Jobs · Consulting

Threat Hunting Consultant

Tata Consultancy Services · San Jose, CA · 3 wk ago
Consulting$110k–$150k/yrFull-time

About the Role

We are seeking a Microsoft Security Stack Expert with extensive hands-on experience in detection, threat hunting, and incident response to join our fully remote, distributed team.

Responsibilities

  • Conduct hypothesis-driven threat hunts and translate threat intelligence into actionable hunting queries.
  • Develop high-fidelity detection rules with low false positive rates using Kusto Query Language (KQL) and Splunk Processing Language (SPL).
  • Leverage Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR) for unified security operations, investigations, and automated response.
  • Perform expert-level Splunk Enterprise Security operations, including complex correlation, hunting queries, and behavioral detection using Splunk UBA or similar platforms.
  • Lead hands-on incident response, including endpoint forensics, malware analysis, containment, eradication, and recovery for complex security incidents.
  • Apply the MITRE ATT&CK framework to understand adversary tactics, techniques, and procedures (TTPs) across multiple threat actor groups.
  • Design, optimize, and maintain SIEM architecture, including data onboarding and performance tuning.
  • Develop and deliver technical training, mentorship programs, and documentation to build team capability.
  • Collaborate with cross-functional teams (IR, detection engineering, IT operations) to improve security posture.
  • Support or lead security tool migrations or implementations, particularly within the Microsoft security stack.

Requirements

  • Minimum 5-7 years of experience in cybersecurity with a focus on detection, threat hunting, and/or incident response.
  • At least 2 years of hands-on experience with Microsoft Defender for Endpoint in an enterprise environment.
  • Demonstrated experience conducting threat hunts that led to actionable security improvements.
  • Deep understanding of Windows internals, process behaviors, and security architecture.
  • Knowledge of network protocols, traffic analysis, and common attack vectors.
  • Familiarity with authentication protocols (Active Directory, Azure AD, Kerberos, NTLM).
  • Proficiency in scripting and automation (PowerShell, Python, or similar).
  • Experience with incident response frameworks (NIST, SANS) and playbook development.
  • Understanding of forensic evidence preservation and chain of custody requirements.

Preferred Qualifications

  • GIAC Cyber Threat Intelligence (GCTI), GIAC Certified Incident Handler (GCIH), or GIAC Certified Forensic Analyst (GCFA).
  • Certified Threat Intelligence Analyst (CTIA).
  • Microsoft Certified: Security Operations Analyst Associate (SC-200).
  • Splunk Enterprise Security Certified Admin.
  • CISSP, CISM, or equivalent security management certification.
  • Offensive Security certifications (OSCP, OSCE) demonstrating adversarial perspective.
  • Previous experience supporting or leading security tool migrations or implementations.

Skills

  • Expert-level proficiency with Microsoft Defender for Endpoint (MDE) and Microsoft 365 Defender (XDR).
  • Advanced knowledge of Kusto Query Language (KQL) for threat hunting and detection.
  • Expert-level Splunk Enterprise Security experience and proficiency in Splunk Processing Language (SPL).
  • Strong written and verbal communication skills for documentation, reporting, and training delivery.
  • Ability to explain complex technical concepts to varied technical audiences.
  • Self-directed work style with strong problem-solving and initiative to address novel security challenges.
  • Intellectual curiosity and continuous learning mindset to translate threat research into practical defensive measures.

Benefits

  • Fully remote work environment with a distributed team.

Pay

$110,000 - $150,000 a year.

Similar jobs

Threat Hunt Analyst

Booz Allen HamiltonLakewood, CO· 2 mo ago
Information Technology$99k–$225k/yrapply on careers.boozallen.com