Haystack
← Back to Jobs
Remote
Technology
SD

Threat Hunting Consultant

Stanley David and AssociatesUnited States🇺🇸United StatesPosted 20 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
SplunkActive DirectoryAzureOnboardingPowerShellPython

Job Description

Job Title :: Threat Hunting Consultant

Location :: Remote 

Type ::Fulltime role

 

Microsoft Security Stack Expertise

  • Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)
  • Proficiency with Microsoft 365 Defender (XDR) unified security operations
  • Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection
  • Deep understanding of MDE investigation capabilities, automated response features, and integration architecture

 

SIEM and Analytics

  • Expert-level Splunk Enterprise Security experience
  • Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries
  • Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
  • Knowledge of SIEM architecture, data onboarding, and optimization techniques

 

Threat Hunting and Detection Engineering

  • Demonstrated experience conducting hypothesis-driven threat hunts
  • Strong understanding of MITRE ATT&CK framework and its practical application
  • Ability to translate threat intelligence and attack research into actionable hunting queries
  • Experience developing high-fidelity detection rules with low false positive rates
  • Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups

 

Incident Response

  • Proven track record in hands-on incident response and investigation
  • Expertise in endpoint forensics and malware analysis
  • Familiarity with incident response frameworks (NIST, SANS) and playbook development
  • Experience with containment, eradication, and recovery procedures for complex security incidents
  • Understanding of forensic evidence preservation and chain of custody requirements

 

Technical Foundations

  • Deep understanding of Windows internals, process behaviors, and security architecture
  • Knowledge of network protocols, traffic analysis, and common attack vectors
  • Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
  • Understanding of scripting and automation (PowerShell, Python, or similar)

 

Knowledge Transfer and Teaching Ability

  • Proven ability to explain complex technical concepts to varied technical audiences
  • Experience developing and delivering technical training or mentorship programs
  • Patience and commitment to building team capability, not just completing tasks
  • Ability to adapt teaching style to different learning preferences and skill levels

 

Communication and Collabo ration

  • Excellent written communication skills for documentation and reporting
  • Strong verbal communication skills for training delivery and incident collaboration
  • Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)
  • Comfort operating in a fully remote environment with distributed team members

 

Problem Solving and Initiative

  • Self-directed work style with ability to identify priorities independently
  • Creative problem-solving approach to novel security challenges
  • Intellectual curiosity and continuous learning mindset
  • Ability to translate theoretical threat research into practical defensive measures
  • Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response
  • At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment
  • Demonstrated experience conducting threat hunts that led to actionable security improvements
  • Previous experience supporting or leading security tool migrations or implementations (highly valued)
  • Certifications (Preferred)

 

Highly Valued:

  • GIAC Cyber Threat Intelligence (GCTI)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Threat Intelligence Analyst (CTIA)

 

Relevant:

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Splunk Enterprise Security Certified Admin
  • CISSP, CISM, or equivalent security management certification
  • Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective

 

 Knowledge Transfer and Teaching Ability

  • Proven ability to explain complex technical concepts to varied technical audiences
  • Experience developing and delivering technical training or mentorship programs
  • Patience and commitment to building team capability, not just completing tasks
  • Ability to adapt teaching style to different learning preferences and skill levels

 

Communication and Collaboration

  • Excellent written communication skills for documentation and reporting
  • Strong verbal communication skills for training delivery and incident collaboration
  • A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)
  • Comfort operating in a fully remote environment with distributed team members

 

Problem Solving and Initiative

  • Self-directed work style with ability to identify priorities independently
  • Creative problem-solving approach to novel security challenges
  • Intellectual curiosity and continuous learning mindset
  • Ability to translate theoretical threat research into practical defensive measures

Similar jobs