Serve as the senior technical authority for proactive threat hunting and adversary-focused analysis within the SOC. Lead development of the SOC threat-hunting methodology, hunt lifecycle, prioritization model, documentation standards, quality criteria, and integration with watch operations and engineering. Proactively search across enterprise network, endpoint, identity, SIEM, and other security telemetry for indicators of compromise and behavioral evidence of malicious activity that has evaded automated detection. Develop and direct advanced hunt campaigns based on threat intelligence, adversary TTPs, mission priorities, predictive/advanced analytics, environmental changes, incidents, and identified detection gaps. Assess and validate analytical or predictive models and determine whether identified patterns represent meaningful adversary behavior, benign activity, or require additional collection and analysis. Lead complex analytical pivots across multiple sources and enclaves and direct expansion of scope when evidence indicates broader adversary activity. Ensure actionable hunt findings are transitioned to incident response, watch operations, detection engineering, or security engineering with clear evidence and recommended actions. Provide senior technical input to daily/weekly SOC reporting, leadership briefings, threat assessments, and defensive priorities. Establish reusable hunt playbooks, analytical techniques, ATT&CK mappings, queries, knowledge repositories, and lessons-learned processes. Mentor threat analysts at all levels and provide technical leadership for exercises, training, and proficiency development. Identify telemetry and detection blind spots and work with engineering teams to improve collection, analytics, enrichment, and automated detection coverage.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior