Remotely
pythonpowershellkqlsplmicrosoft defender for endpointmicrosoft 365 defender/xdrsplunk uba
Job Description
📋 Description
- Conduct hypothesis-driven threat hunts across endpoint, identity, network, and security analytics
- Utilize Microsoft Defender for Endpoint, Microsoft 365 Defender/XDR, Splunk Enterprise Security
- Develop and refine high-fidelity detection rules, correlation searches, and threat-hunting queries
- Apply the MITRE ATT&CK framework and current attacker TTPs to guide threat-hunting activities
- Perform incident response, endpoint forensics, malware analysis, and technical investigations to
- Translate threat intelligence into actionable detection logic, hunting hypotheses, response
🎯 Requirements
- 5+ years of relevant experience in threat hunting, detection engineering, incident response
- Extensive hands-on experience with Microsoft Defender for Endpoint and strong knowledge of
- Expert-level experience with Splunk Enterprise Security, including advanced SPL for threat hunting
- Experience with Splunk UBA or comparable behavioral analytics platforms.
- Advanced proficiency in Kusto Query Language (KQL) and strong ability to develop sophisticated
- Proven experience conducting hypothesis-driven threat hunts and identifying sophisticated attacker
🎁 Benefits
- Annual salary range of $110,000–$130,000.
- Full-time opportunity focused on advanced cybersecurity, threat hunting, and detection engineering.
- Remote work environment with flexibility to collaborate from India.
- Opportunity to work with leading security technologies including Microsoft Defender, Splunk
- Exposure to complex security investigations, enterprise-scale threat detection, incident response
- Opportunities to contribute to security strategy, knowledge sharing, training, and technical
Back to all jobs