Remotely
pythonsecuritypowershellkqlsplmicrosoft defender for endpoint
Job Description
📋 Description
- Conduct hypothesis-driven threat hunts across endpoint, identity, network, and security analytics
- Use Defender and Splunk platforms to investigate suspicious activity and attacker behaviors.
- Develop and refine high-fidelity detection rules, correlation searches, and threat-hunting queries
- Apply MITRE ATT&CK framework to guide hunting, detection coverage, and defensive improvements.
- Perform incident response, endpoint forensics, malware analysis, and investigations to determine
- Translate threat intelligence into actionable detection logic, hypotheses, and response procedures.
🎯 Requirements
- 5+ years in threat hunting, detection engineering, incident response, or related security
- Extensive hands-on experience with Microsoft Defender for Endpoint and Microsoft 365 Defender/XDR.
- Expert-level Splunk Enterprise Security with advanced SPL for threat hunting and investigations.
- Experience with Splunk UBA or comparable behavioral analytics platforms.
- Advanced proficiency in KQL and developing hunting/detection queries.
- Strong knowledge of MITRE ATT&CK and modern attack techniques; proven capability to develop
🎁 Benefits
- Annual salary range of $110,000–$130,000.
- Full-time opportunity focused on cybersecurity, threat hunting, and detection engineering.
- Remote work environment with flexibility to collaborate from Brazil.
- Opportunities to work with Microsoft Defender, Splunk, and behavioral analytics platforms.
- Exposure to complex security investigations, enterprise-scale threat detection, incident response
- Contribute to security strategy, knowledge sharing, training, and mentoring.
Back to all jobs