This role leads proactive, intelligence-driven hunting to uncover advanced threats while managing critical Incident Response (IR) activities. The Lead will develop hypotheses based on MITRE ATT&CK, analyze logs/EDR data to minimize dwell time, and mentor staff to strengthen the overall security posture and detection capabilities. The Lead will examine new AI tools and determine which if any, bring value to the process and help implement any approved solutions. A typical day will include... Proactive Threat Hunting: Develop and execute hypothesis-driven hunts using EDR, SIEM, and network traffic analysis to find threats bypassing existing defenses. Incident Response Leadership: Lead complex investigations and CSIRT activities, providing technical expertise during containment, eradication, and post-incident analysis. Threat Intelligence Integration: Analyze adversary Tactics, Techniques, and Procedures (TTPs) and integrate intelligence feeds to drive targeted hunting scenarios. Detection Engineering: Collaborate with security engineering to convert hunting discoveries into permanent actionable alerts, reducing future risk. Mentorship & Strategy: Mentor junior analysts, define the technical standards for hunting workflows, and report findings to stakeholders.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed