Start Date
Immediate
Expiry Date
03 Jan, 27
Salary
420000.0
Posted On
06 Oct, 26
Experience
15 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
Yes
Skills
Industry
Information Technology & Services
Job Description
Help AG is looking for an experience Digital Threat Hunting Specialist who will be responsible for proactively identifying, investigating, and mitigating advanced cyber threats within the client environment through hypothesis-driven threat hunting activities. This position will focus on proactive threat hunting, advanced threat analysis, detection engineering, threat intelligence correlation, investigation of suspicious activities, and continuous improvement of cyber defense capabilities.
Responsibilities
❖ Proactively conduct hypothesis-driven threat hunting across enterprise networks, endpoints, cloud, and hybrid environments to identify advanced persistent threats (APTs) and hidden malicious activities.
❖ Investigate suspicious events and analyze attacker tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework.
❖ Perform advanced analysis of security logs, endpoint telemetry, network traffic, authentication events, and cloud security data to identify indicators of compromise (IOCs) and indicators of attack (IOAs).
❖ Develop and refine threat hunting methodologies, playbooks, and standard operating procedures.
❖ Create and enhance detection use cases, analytics rules, and hunting queries within SIEM and EDR platforms.
❖ Support Incident Response teams by providing detailed investigative findings, root cause analysis, and threat attribution where applicable.
❖ Collaborate with Security Operations, Threat Intelligence, Vulnerability Management, and Infrastructure teams to strengthen the overall security posture.
❖ Prepare technical reports, threat hunting findings, executive summaries, and recommendations for continuous security improvement.
❖ Provide technical guidance on threat hunting best practices, detection strategies, and emerging attack techniques.
Qualifications & Skills
❖ Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Information Security, Engineering, or a related field. Equivalent professional experience and relevant certifications may be considered in lieu of a degree.
❖ 7+ years of experience in cybersecurity operations, threat hunting, incident response, security monitoring, or detection/security engineering.
❖ Demonstrable, hands-on experience leading or performing proactive threat hunts in enterprise scale environments.
❖ Strong understanding of threat hunting methodologies, cyber kill chain, MITRE ATT&CK framework, and adversary TTPs.
❖ Experience with Endpoint Detection and Response (EDR) platforms such as Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, Cortex XDR, or equivalent.
❖ Experience analyzing Windows, Linux, Active Directory, cloud, endpoint, and network security telemetry.
❖ Knowledge of threat intelligence platforms, IOC analysis, malware behavior, and advanced attack techniques.
❖ Experience developing detection rules, hunting queries (KQL, SPL, or equivalent), and SIEM use cases.
❖ Relevant certifications such as SC-200, GCTI, GCIH, GCFA, CISSP, CISM, CompTIA CySA+, or equivalent are preferred.
❖ Solid understanding of networking fundamentals, operating system internals, and common enterprise architectures (on-premises, cloud, and hybrid).
Job Description
Help AG is looking for an experience Digital Threat Hunting Specialist who will be responsible for proactively identifying, investigating, and mitigating advanced cyber threats within the client environment through hypothesis-driven threat hunting activities. This position will focus on proactive threat hunting, advanced threat analysis, detection engineering, threat intelligence correlation, investigation of suspicious activities, and continuous improvement of cyber defense capabilities.
Responsibilities
❖ Proactively conduct hypothesis-driven threat hunting across enterprise networks, endpoints, cloud, and hybrid environments to identify advanced persistent threats (APTs) and hidden malicious activities.
❖ Investigate suspicious events and analyze attacker tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework.
❖ Perform advanced analysis of security logs, endpoint telemetry, network traffic, authentication events, and cloud security data to identify indicators of compromise (IOCs) and indicators of attack (IOAs).
❖ Develop and refine threat hunting methodologies, playbooks, and standard operating procedures.
❖ Create and enhance detection use cases, analytics rules, and hunting queries within SIEM and EDR platforms.
❖ Support Incident Response teams by providing detailed investigative findings, root cause analysis, and threat attribution where applicable.
❖ Collaborate with Security Operations, Threat Intelligence, Vulnerability Management, and Infrastructure teams to strengthen the overall security posture.
❖ Prepare technical reports, threat hunting findings, executive summaries, and recommendations for continuous security improvement.
❖ Provide technical guidance on threat hunting best practices, detection strategies, and emerging attack techniques.
Qualifications & Skills
❖ Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Information Security, Engineering, or a related field. Equivalent professional experience and relevant certifications may be considered in lieu of a degree.
❖ 7+ years of experience in cybersecurity operations, threat hunting, incident response, security monitoring, or detection/security engineering.
❖ Demonstrable, hands-on experience leading or performing proactive threat hunts in enterprise scale environments.
❖ Strong understanding of threat hunting methodologies, cyber kill chain, MITRE ATT&CK framework, and adversary TTPs.
❖ Experience with Endpoint Detection and Response (EDR) platforms such as Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, Cortex XDR, or equivalent.
❖ Experience analyzing Windows, Linux, Active Directory, cloud, endpoint, and network security telemetry.
❖ Knowledge of threat intelligence platforms, IOC analysis, malware behavior, and advanced attack techniques.
❖ Experience developing detection rules, hunting queries (KQL, SPL, or equivalent), and SIEM use cases.
❖ Relevant certifications such as SC-200, GCTI, GCIH, GCFA, CISSP, CISM, CompTIA CySA+, or equivalent are preferred.
❖ Solid understanding of networking fundamentals, operating system internals, and common enterprise architectures (on-premises, cloud, and hybrid).