V

Senior Security Engineer - Threat Hunting & Detection

ventures unlimited inc United State
Remote
Apply
AI Summary

This role focuses on advanced threat hunting and detection engineering within the Microsoft Security Stack and Splunk. Responsibilities include conducting hypothesis-driven hunts, developing high-fidelity detection rules, and performing incident response. Key requirements include extensive experience with Microsoft Defender for Endpoint, Splunk Enterprise Security, and KQL/SPL, alongside a strong understanding of threat intelligence and adversary TTPs.

Key Highlights
Extensive experience with Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR).
Expert-level Splunk Enterprise Security experience with proficiency in KQL and SPL for threat hunting.
Proven ability in threat hunting, detection engineering, and incident response, with a strong understanding of MITRE ATT&CK.
Key Responsibilities
Conduct hypothesis-driven threat hunts.
Develop high-fidelity detection rules with low false positive rates.
Perform hands-on incident response and investigation.
Translate threat intelligence and attack research into actionable hunting queries.
Explain complex technical concepts to varied technical audiences.
Develop and deliver technical training or mentorship programs.
Work effectively with cross-functional teams.
Operate in a fully remote environment with distributed team members.
Identify priorities independently and creatively solve novel security challenges.
Technical Skills Required
Microsoft Defender for Endpoint Splunk Enterprise Security Kusto Query Language (KQL)
Nice to Have
Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms
Incident response frameworks (NIST, SANS) and playbook development
Endpoint forensics and malware analysis
Windows internals, process behaviors, and security architecture
Network protocols, traffic analysis, and common attack vectors
Authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)
Scripting and automation (PowerShell, Python, or similar)
Supporting or leading security tool migrations or implementations
GIAC Cyber Threat Intelligence (GCTI)
GIAC Certified Incident Handler (GCIH)
GIAC Certified Forensic Analyst (GCFA)
Certified Threat Intelligence Analyst (CTIA)
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Splunk Enterprise Security Certified Admin
CISSP, CISM, or equivalent security management certification
Offensive Security certifications (OSCP, OSCE)

Job Description


Job Description

Microsoft Security Stack Expertise

• Extensive hands-on experience with Microsoft Defender for Endpoint (MDE)

• Proficiency with Microsoft 365 Defender (XDR) unified security operations

• Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection

• Deep understanding of MDE investigation capabilities, automated response features, and integration architecture

SIEM and Analytics

• Expert-level Splunk Enterprise Security experience

• Proficiency in Splunk Processing Language (SPL) for complex correlation and hunting queries

• Experience with Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms

• Knowledge of SIEM architecture, data onboarding, and optimization techniques

Threat Hunting and Detection Engineering

• Demonstrated experience conducting hypothesis-driven threat hunts

• Strong understanding of MITRE ATT&CK framework and its practical application

• Ability to translate threat intelligence and attack research into actionable hunting queries

• Experience developing high-fidelity detection rules with low false positive rates

• Knowledge of adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups

Incident Response

• Proven track record in hands-on incident response and investigation

• Expertise in endpoint forensics and malware analysis

• Familiarity with incident response frameworks (NIST, SANS) and playbook development

• Experience with containment, eradication, and recovery procedures for complex security incidents

• Understanding of forensic evidence preservation and chain of custody requirements

Technical Foundations

• Deep understanding of Windows internals, process behaviors, and security architecture

• Knowledge of network protocols, traffic analysis, and common attack vectors

• Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM)

• Understanding of scripting and automation (PowerShell, Python, or similar)


Knowledge Transfer and Teaching Ability

• Proven ability to explain complex technical concepts to varied technical audiences

• Experience developing and delivering technical training or mentorship programs

• Patience and commitment to building team capability, not just completing tasks

• Ability to adapt teaching style to different learning preferences and skill levels

Communication and Collabo ration

• Excellent written communication skills for documentation and reporting

• Strong verbal communication skills for training delivery and incident collaboration

• Ability to work effectively with cross-functional teams (IR, detection engineering, IT operations)

• Comfort operating in a fully remote environment with distributed team members

Problem Solving and Initiative

• Self-directed work style with ability to identify priorities independently

• Creative problem-solving approach to novel security challenges

• Intellectual curiosity and continuous learning mindset

• Ability to translate theoretical threat research into practical defensive measures

• Minimum 5-7 years of experience in cybersecurity with focus on detection, threat hunting, and/or incident response

• At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment

• Demonstrated experience conducting threat hunts that led to actionable security improvements

• Previous experience supporting or leading security tool migrations or implementations (highly valued)

• Certifications (Preferred)


Highly Valued:

• GIAC Cyber Threat Intelligence (GCTI)

• GIAC Certified Incident Handler (GCIH)

• GIAC Certified Forensic Analyst (GCFA)

• Certified Threat Intelligence Analyst (CTIA)


• Relevant:

• Microsoft Certified: Security Operations Analyst Associate (SC-200)

• Splunk Enterprise Security Certified Admin

• CISSP, CISM, or equivalent security management certification

• Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective


Knowledge Transfer and Teaching Ability

• Proven ability to explain complex technical concepts to varied technical audiences

• Experience developing and delivering technical training or mentorship programs

• Patience and commitment to building team capability, not just completing tasks

• Ability to adapt teaching style to different learning preferences and skill levels

Communication and Collaboration

• Excellent written communication skills for documentation and reporting

• Strong verbal communication skills for training delivery and incident collaboration

• A bility to work effectively with cross-functional teams (IR, detection engineering, IT operations)

• Comfort operating in a fully remote environment with distributed team members

Problem Solving and Initiative

• Self-directed work style with ability to identify priorities independently

• Creative problem-solving approach to novel security challenges

• Intellectual curiosity and continuous learning mindset

• Ability to translate theoretical threat research into practical defensive measures


Similar Jobs

Explore other opportunities that match your interests

Senior Global Incident Response & Travel Risk Management Director (Remote)

Networking
7h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

RTX

United State

Database Administrator II

Networking
2d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

State of Colorado

United State

Senior Site Reliability Engineer - IT/DevOps

Networking
3d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

GitHub

United State

Subscribe our newsletter

New Things Will Always Update Regularly