Senior Threat Hunter / Detection Engineer
@ Neshent TechnologiesNeshent Technologiesneshenttechnologies.com
Senior Threat Hunter / Detection Engineer
Remote, US
Posted 3 days ago
About the job
Our company specializes in cybersecurity, focusing on threat hunting, detection engineering, and incident response. This role involves developing detection rules, investigating security incidents, and collaborating with security teams to enhance defenses.
Requirements
- 5–7+ years cybersecurity experience
- Hands-on with Microsoft Defender
- Expertise in KQL and SPL
- Experience with threat hunting
- Knowledge of MITRE ATT&CK
Qualifications
- Bachelor's degree in related field
- Strong analytical skills
- Experience in incident response
- Excellent communication skills
Full job description
Roles & Responsibilities
- Conduct hypothesis-driven threat hunts across endpoints, identities, networks, and security data sources.
- Leverage Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR) for threat investigation, hunting, and automated response.
- Develop advanced Kusto Query Language (KQL) queries for threat hunting and detection.
- Use Splunk Enterprise Security and SPL to perform complex security investigations, correlation, and threat hunting.
- Develop and tune high-fidelity detection rules while minimizing false positives.
- Apply the MITRE ATT&CK framework to threat hunting, detection engineering, and adversary analysis.
- Translate threat intelligence and attack research into actionable detection and hunting use cases.
- Investigate security incidents using endpoint forensics, malware analysis, and security analytics.
- Support containment, eradication, and recovery activities for complex incidents.
- Develop and maintain incident response playbooks, procedures, and technical documentation.
- Preserve forensic evidence and follow appropriate evidence-handling and chain-of-custody practices.
- Analyze Windows systems, processes, authentication activity, network traffic, and common attack vectors.
- Develop scripts and automation using PowerShell, Python, or similar technologies.
- Collaborate with incident response, detection engineering, IT operations, and other security teams.
- Provide technical training, mentoring, and knowledge transfer to security teams.
- Develop training materials and explain complex security concepts to audiences with varying technical skill levels.
- Identify opportunities to improve security tools, processes, detections, and threat-hunting capabilities.
- Support security tool implementations, migrations, and optimization initiatives.
Required Skills
- 5–7+ years of cybersecurity experience with a focus on threat hunting, detection engineering, and/or incident response.
- At least 2 years of hands-on enterprise experience with Microsoft Defender for Endpoint (MDE).
- Strong experience with Microsoft 365 Defender/XDR and MDE investigation capabilities.
- Advanced KQL skills for threat hunting and detection development.
- Expert-level experience with Splunk Enterprise Security and strong SPL skills.
- Experience with Splunk UBA or similar behavioral analytics platforms.
- Strong knowledge of MITRE ATT&CK, adversary TTPs, and threat intelligence.
- Demonstrated experience conducting threat hunts that resulted in actionable security improvements.
- Hands-on experience with incident response, endpoint forensics, and malware analysis.
- Strong understanding of Windows internals, Active Directory, Azure AD, Kerberos, and NTLM.
- Knowledge of network protocols, traffic analysis, and common attack techniques.
- Experience with scripting or automation using PowerShell, Python, or similar languages.
- Strong analytical, problem-solving, documentation, and communication skills.
- Ability to work independently and collaborate effectively with distributed, cross-functional teams.
Preferred Skills
- Experience supporting or leading security tool migrations or implementations.
- Experience with Splunk UBA, SIEM architecture, data onboarding, and platform optimization.
- Knowledge of NIST and SANS incident response frameworks.
- Experience developing incident response playbooks and security procedures.
- Experience with detection engineering and reducing false positives.
- Strong technical training, mentoring, and knowledge-transfer experience.
- Ability to translate threat research into practical defensive controls and security improvements.
- Experience working in a fully remote and distributed team environment.
Show full description
Similar jobs in Remote, US
- O
Protective Intelligence & Threat Analyst
OpenAI · US - Remote
Posted 5 days ago - S
Staff Security Engineer - Threat Detection
Snowflake · US, Remote
Posted 2 weeks ago - F
Senior/Staff Data Scientist
FloatMe · Remote
Posted 3 weeks ago - P
Senior/Staff Software Engineer, Search & Retrieval Infrastructure
Pinecone · US Remote
Posted 2 weeks ago - W
Senior Director, Client Strategy (Senior Media Director)
Wpromote · Remote, United States
Posted 1 week ago - V
Senior Accountant
Virta Health · Remote
Posted 6 days ago