Job Description:
• Develop and execute threat-hunting hypotheses based on adversary tactics, techniques, and procedures (TTPs), leveraging frameworks such as MITRE ATT&CK.
• Engage with Client Security & IT infrastructure and internal AHEAD Managed Security teams to proactively hunt for advanced threats, suspicious behavior, and indicators of compromise (IOCs) across endpoints, networks, cloud, and identity systems.
• Analyze data from SIEM, EDR/XDR, NDR, cloud security tools, and logs to uncover stealthy or unknown threats.
• Conduct deep-dive investigations to determine root cause, scope, and impact of identified threats.
• Collaborate with incident response teams to contain, eradicate, and remediate confirmed threats.
• Create and refine detection logic, queries, dashboards, and alerts to enhance ongoing monitoring.
• Stay current on emerging threats, attack techniques, and vulnerabilities, and translate intelligence into actionable hunts.
• Document findings, develop reports, and communicate results to technical and non-technical stakeholders.
• Collaborate with managed security peers to contribute to continuous improvement of threat detection and response processes.
Requirements:
• Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
• 3–7+ years of experience in cybersecurity, with hands-on experience in threat hunting, incident response, or SOC operations.
• Strong understanding of operating systems (Windows, Linux, macOS), networking concepts, and common enterprise architectures.
• Threat intelligence analysis experience and integration into hunting workflows.
• Proficiency with SIEM platforms and query languages (e.g., SQL, Splunk SPL, Elastic KQL, ESQL).
• Experience with EDR/XDR tools (e.g., Elastic Defend, Microsoft Defender, CrowdStrike, SentinelOne).
• Experience with cloud platforms and security tooling (AWS, Azure, GCP).
• Solid knowledge of attacker techniques, malware behavior, and persistence mechanisms.
• Ability to analyze large datasets and identify subtle patterns of malicious activity.
• Strong scripting or programming skills (e.g., Python, PowerShell, Bash).
• Customer service focused and portrays energy, professionalism and welcoming characteristics.
Benefits:
• Medical, Dental, and Vision Insurance
• 401(k)
• Paid company holidays
• Paid time off
• Paid parental and caregiver leave
• Plus more! See benefits https://www.aheadbenefits.com/ for additional details.