About The Position

This position contributes to incident response efforts, analyzes threat actors' tactics, techniques, and procedures (TTPs), and develops actionable reports for stakeholders. The role leverages expertise in cutting-edge technologies and ethical artificial intelligence to maintain the organization’s robust cybersecurity posture. A key focus is on researching and developing innovative tools, techniques, and processes to strengthen the security ecosystem. This role requires the ability to research attackers’ TTPs and build custom profiles and content based on their behaviors, enabling enhanced detection and response capabilities. The Threat Hunter will design custom attacks and security emulations to test and improve organizational defenses while also training staff to bolster overall security readiness. Maintaining a high level of technical knowledge through continuous learning, networking, and professional development is integral to this role. Additionally, this position involves creating and refining SIEM, EDR, and SOAR content, analyzing forensic artifacts to uncover security gaps, and driving collaboration across cross-functional teams to deliver solutions for complex cybersecurity challenges. Strong communication skills, a commitment to FirstEnergy's core values, and an ability to translate technical findings into actionable strategies are essential for success in this role.

Requirements

  • Bachelor's degree in computer science, Information Security, or similar discipline is required with 1 to 3 years of experience
  • Industry standard certifications will be considered such as OSCP, GIAC (GCTI, GCIH, GREM, GCFA), CISSP and HTB CPTS
  • A bachelor's degree in another field with 4 years relevant industry experience in cyber/information security will be considered
  • In lieu of a degree, 3 years of related experience is required
  • Related experience includes but is not limited to: SOC (Security Operations Center) experience, IT Security experience in detection, triage, investigation, and remediation of security incidents within a network
  • Understanding of adversarial techniques (i.e., MITRE ATT&CK framework)
  • Understanding programming/scripting code (Python, PowerShell, Bash. C#)
  • Understanding of both Linux and Windows operating systems
  • Demonstrate strong communication skills, both verbal and written
  • Demonstrate creative problem solving and solutioning
  • Ability to work effectively, independently and within a team environment
  • Ability to handle, protect and preserve highly confidential information
  • Ability to learn independently and from others
  • Ability to find answers effectively using open-sourced information
  • Understanding of networking concepts and technologies
  • Must be organized and comfortable with ongoing changes in priorities
  • Must be able to work independently with minimal supervision
  • Minimum of 3 years professional experience in a cyber related function (for Level II)
  • Strong foundation in cyber security (for Level II)
  • Ability to create, detect, and enhance security content (for Level II)
  • Working knowledge of relevant experience (for Level II)
  • Minimum of 5 years professional experience in a cyber-related function (for Level III)
  • Experience and subject matter expert knowledge in at least one major discipline required (for Level III)
  • Demonstrable subject matter expert knowledge in Threat Emulation, Threat Hunting, or Threat Intelligence (for Level III)
  • Proven ability to mentor and guide others in creating, detecting, and enhancing security content (for Level III)
  • In-depth knowledge of relevant work experience (for Level III)

Responsibilities

  • Proactively search for and identify vulnerabilities in the organization’s security systems
  • Collaborate with the SOC s to convert intelligence into actionable defensive capabilities
  • Evaluate intelligence sources and feeds for relevance, accuracy, timeliness, and operational value to reduce unnecessary alerting and noise
  • Analyze threat actors' TTPs (Tactics, Techniques, and Procedures) to provide detailed technical reports with a high level of attention to detail for stakeholders, as well as assist in developing related content
  • Analyze threat reporting from commercial intelligence platforms, OSINT, government advisories, ISACs, and trusted industry partner
  • Research and enrich IOCs, including domains, IP addresses, URLs, file hashes, certificates, and adversary infrastructure
  • Monitor geopolitical events, vulnerabilities, cybercriminal activity, and nation-state campaigns for potential organizational impact
  • Act as a cybersecurity subject matter expert (SME) to support the SOC, providing consultancy and advice on the delivery of security solutions
  • Maintain a high level of expertise in log analysis, malware reverse engineering, memory forensics, network and endpoint telemetry, and behavioral analytics
  • Assist with incident response for operational and cybersecurity related issues
  • Identify process improvements to further advance security operations
  • Improve detections in SIEM, EDR, and SOAR platforms by fine-tuning existing content and developing new custom rules and alerts
  • Re-evaluate current controls and make recommendations for best practices based on new information received in an ever-evolving threat landscape
  • Research new capabilities from both open and closed sourced technologies to find opportunities to enhance the Security Operation Center (SOC) ecosystem
  • Participate with cross-functional team members in issue identification, process impacts and solution development for cybersecurity projects and initiatives
  • Educate and influence IT, Cyber Security and Business stakeholders to better understand existing security risks, best practices, and infrastructure designs/changes required to support business and IT strategies securely
  • Champions FE’s Core Values & Behaviors, through coaching and by personal example
  • Assist with metrics, reporting, and other SOC communications
  • Process and share information with other FirstEnergy security teams

Benefits

  • competitive pay plus incentive compensation
  • company-sponsored pension plan
  • 401(k) savings plan with matching employer contribution
  • choice of medical, prescription drug, dental, vision, and life insurance programs
  • skills development training with tuition reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service