Jobs · Business Development · Oregon

SOC Threat Hunter

ECS · Portland, OR · 4 wk ago
Business DevelopmentFull-time

Key Responsibilities

  • Develop and execute hypothesis-driven hunts across enterprise, cloud, endpoint, identity, and network data sources
  • Analyze anomalous behavior, suspicious activity, and attacker tactics, techniques, and procedures (TTPs)
  • Use SIEM, EDR, network, log analytics, and threat intelligence tools to identify potential compromise or unauthorized activity
  • Validate hunt findings, assess potential impact, and determine whether escalation to incident response or SOC operations is required
  • Translate hunt findings into detection logic, analytic requirements, alert tuning recommendations, and monitoring use cases
  • Identify gaps in logging, visibility, correlation logic, and alert coverage
  • Partner with SOC analysts, Splunk engineers, security engineers, and threat intelligence analysts to improve detection fidelity and coverage
  • Support development of repeatable hunt playbooks, queries, dashboards, and analytic procedures
  • Investigate support & escalation, coordinate with SOC Tier 2 and Tier 3 analysts, forensics personnel, and incident response teams during escalations
  • Aid in post-incident hunt activity to identify related indicators, lateral movement, persistence, or additional affected assets
  • Produce clear hunt reports, summaries, findings, and recommendations for technical and leadership audiences
  • Track hunt outcomes, recurring patterns, detection gaps, and operational metrics
  • Contribute to continuous improvement of SOC processes, analytic standards, and knowledge management resources
  • Stay current with adversary tradecraft, detection engineering practices, and security analytics techniques

Required Skills

  • U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance after start
  • 5+ years of experience in cybersecurity operations, threat hunting, incident response, detection engineering, security monitoring, or related roles
  • Hands-on experience using SIEM, EDR, network security, endpoint telemetry, cloud logging, and/or log analytics platforms
  • Strong understanding of adversary tactics, techniques, and procedures; common attack paths; and enterprise security controls
  • Experience developing or using hunt hypotheses, detection logic, investigative queries, and analytic playbooks
  • Ability to analyze large volumes of security data and distinguish suspicious activity from benign behavior
  • Strong written communication skills, including the ability to document findings, evidence, and recommendations clearly

Desired Skills

  • Experience with Splunk, EDR platforms, packet analysis, cloud security telemetry, identity logs, or scripting for data analysis
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, NIST, or other cybersecurity frameworks
  • Experience supporting SOC operations, incident response, malware analysis, forensics, or threat intelligence functions
  • Knowledge of Windows, Linux, networking, authentication, cloud services, and common attacker tooling
  • Certifications such as GCIH, GCIA, GCFA, GNFA, GREM, CISSP, CySA+, Security+, or equivalent experience

Similar jobs

Threat Hunter

Bank of AmericaDenver, CO· 1 wk ago
Business Developmentapply on careers.bankofamerica.com

Threat Hunter

ALPFA Baltimore ChapterChicago, IL· 1 wk ago
Business Development$100k–$141k/yrapply on jobs.alpfa.org

Threat Hunter

Digital HandsTampa, FL· 2 mo ago
Business Developmentapply on grnh.se

Threat Hunter

CNA InsuranceChicago, IL· 2 mo ago
Management$97k–$189k/yrapply on cna.wd1.myworkdayjobs.com

Threat Hunter

TENEX.AISan Jose, CA· 1 mo ago
Business Developmentapply on tenex.ai

Threat Hunter

TENEX.AISarasota, FL· 2 mo ago
Managementapply on tenex.ai