Quick Overview
Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
SplunkActive DirectoryAzureOnboardingPowerShellPython
Job Description
Job Title :: Threat Hunting Consultant
Location :: Remote
Type ::Fulltime role
Microsoft Security Stack Expertise
- Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)
- Proficiency with Microsoft 365 Defender (XDR) unified security operations
- Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection
- Deep understanding of MDE investigation capabilities, automated response features, and integration architecture
SIEM and Analytics
- Expert-level Splunk Enterprise Security experience
- Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries
- Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
- Knowledge of SIEM architecture, data onboarding, and optimization techniques
Threat Hunting and Detection Engineering
- Demonstrated experience conducting hypothesis-driven threat hunts
- Strong understanding of MITRE ATT&CK framework and its practical application
- Ability to translate threat intelligence and attack research into actionable hunting queries
- Experience developing high-fidelity detection rules with low false positive rates
- Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups
Incident Response
- Proven track record in hands-on incident response and investigation
- Expertise in endpoint forensics and malware analysis
- Familiarity with incident response frameworks (NIST, SANS) and playbook development
- Experience with containment, eradication, and recovery procedures for complex security incidents
- Understanding of forensic evidence preservation and chain of custody requirements
Technical Foundations
- Deep understanding of Windows internals, process behaviors, and security architecture
- Knowledge of network protocols, traffic analysis, and common attack vectors
- Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
- Understanding of scripting and automation (PowerShell, Python, or similar)
Knowledge Transfer and Teaching Ability
- Proven ability to explain complex technical concepts to varied technical audiences
- Experience developing and delivering technical training or mentorship programs
- Patience and commitment to building team capability, not just completing tasks
- Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collabo ration
- Excellent written communication skills for documentation and reporting
- Strong verbal communication skills for training delivery and incident collaboration
- Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)
- Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
- Self-directed work style with ability to identify priorities independently
- Creative problem-solving approach to novel security challenges
- Intellectual curiosity and continuous learning mindset
- Ability to translate theoretical threat research into practical defensive measures
- Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response
- At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
- Demonstrated experience conducting threat hunts that led to actionable security improvements
- Previous experience supporting or leading security tool migrations or implementations (highly valued)
- Certifications (Preferred)
Highly Valued:
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Threat Intelligence Analyst (CTIA)
Relevant:
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Splunk Enterprise Security Certified Admin
- CISSP, CISM, or equivalent security management certification
- Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective
Knowledge Transfer and Teaching Ability
- Proven ability to explain complex technical concepts to varied technical audiences
- Experience developing and delivering technical training or mentorship programs
- Patience and commitment to building team capability, not just completing tasks
- Ability to adapt teaching style to different learning preferences and skill levels
Communication and Collaboration
- Excellent written communication skills for documentation and reporting
- Strong verbal communication skills for training delivery and incident collaboration
- A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)
- Comfort operating in a fully remote environment with distributed team members
Problem Solving and Initiative
- Self-directed work style with ability to identify priorities independently
- Creative problem-solving approach to novel security challenges
- Intellectual curiosity and continuous learning mindset
- Ability to translate theoretical threat research into practical defensive measures
Similar jobs
- UA
Automation Engineer
NewUS AMR-Jones Lang LaSalle Americas, Inc.
Schofield, Wisconsin🇺🇸On-site1 minute agoRoboticsLESSTechnology - MC
Principle Enterprise Architect
NewMCKESSON
Irving, Texas🇺🇸$178.5k - $297.5k/yrHybrid1 minute agoGoogle CloudKubernetesTerraformTechnology - JC
SAP FICO Consultant (AMS)
NewJubilant Consulting
San Bernardino, CA🇺🇸On-siteYesterdayTechnology - MU
Need Data Testing - Databricks Automation Engineer @ Atlanta, GA (Hybrid)
NewMomento USA LLC
Atlanta, GA🇺🇸HybridYesterdaySQLDatabricksPython+1Technology - AE
Principal Embedded Software Engineer with Security Clearance
NewAnonymous Employer
Denver, CO🇺🇸HybridYesterdayEmbedded SystemsAssemblyC+++3Technology - DI
Intermediate Cloud / Artificial Intelligence (AI) Developer - Remote
NewDivIHN Integration Inc.
United States🇺🇸RemoteYesterdayDockerEncryptionAgile+5Technology