Run hypothesis-driven hunts across client telemetry, turn adversary behavior into durable detections, and stand up when an incident is live. You will find what tooling missed and prove it in the data.
What you will do
Form and test hunting hypotheses grounded in MITRE ATT&CK and current adversary tradecraft
Hunt across SIEM and EDR telemetry to surface behavior that signatures and rules miss
Engineer, tune, and validate detections, then measure their coverage against real techniques
Triage and investigate suspicious activity end to end and rule in or out compromise
Support incident response with scoping, containment guidance, and root-cause analysis
Document findings, detection logic, and gaps so clients can defend themselves after we leave
What we are looking for
4+ years in threat hunting, detection engineering, or hands-on incident response
GCFA, GCTI, GCTD, or GCDA, or equivalent demonstrable hunting and forensics depth
Fluent query skills across a SIEM (Splunk SPL, Elastic, Sentinel KQL) and a major EDR
Deep grasp of Windows and Linux internals, logging, and attacker behavior mapped to ATT&CK
Detection-as-code experience with Sigma or YARA and scripting in Python or PowerShell
Structured analytic rigor and the judgment to separate signal from noise under pressure
Nice to have
Memory or disk forensics and malware triage experience
Cloud and identity threat detection across AWS, Azure, or GCP
Prior work alongside a red team in purple-team exercises
Get ahead of zero
Ready to see yourself the way an adversary would?
Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.