North AmericaFull TimeEngineering
Remotely
pythonpowershellkqlsplmicrosoft defender for endpointmicrosoft 365 defender/xdrsplunk uba
Job Description
📋 Description
- Threat hunts across endpoint, identity, network, and security analytics to uncover malicious
- Investigate with Microsoft Defender for Endpoint, Microsoft 365 Defender/XDR, Splunk Enterprise
- Develop high-fidelity detection rules, correlation searches, and hunting queries using KQL and SPL
- Apply MITRE ATT&CK and attacker TTPs to guide threat-hunting activities and detection coverage.
- Perform incident response, endpoint forensics, malware analysis, and investigations to determine
- Translate threat intel into actionable detection logic, hunting hypotheses, and response procedures.
🎯 Requirements
- 5+ years of threat hunting, detection engineering, incident response, or related security
- Extensive hands-on experience with Microsoft Defender for Endpoint and strong knowledge of
- Expert-level experience with Splunk Enterprise Security, with advanced SPL for threat hunting and
- Experience with Splunk UBA or comparable behavioral analytics platforms.
- Advanced proficiency in Kusto Query Language (KQL) and developing sophisticated hunting/detection
- Proven experience conducting hypothesis-driven threat hunts and identifying attacker behaviors and
🎁 Benefits
- Annual salary range of $110,000–$130,000.
- Full-time opportunity focused on cybersecurity, threat hunting, and detection engineering.
- Remote work environment with collaboration from India.
- Opportunity to work with Microsoft Defender, Splunk Enterprise Security, and behavioral analytics.
- Exposure to complex security investigations, enterprise-scale threat detection, and incident
- Contribute to security strategy, knowledge sharing, training, and mentoring.
Back to all jobs