SOC Threat Hunter
ECS · Portland, OR · 4 wk ago
Business DevelopmentFull-time
Key Responsibilities
- Develop and execute hypothesis-driven hunts across enterprise, cloud, endpoint, identity, and network data sources
- Analyze anomalous behavior, suspicious activity, and attacker tactics, techniques, and procedures (TTPs)
- Use SIEM, EDR, network, log analytics, and threat intelligence tools to identify potential compromise or unauthorized activity
- Validate hunt findings, assess potential impact, and determine whether escalation to incident response or SOC operations is required
- Translate hunt findings into detection logic, analytic requirements, alert tuning recommendations, and monitoring use cases
- Identify gaps in logging, visibility, correlation logic, and alert coverage
- Partner with SOC analysts, Splunk engineers, security engineers, and threat intelligence analysts to improve detection fidelity and coverage
- Support development of repeatable hunt playbooks, queries, dashboards, and analytic procedures
- Investigate support & escalation, coordinate with SOC Tier 2 and Tier 3 analysts, forensics personnel, and incident response teams during escalations
- Aid in post-incident hunt activity to identify related indicators, lateral movement, persistence, or additional affected assets
- Produce clear hunt reports, summaries, findings, and recommendations for technical and leadership audiences
- Track hunt outcomes, recurring patterns, detection gaps, and operational metrics
- Contribute to continuous improvement of SOC processes, analytic standards, and knowledge management resources
- Stay current with adversary tradecraft, detection engineering practices, and security analytics techniques
Required Skills
- U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance after start
- 5+ years of experience in cybersecurity operations, threat hunting, incident response, detection engineering, security monitoring, or related roles
- Hands-on experience using SIEM, EDR, network security, endpoint telemetry, cloud logging, and/or log analytics platforms
- Strong understanding of adversary tactics, techniques, and procedures; common attack paths; and enterprise security controls
- Experience developing or using hunt hypotheses, detection logic, investigative queries, and analytic playbooks
- Ability to analyze large volumes of security data and distinguish suspicious activity from benign behavior
- Strong written communication skills, including the ability to document findings, evidence, and recommendations clearly
Desired Skills
- Experience with Splunk, EDR platforms, packet analysis, cloud security telemetry, identity logs, or scripting for data analysis
- Familiarity with MITRE ATT&CK, Cyber Kill Chain, NIST, or other cybersecurity frameworks
- Experience supporting SOC operations, incident response, malware analysis, forensics, or threat intelligence functions
- Knowledge of Windows, Linux, networking, authentication, cloud services, and common attacker tooling
- Certifications such as GCIH, GCIA, GCFA, GNFA, GREM, CISSP, CySA+, Security+, or equivalent experience