Senior Security Engineer - Cyber Hunting & Incident Response
TalentAlly · Zebulon, NC · Yesterday
Information TechnologyFull-time
About the role
The Cyber Hunt & Respond Senior Engineer is a senior-level cybersecurity professional within the 24x7 Cyber Fusion Center responsible for advanced threat hunting and incident response activities.
Responsibilities
- Conduct proactive threat hunting activities to identify previously unknown or undetected threats across enterprise environments.
- Develop, test, and validate threat-hunting hypotheses using internal and external data sources.
- Perform digital forensics and incident response activities, including investigation, root cause analysis, containment, eradication, and recovery.
- Analyze endpoint, network, packet, log, and forensic data to identify malicious activity and determine attack scope and impact.
- Leverage data analysis, automation, and programming techniques to process large datasets and improve threat detection and response capabilities.
- Create and maintain searches, visualizations, analytic content, and advanced detection methodologies to identify emerging threats.
- Investigate suspicious artifacts and activity to distinguish malicious behavior from legitimate business operations.
- Collaborate with security, technology, and business teams to identify data requirements and enhance threat visibility across the organization.
- Provide technical consultation and subject matter expertise on cybersecurity incidents, investigations, and threat-hunting initiatives.
- Present findings, lessons learned, and threat intelligence to technical and non-technical audiences.
- Mentor and provide guidance to team members in threat hunting, digital forensics, incident response, and related disciplines.
- Participate in an on-call rotation and provide after-hours incident response support as required.
Qualifications
- Bachelor's degree or equivalent education, training, and work-related experience.
- Minimum of 7 years of experience in security engineering or related cybersecurity roles.
- Deep specialized knowledge in cybersecurity principles, theories, and concepts.
- Proven experience in software development lifecycle security practices.
- Deep knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
Preferred Qualifications
- Strong knowledge of cybersecurity principles, network security, and modern identity and access management (IAM).
- Experience with network traffic analysis, packet capture analysis, and associated tools (e.g., Wireshark, tcpdump).
- Knowledge of Windows and Linux/Unix operating systems, internals, services, and file systems.
- Understanding of phishing techniques, advanced cyber threats, vulnerabilities, and adversary tactics, techniques, and procedures (TTPs).
- Experience with threat hunting, intrusion detection, incident response, and digital forensics investigations.
- Knowledge of digital evidence collection, preservation, and forensic artifact analysis.
- Experience leveraging automation, scripting, machine learning, and AI to support cybersecurity operations.
- Experience working in cloud environments, including Microsoft Azure and Amazon Web Services (AWS).
- Relevant technology or cybersecurity certifications (e.g., Security+, CySA+, GCIH, GCFA, GCFE, GNFA, GREM, Azure, AWS).
- Experience in Cyber Incident Response, Threat Hunting, Security Operations Centers (SOC), Network Operations Centers (NOC), Cybersecurity Engineering, or Intelligence Community environments.