Search by job, company or skills

Threat Hunting Analyst

Threat Hunting Analyst

nextgen identity pty ltd
5-7 Years
Not Disclosed
Early Applicant
  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

We're Hiring: Threat Hunting Analyst

Location: Remote

Experience: 5+ Years

Availability: Immediate Joiners / Serving Notice Period Preferred

What You'll Do

  • Conduct proactive threat hunting across endpoint, identity, email, and network telemetry to identify advanced attacker behaviors.
  • Develop and execute hypothesis-driven hunts (IF–THEN) aligned with MITRE ATT&CK techniques.
  • Investigate complex security events using evidence-driven analysis and validate findings through available telemetry.
  • Identify and investigate advanced techniques such as MFA bypass, RMM abuse, Living-off-the-Land (LOLBins), persistence, credential access, and cloud abuse.
  • Translate emerging threats and attacker behaviors into actionable detection logic.
  • Create and optimize detections across SIEM/EDR platforms such as Splunk, CrowdStrike, and Microsoft 365 Defender.
  • Use advanced queries to investigate threats and identify suspicious patterns across security telemetry.
  • Document investigations, findings, detection gaps, and recommendations in audit-ready and leadership-ready formats.
  • Collaborate with Detection Engineering and Security Operations teams to close visibility gaps and improve detection coverage.
  • Participate in threat hunting forums and contribute to improving investigation quality and consistency.

What We're Looking For

  • Strong hands-on experience with SIEM and EDR platforms, particularly Splunk, CrowdStrike, and Microsoft 365 Defender.
  • Deep understanding of attacker tradecraft and MITRE ATT&CK.
  • Advanced query-building skills using SPL, LogScale, KQL, or similar query languages.
  • Strong experience detecting stealthy attacker techniques including LOLBins, persistence, credential access, and cloud abuse.
  • Ability to perform evidence-based investigations and reduce false positives.
  • Strong understanding of detection engineering and threat hunting methodologies.
  • Excellent documentation and reporting skills with the ability to create leadership-ready summaries.
  • Strong analytical mindset with a focus on hypothesis-driven threat hunting.

Preferred Skills

  • Splunk Analyst
  • Splunk Content Development
  • CrowdStrike

What Makes You Successful

  • Strong investigative and analytical skills.
  • Ability to think like an attacker and identify abnormal behaviors.
  • Strong hands-on experience with SIEM/EDR investigation and detection development.
  • Ability to turn threat hypotheses into effective hunts and actionable detections.
  • Strong collaboration with SOC and Detection Engineering teams.

Interested candidates

Apply or DM your updated resume.

#Hiring #ThreatHunting #ThreatHunter #CyberSecurity #MITREATTACK #Splunk #CrowdStrike #MicrosoftDefender #DetectionEngineering #SOC #CyberDefense #ThreatDetection #CyberJobs #InfoSec #CyberCareers

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Microsoft 365 Defender

KQL

LogScale

Similar Jobs

4-7 yrs
Pune, India
Skills:
Network Protocols, Windows, Linux, Siem, SOC technologies, CrowdStrike QL, EPP, Qualys VM, threat intelligence platforms, open-source tools, Recorded Future TI, CrowdStrike EDR, YARA, Vectra NDR, TAXII, STIX, Sps, Mitre ATT CK Framework, Google Chronicle