins, persistence, credential access, and cloud abuse.
- Ability to perform evidence-based investigations and reduce false positives.
- Strong understanding of detection engineering and threat hunting methodologies.
- Excellent documentation and reporting skills with the ability to create leadership-ready summaries.
- Strong analytical mindset with a focus on hypothesis-driven threat hunting.
⭐ Preferred Skills
- Splunk Analyst
- Splunk Content Development
- CrowdStrike
? What Makes You Successful
- Strong investigative and analytical skills.
- Ability to think like an attacker and identify abnormal behaviors.
- Strong hands-on experience with SIEM/EDR investigation and detection development.
- Ability to turn threat hypotheses into effective hunts and actionable detections.
- Robust collaboration with SOC and Detection Engineering teams.
? Interested candidates? Apply or DM your updated resume.