Lead, Cyber Defense & Response
- Lead proactive threat hunts across enterprise environments (on-prem and cloud), including Active Directory/Entra, M365, Azure, AWS, endpoints, identity, network, and application telemetry.
- Develop and refine hunt hypotheses based on emerging threats, adversary TTPs, vulnerability exploitation trends, and internal detections/incident learnings; map activity to frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
- Execute advanced investigations and log analytics using SIEM/XDR platforms; leverage Splunk SPL and Microsoft KQL to identify suspicious patterns, perform pivoting, and validate attack paths.
- Operationalize outcomes by translating hunt findings into durable defensive improvements: candidate detections/use-cases, analytic content, prioritized telemetry gaps, and actionable response guidance for IR/CSOC.
- Partner with Cyber Threat Intelligence to convert intelligence into environment-specific hunting plans, tracking, and measurable coverage (e.g., techniques, telemetry sources, and control validations).
- Partner with Detection Engineering to develop, test, and tune detection logic, including supporting documentation, test cases, and validation against realistic adversary behaviors.
- Drive visibility and resiliency improvements by identifying logging and data quality deficiencies, prioritizing remediation with stakeholders, and validating that required telemetry is consistently available.
- Provide technical leadership and coaching to threat hunting staff, including reviewing analytic approaches, promoting repeatable methodologies, and uplifting standards for documentation and knowledge sharing.
- Communicate clearly to stakeholders by producing concise executive summaries and detailed technical write-ups, brief leadership and technical partners on risk, scope, and recommended actions.
- Support incident response as needed by performing adjacency and scoping hunts during active incidents to prevent under-scoping and to identify persistence, lateral movement, and follow-on activity.
- Contribute to program maturity by improving playbooks, workflows, metrics, and reporting for threat hunting operations (e.g., coverage progress, outcomes, and time-to-insight). The Skills & Expertise You Bring
- 5+ years of experience in cyber threat hunting, incident response, detection engineering, or security operations in large enterprise environments.
- Demonstrated experience conducting investigations across endpoint, identity, network, and cloud telemetry in complex environments.
- Strong proficiency with at least one major SIEM/XDR ecosystem and advanced query authoring; hands-on experience with Splunk SPL and/or Microsoft KQL strongly preferred.
- Working knowledge of attacker tradecraft, including credential access, persistence, lateral movement, defense evasion, command-and-control, and data exfiltration techniques.
- Strong understanding of adversarial frameworks including MITRE ATT&CK and Lockheed Martin’s Cyber Kill Chain, and ability to apply them to analytic development and hunting.
- Experience designing or improving hunt programs, including workflow/process, metrics, reporting, and knowledge management.
- Industry Standard certifications (one or more), such as:
- GIAC GCIA, GMON, GX-IA, GCED, GX-CX, GCIH, GCFE, GCFA, GEIR, GCFR, GNFA, GCTI, GCTD, GCFR, GCPN, GPEN, GXPN
- Microsoft SC-200, AZ-500
- CompTIA Cybersecurity Analyst (CySA+)
- Market competitive base salaries, with a yearly bonus potential at every level.
- Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave.
- 401(k) plan with company match (up to 4%).
- Company-funded pension plan.
- Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.
- Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
- Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.
- Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period), after one year of service.
If you are experiencing a technical issue with your application or an assessment, please email [email protected] to request assistance.
Recommended Jobs
Tableau Developer
Responsibilities: Data Visualization: Develop interactive and visually appealing dashboards using Tableau. Design and implement charts, graphs, maps, and other visualization elements to effect…
Irrigation Tech
Lawn sprinkler company is seeking experienced (minimum 3 years) techs to join our team. Qualifications: You must be able to diagnose irrigation issues and resolve them timely and clean. Be w…
Strategic Account Manager
Position Summary We are seeking a strategic Key Account Manager to oversee and grow a portfolio of enterprise-level customers. This role is focused on deepening relationships and expanding sh…
Assistant Food Prep Worker
Summary The Assistant Food Preparation worker assists the Food Worker in serving meals and snacks to children and staff at an early childhood center with six classrooms. This person is responsib…
Scrum Master
Job Description Must Have Technical/Functional Skills Facilitate all Scrum ceremonies (Sprint Planning, Daily Stand-ups, Sprint Reviews, Retrospectives) ensuring disciplined execution aligned t…
EEG Tech Level I
Job Title: EEG Tech Level I Location: Cooperman Barnabas Medical Ctr Department: EEG Req#: 0000184795 Status: Per Diem Shift: Day Pay Range: $36.23 - $36.23 per hour Pay Transpare…
Senior Mechanical Engineer (Edison)
Senior Mechanical Engineer US-NJ-Edison Job ID: 2026-3254 Type: Regular Full-Time # of Openings: 1 Category: MEP LiRo-Hill Overview We have an immediate need for a Sr. Mec…
Occupational Therapist
Job Description Job Description Benefits: Competitive salary Flexible schedule Training & development Overview: As a Medicare B mobile Occupational Therapist, you will be an integr…
Support Engineer | L1 Support (EST Timezone)
n8n is a workflow automation platform that uniquely combines AI capabilities with business process automation. We give technical teams the flexibility of code with the speed of no-code, backed by a p…
Registered Nurse (RN) - Outpatient Infusion
Job Title: RN Location: RWJUH Somerset Department Name: Outpatient Infusion Req #: 0000237785 Status: Hourly Shift: Day Pay Range: $45.55 - $61.17 per hour Pay Transparency: Th…