Senior Security Engineer – Cyber Hunting & Incident Response
Truist · Zebulon, NC · Yesterday
Information TechnologyFull-time
About the role
The Cyber Hunt & Respond Senior Engineer is a senior-level cybersecurity professional within the 24x7 Cyber Fusion Center responsible for advanced threat hunting and incident response activities.
Responsibilities
- Conduct proactive threat hunting activities to identify previously unknown or undetected threats across enterprise environments.
- Develop, test, and validate threat-hunting hypotheses using internal and external data sources.
- Perform digital forensics and incident response activities, including investigation, root cause analysis, containment, eradication, and recovery.
- Analyze endpoint, network, packet, log, and forensic data to identify malicious activity and determine attack scope and impact.
- Leverage data analysis, automation, and programming techniques to process large datasets and improve threat detection and response capabilities.
- Create and maintain searches, visualizations, analytic content, and advanced detection methodologies to identify emerging threats.
- Investigate suspicious artifacts and activity to distinguish malicious behavior from legitimate business operations.
- Collaborate with security, technology, and business teams to identify data requirements and enhance threat visibility across the organization.
- Provide technical consultation and subject matter expertise on cybersecurity incidents, investigations, and threat-hunting initiatives.
- Present findings, lessons learned, and threat intelligence to technical and non-technical audiences.
- Mentor and provide guidance to team members in threat hunting, digital forensics, incident response, and related disciplines.
- Participate in an on-call rotation and provide after-hours incident response support as required.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 7 years of experience in security engineering or related cybersecurity roles.
- Deep specialized knowledge in cybersecurity principles, theories, and concepts.
- Proven experience in software development lifecycle security practices.
- Deep knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
Qualifications
- Strong knowledge of cybersecurity principles, network security, and modern identity and access management (IAM).
- Experience with network traffic analysis, packet capture analysis, and associated tools (e.g., Wireshark, tcpdump).
- Knowledge of Windows and Linux/Unix operating systems, internals, services, and file systems.
- Understanding of phishing techniques, advanced cyber threats, vulnerabilities, and adversary tactics, techniques, and procedures (TTPs).
- Experience with threat hunting, intrusion detection, incident response, and digital forensics investigations.
- Knowledge of digital evidence collection, preservation, and forensic artifact analysis.
- Experience leveraging automation, scripting, machine learning, and AI to support cybersecurity operations.
- Experience working in cloud environments, including Microsoft Azure and Amazon Web Services (AWS).
- Relevant technology or cybersecurity certifications (e.g., Security+, CySA+, GCIH, GCFA, GCFE, GNFA, GREM, Azure, AWS).
- Experience in Cyber Incident Response, Threat Hunting, Security Operations Centers (SOC), Network Operations Centers (NOC), Cybersecurity Engineering, or Intelligence Community environments.
Skills
- Threat modeling, security testing, and penetration testing.
- Data analysis, automation, and programming techniques.
- Digital forensics investigations.
- Network traffic analysis, packet capture analysis.
- Windows and Linux/Unix operating systems, internals, services, and file systems.
- Phishing techniques, advanced cyber threats, vulnerabilities, and adversary tactics, techniques, and procedures (TTPs).
- Automation, scripting, machine learning, and AI.
- Cloud environments, including Microsoft Azure and Amazon Web Services (AWS).
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan.
- No less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during the first year of employment, along with 10 sick days (also prorated), and paid holidays.
- Defined benefit pension plan, restricted stock units, and/or a deferred compensation plan.
Pay
Details on pay will be provided during the interview process.
Schedule
Regular or Temporary: Regular Work Shift: 1st shift (United States of America)