The Threat Hunter supports a Cybersecurity Operations Division by proactively identifying malicious activity, uncovering hidden threats, and strengthening the organization’s defensive posture. This role conducts hypothesis‑driven hunts across enterprise networks, leveraging threat intelligence, adversary TTPs, and behavioral analytics to detect early indicators of compromise. The hunter performs deep‑dive analysis of logs, endpoint telemetry, and network data to validate findings, uncover patterns, and escalate confirmed threats to SOC and IR teams. This position contributes to the continuous improvement of detection capabilities by developing new analytics, refining existing logic, and identifying visibility gaps across the environment. The hunter documents repeatable workflows, produces high‑quality hunt reports, and briefs leadership and mission stakeholders on emerging threats, hunt outcomes, and recommended defensive improvements. The role also collaborates closely with SOC, IR, CTI, and platform engineering teams to operationalize intelligence, integrate new data sources, and mature the organization’s hunt program.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level