Threat Hunting Consultant
Tata Consultancy Services · San Jose, CA · 3 wk ago
Consulting$110k–$150k/yrFull-time
About the Role
We are seeking a Microsoft Security Stack Expert with extensive hands-on experience in detection, threat hunting, and incident response to join our fully remote, distributed team.
Responsibilities
- Conduct hypothesis-driven threat hunts and translate threat intelligence into actionable hunting queries.
- Develop high-fidelity detection rules with low false positive rates using Kusto Query Language (KQL) and Splunk Processing Language (SPL).
- Leverage Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR) for unified security operations, investigations, and automated response.
- Perform expert-level Splunk Enterprise Security operations, including complex correlation, hunting queries, and behavioral detection using Splunk UBA or similar platforms.
- Lead hands-on incident response, including endpoint forensics, malware analysis, containment, eradication, and recovery for complex security incidents.
- Apply the MITRE ATT&CK framework to understand adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups.
- Design, optimize, and maintain SIEM architecture, including data onboarding and performance tuning.
- Develop and deliver technical training, mentorship programs, and documentation to build team capability.
- Collaborate with cross-functional teams (IR, detection engineering, IT operations) to improve security posture.
- Support or lead security tool migrations or implementations, particularly within the Microsoft security stack.
Requirements
- Minimum 5-7 years of experience in cybersecurity with a focus on detection, threat hunting, and/or incident response.
- At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment.
- Demonstrated experience conducting threat hunts that led to actionable security improvements.
- Deep understanding of Windows internals, process behaviors, and security architecture.
- Knowledge of network protocols, traffic analysis, and common attack vectors.
- Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM).
- Proficiency in scripting and automation (PowerShell, Python, or similar).
- Experience with incident response frameworks (NIST, SANS) and playbook development.
- Understanding of forensic evidence preservation and chain of custody requirements.
Preferred Qualifications
- GIAC Cyber Threat Intelligence (GCTI), GIAC Certified Incident Handler (GCIH), or GIAC Certified Forensic Analyst (GCFA).
- Certified Threat Intelligence Analyst (CTIA).
- Microsoft Certified: Security Operations Analyst Associate (SC-200).
- Splunk Enterprise Security Certified Admin.
- CISSP, CISM, or equivalent security management certification.
- Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective.
- Previous experience supporting or leading security tool migrations or implementations.
Skills
- Expert-level proficiency with Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR).
- Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection.
- Expert-level Splunk Enterprise Security experience and proficiency in Splunk Processing Language (SPL).
- Strong written and verbal communication skills for documentation, reporting, and training delivery.
- Ability to explain complex technical concepts to varied technical audiences.
- Self-directed work style with strong problem-solving and initiative to address novel security challenges.
- Intellectual curiosity and continuous learning mindset to translate threat research into practical defensive measures.
Benefits
- Fully remote work environment with a distributed team.
Pay
$110,000 - $150,000 a year.